23andMe says user data stolen in credential stuffing attack
bleepingcomputer.com
bleepingcomputer.com
So the database that is for sale is just a list of emails/passwords from other breaches that worked on 23andme, along with the data that 23andme had on those users. Not exactly a 23andme breach.
The included one on macOS is hidden in some setting panel.
For non-technical people the best authentication method is probably their phone (Passkeys, or tokens sent to their email address).
It's not a solved problem, even if a rudimentary password manager is in most browsers.
Personally I don't know a single person outside of my tech bubble that uses passwords that you can't keep in your head, or write down on a piece of paper on their desk.
As it's not possible to remember n passwords for n sites, if one of them gets hacked "darn secure" isn't so secure any more. The main point of password managers is that you don't have to remember your password and if it leaks out on one site, it doesn't matter as it's only used on that one site.
As long as you stay in the Mac/iOS walled garden, you really don’t need to access the Settings page/app. Safari and most apps will happily pull the user/pwd from the manager for you. I’ve used for a few years now (after tiring of the mediocre UX of several other managers).
> did not have 2fa enabled
be allowed to coexist with
> pretty extensive and personal data
In the meantime plain old high-entropy passwords with a good manager gives me all those features and a simplicity that's hard to beat.
In my 30+ years of computing I've suffered more harm from failures of other companies than I have from any failure of my own diligence. The whole lesson learned is to reduce trust in them and, maybe I'm wrong, but everything I've read about passkeys and the like seems to put me at liberty of the companies developing and pushing the implementations of them down my throat. It will take a lot of trust before I give up my ability to copy/paste my credentials.
Bitwarden has a few blogs if you search for bitwarden passkeys, but from skimming one it didn't seem to go into technical details (though I didn't watch the videos). I guess you could look through the PRs: https://github.com/bitwarden/clients/pulls?q=is%3Apr+passkey... but I don't really feel like doing that.
Yes it is. It's their fault for giving the user a choice. Google requires (some) users to enable 2FA, why can't 23andme?
Maybe that's the next big thing - local, personal companies that are your "online power of attorney" that have the right to reset your shit, make claims about your identity. I have no idea. But the current state of things is just a mess.
The account recovery process should be setup at the start of the 2FA setup - e.g., you get emailed a bunch of backup codes (easiest way imho).
The site should not be using their own 2FA app, but use a standard OTP implementation, and let the user use their own OTP app (most people default to google's authy, but there's a couple out there that are common too).
Or, as an alternative, delegate the login to email and use a password-less login mechanism (effectively delegating the account security to the email's security). I argue this is actually more convenient, but some people (esp. young people?) have an aversion to email which i don't understand.
Therefore, backup codes are no less secure than that.
Uhaul does this and it’s maybe the only good I can say about Uhaul. I think the catch is that some people don’t use email (or much of anything) on their mobile phones. Most will get sms immediately wherever they are at. Not everyone uses email that way.
Maybe for some irrelevant social media site I can understand doing password-only auth because who cares, but this has your DNA on it. Even if the person who has all their personal information leak doesn't care, they fucked over their entire family. I guess that's not 23andMe's fault though because they were just satisfying a rational user aversion!
Not only that, but the aversion to using methods of logon other than passwords are less rooted in passwords being easy, and more in passwords being STANDARD. Passkeys for instance are faster to use than passwords. The ONLY thing that makes passwords "Easy" is peoples refusal to start using something better because of one-time switching costs and inertia.
Which is bad, obviously, but I think everyone is catastrophising it.
if they can’t take responsibility for it, then they’re too irresponsible to make money it.
it would be entirely reasonable for them to say “we don’t want anything to do with this data, we don’t want to profit from it, we don’t want to use it in anyway, therefor we will not retain it at all.”
babying the user by taking responsibility for the very data they profit from? unreal.
i would absolutely argue that having my
1) genetic ancestry,
2) full name,
3) date of birth,
etc… is sensitive information.
even removing genetic information, if a company is too irresponsible to catch millions of users info being stolen, then they’re too irresponsible to have that data.
again, either it’s important to your business or it isn’t. if it isn’t important, then refuse to store it.
> Not too different from services requiring 2FA
That is another practice I find awful for the above reason.
