Thursday, January 8, 2009

Will Your Health Information Be Secure?

Today, President-Elect Obama announced his goal of having all medical records computerized in five years.

Approximately 10 days ago, a team (Alexander Sotirov, Marc Stevens,
Jacob Appelbaum, Arjen Lenstra, David Molnar, Dag Arne Osvik, Benne de Weger) "...identified a vulnerability in the Internet Public Key Infrastructure (PKI) used to issue digital certificates for secure websites. As a proof of concept we executed a practical attack scenario and successfully created a rogue Certification Authority (CA) certificate trusted by all common web browsers. This certificate allows us to impersonate any website on the Internet, including banking and e-commerce sites secured using the HTTPS protocol." http://www.win.tue.nl/hashclash/rogue-ca/

Because access is not assured secure, computer medical records, which hold your and my highly personal and sensitive information, are not secure. A team has documented its ability to break a major security system used by financial agencies. Hackers will be attracted to the new challenge of computerized medical records like maggots to old meat.

No comments: