Obamacare website too vulnerable, say security experts

20 November 2013
By Tereza Pultarova
Mobile version
Share |
Some experts have said the Obamacare website would better be shut down due to security glitches

Some experts have said the Obamacare website would better be shut down due to security glitches

Obamacare website puts sensitive data of users at risk, experts have said said, recommending it to be shut down until the problems are addressed.

Speaking in front of the US congress on Tuesday, some of the questioned experts said the site needed to be completely rebuilt to run more efficiently, making it easier to protect.

With its 500 million lines of code – 25 times the size of Facebook – the HealthCare.gov website is extremely vulnerable, the experts believe.

"When your code base is that large it's going to be indefensible," Morgan Wright, CEO of a firm known as Crowd Sourced Investigations, said in a Republican-led questioning.

David Kennedy, head of computer security consulting firm TrustedSec LLC and a former US Marine Corps cyber analyst said in a written testimony some of the major security glitches of the HealthCare.gov would require at least seven to 12 months to be fixed and suggested the site would better be shut down until the problems are solved.

Earlier this month, experts revealed the site lets people know invalid user names when logging in, allowing hackers to identify user IDs.

Avi Rubin, director of the Information Security Institute at Johns Hopkins University and an expert on health and medical security, said he needed more data before calling for a shutdown of the site.

"Bringing down the site is a very drastic response," he told Reuters after the hearing. However, he admitted, he would not use the site himself because of security concerns.

It has also been revealed during the hearing that the part of the HealthCare.gov system securing financial operations is by far not ready and won’t be until at least mid-January.

According to Henry Chao, HealthCare.gov’s project manager, the unfinished technology makes up 40 per cent of the whole system.

According to insider sources, work on the back-end technology was postponed by the managers in order to allow developers to fully concentrate on the user interface prior to the website’s launch.

Julie Bataille, the spokeswoman for Centers for Medicare & Medicaid Services – a federal health agency operating the website, said the financial functions would not be needed until mid-January.

"The back-end financial management systems are something that we do not believe are essential until 2014 and we'll roll those out in those timeframes," she said.

However, the insurers will start sending the bills as soon as 1 January, claiming billions of dollars for subsidised coverage, which could possibly lead to a collapse of the fragile website.

Some experts have also suggested a program needed to confirm the identities, subsidy levels and coverage choices of individual plan enrolees would have to be in place in December, if coverage is to begin on time on 1 January.

Latest Issue

E&T cover image 1605

"We visit Barcelona, one of the smartest cities in the world, to find out what makes it so special. What does it look like and what is the future?"

E&T jobs

  • High Voltage Engineer

    Premium job

    Essex X-Ray & Medical Equipment
    • Great Dunmow, Essex

    This High Voltage Engineer will provide design leadership for high voltage cable assemblies up to one megavolt.

    • Recruiter: Essex X-Ray & Medical Equipment

    Apply for this job

  • Sales Electronics Engineer

    Premium job

    Precision Microdrives
    • London (Greater)
    • £25,000 - £30,000 starting salary, inclusive of on-target commissions.

    Precision Microdrives (PMD) is a fast growing technology company that designs, produces and trades miniature electro-mechanical mechanisms

    • Recruiter: Precision Microdrives

    Apply for this job

  • Senior Development Engineer, Electronics

    Premium job

    Helmet Integrated Systems / Gentex Corporation
    • Letchworth Garden City, Hertfordshire
    • Competitive

    We are innovative, robust and fast growing business, whose main focus is to deliver continues improvement to existing products and offer new soluti...

    • Recruiter: Helmet Integrated Systems / Gentex Corporation

    Apply for this job

  • Analogue Electronics Engineer

    Premium job

    Swedish Institute of Space Physics (IRF)
    • Uppsala (Stad) (SE)

    The Swedish Institute of Space Institute (IRF) in Uppsala search for an analogue electronics engineer.

    • Recruiter: Swedish Institute of Space Physics (IRF)

    Apply for this job

  • Principal Robotic Systems Engineer

    Premium job

    National Oceanographic Centre
    • Southampton, Hampshire
    • £45,271 to £49,207 per annum

    Responsible for technical oversight and project management of internally and externally funded innovation centre projects.

    • Recruiter: National Oceanographic Centre

    Apply for this job

  • Smart Grid Research Engineer

    Premium job

    University of Strathclyde
    • Cumbernauld, Glasgow
    • Grade: 6/7* £26,537 - £37,768*

    Work as part of a growing dynamic team on a wide range of technical projects with particular emphasis on experimental validation and testing

    • Recruiter: University of Strathclyde

    Apply for this job

  • Electrical Engineer - Water

    Premium job

    Mott MacDonald
    • Peterborough, Cambridgeshire

    Mott MacDonald's highly successful Water and Environment Unit is recruiting an electrical engineer....

    • Recruiter: Mott MacDonald

    Apply for this job

  • Electrical Design Engineer

    Premium job

    Mott MacDonald
    • Cambridge, Cambridgeshire

    Mott MacDonald's highly successful water business continues to win and deliver a fantastic amount of work....

    • Recruiter: Mott MacDonald

    Apply for this job

  • Launcher Verication & Validation Lead

    MBDA
    • Bristol
    • Competitive Salary & Benefits

    What’s the opportunity? Opportunity to join a very dynamic, responsive and multinational Launcher team, focussed on rapid development, proving and manufacture to meet challenging programme...

    • Recruiter: MBDA

    Apply for this job

  • Technical Design Authority - Marine Systems (Mechanical)

    BAE Systems
    • Scotland, Glasgow
    • Negotiable

    Technical Design Authority - Marine Systems (Mechanical) Would you like to play an exciting and varied role working with the River Class Batch 2 (RCB2) vessels for the Royal Navy? We currently have a vacancy for a Technical Design Authority - Marine Syste

    • Recruiter: BAE Systems

    Apply for this job

More jobs ▶

Subscribe

Choose the way you would like to access the latest news and developments in your field.

Subscribe to E&T