Actually, the www was working. It's a cname to tp.47cf2c8c9-frontier.amazon.com, which should have been a cname to d3ag4hukkh62yn.cloudfront.net, but that record was broken for about 20 minutes.
Update: that frontier cname seems to be bouncing between Cloudfront and Akamai now, so I suspect they're fighting off either an attack or internal issues. I see issues to other route53 servers as well.
I've seen more compromised boxes than one can shake a stick at. There's all sorts of reasons that blocking egress is a great idea. Compromises are usually automated bots, and no, they're not smart enough to bring down iptables. Even if it's a human that's pwned you, it's frequently a stupid human, or a lazy human. It's just good practice to practice security in depth.
To go a little further - at a glance, it's not clear if they've been fined yet or not, but either way there's soft costs to all of this - being in the news in a negative light, some patients will go elsewhere, their insurance premiums are going to go up as a result of the breaches, etc etc.
Last year when KC shot themselves in the face, they were running trading algos that hadn't been well tested. When dropped into production, things blew up fairly quickly.
I probably should have left it off the list, it's more of a compliance/procedural issue than purely infosec.
TJ Max,
UBS,
Knight Capital,
Heartland Payment Systems,
Visa,
Sony (already mentioned, but it's my fave),
Stanford,
Countless other hospitals, e-commerce vendors, banks, and other organizations that handle payment or personal information.
If you want to say "name a startup that's gone out of business because of a security problem" I'll let you away with that. There's still instances, and I'd love startups to pay more attention to security, but I know reality as well...
A problem for security geeks is they frequently forget about 2 things: 1) the balance between usability and security, and 2) The risk acceptance/appetite of the person for the security they want/need to use.
The two are intertwined closely. For something that isn't that important, a user isn't going to jump through complex hoops every time they have to login. What they will end up doing is finding workarounds (Hello Mr. Post-It).
For most folks, they don't really need complex solutions to reset their email password. What needs to be asked is "What am I protecting, and what is it worth to me?"
Oh, and I'd suggest certificate-based auth is way better than complex passwords.
Daniel's been around for a while (I've loved OSSEC for years) so I suspect this post just wasn't meant to be a complete essay on the topic...
Yeah...this is nice, but really who's gonna implement it? Only folks with a lot of resources and need to protect something more serious than passwords on a social network.
Or organizations who are vulnerable to the RSA sales person attack. ;)
As others have hinted - once you have folks sophisticated enough to do tricks like using multiple operating systems, you'd hope they're going to catch the basics...