MNsure Denies Website is Vulnerable, Blames Users

Updated: 11/27/2013 10:28 PM
Created: 11/27/2013 7:37 PM
By: Nick Winkler

MNsure, the state's health care exchange, says the vulnerability 5 EYEWITNESS NEWS exposed recently is not a MNsure vulnerability.

Instead, MNsure blames users who are not following sound security practices.

In our test, Mark Lanterman at Computer Forensic Services in Minnetonka, was able to use a device available to hackers to intercept username and password data.

Lanterman says the simulated attack is not a traditional middle man attack. Instead, he says the device exploits a vulnerability in the MNsure website itself.

However, MN.IT, the state's information technology department that developed MNsure's security, says the problem is not with its web. It says there's not a lot government entities can do to prevent such attacks.

Lanterman disagrees and says websites can be coded in a manner that protects user data even when middle man attacks like the one we performed are launched.

5 EYEWITNESS NEWS has also learned that despite the botched federal health care exchange rollout, even it is more secure than MNsure in terms of the simulated Wi-Fi attack we performed.

Click here for information on cyber security awareness.

Minneapolis/St. Paul

62° | 48°
  • Feels like: 51° F
  • Wind: SE 5mph
  • Humidity: 89%
  • Fri A few clouds
    70° | 50°
  • Sat Abundant sunshine
    66° | 48°
  • Sun Partly cloudy
    71° | 50°
  • Mon A few clouds
    58° | 44°