It's a virtue that a car continues to operate when all the warning signs and buzzers are going off; this means that the human in charge is left in ultimate control of the situation and there doesn't need to be any complex umbrella structuring of liability -- this allows a driver to safely drive away from a dangerous tidal wave/assault/lava flow/whatever even if their seat belt sensor is broken ; this is very important for numerous reasons.
If you think that means the company can be held liable, I'd honestly start leaking my information on the internet if I were you. You have millions of dollars of lawsuits to go win apparently.
If you don't think so, then I think you're beyond reprehensible, and so will the courts. There is no disclaimer that can protect you. Good gravy, this is the easy part.
They have a large set of different emails + passwords, and a large set of IPs.
Each IP can check a single set of credentials, so you never get a single IP in a short timeframe with too many login attempts, and never trying to brute force a single account. If the attacker rented time on the botnet for a long enough period, they can fly under the radar for quite a while. 23andme sees lots of failed logins, but no real way to pin it down.
reCAPTCHA would be the answer here. What's interesting/concerning is that it appears Google's reCAPTCHA (assuming 23andme was using it, and they should've been) was defeated.
I think for sensitive data where you want to protect the user, it makes even more sense to just generate passwords for them. It’s even simpler than 2FA. Some online casinos do this.
The thing that worries me more is the possibility that newer AI tools are allowing attackers to beat reCAPTCHA with automation. If that's the case, a lot of folks are going to be caught with their pants down.
Edit: looks like it's more than a possibility[1].
“ The compromised accounts had opted into the platform's 'DNA Relatives' feature, which allows users to find genetic relatives and connect with them.
The threat actor accessed a small number of 23andMe accounts and then scraped the data of their DNA Relative matches, which shows how opting into a feature can have unexpected privacy consequences.”
Edit: maybe you are right about the lack of genetic info, if this account is correct (unless the researcher didn’t pay full price, and only got the metadata): https://therecord.media/scraping-incident-genetic-testing-si...
https://customercare.23andme.com/hc/en-us/articles/227968028...
For such a mature business (that is publicly-traded, no less!) it is shameful to allow credential stuffing on the scale of millions of accounts.
Is that really feasible today? With widespread use of phones and laptops, most people probably have at least a handful of different IP addresses they regularly use (home WiFi, work WiFi, cellular connection) and then they randomly connect from new up addresses like those from libraries, coffee shops, commute, etc
I think most “normal” apps and websites today allow any random IP to log in without jumping through extra hoops.
Only companies with big budgets (Apple, Google, etc) make regular users jump through extra hoops.
Banks, B2B have users that need extra hoops as well.
But 23andMe. I would not expect them to take any extra steps.
This alerts if there is a sudden login without my knowledge and one click to disable.
23&me could have definitely done that to alert logins.
It is 100% on 23&me even though used id/passwords were used.
Genetic data is by definition extremely personal.
All of whom I already mentioned in the comment you are responding to
GoG and Steam do "email 2fa" and while it's annoying they do it anyway as they are a "risky" target, IIUC.
When, five to ten years ago, everyone started sending email conformations "is this really you??" when logging in with the correct username and password on the first try, I always contacted support if that can be turned off. I figured the only way they were going to know it's a pain is if people complain. I have yet to learn of the first site where this is actually a choice...
Come to think of it, why haven't I made a Thunderbird plugin yet that recognises these emails and either sends the code to the browser or autotypes it. The credentials are filled in automatically, why not also their stupid email? Does this exist already?
The only ones requiring an SMS for me are organisations with a bank license, which are obviously a minority of all the services out there.
(Fwiw, I avoid all of the above besides Spotify, but a lot of code happens to be on github, audio books are invariably ~3x cheaper on amazon compared to buying from the publisher directly, many game developers insist that you let steam take a cut and don't let you buy it from them directly... that's how come I know these things all insist on sending emails.)
Strange answer. What do you actually mean by this? "furtherance of their repressive tactics" can mean just about anything - which government are you talking about, and which tactics?
Any government with racist tendencies might make use of this data and decide someone has $GENE which is primarily seen in $ETHNIC_GROUP so should be treated as poorly as the government treats $ETHNIC_GROUP
tl;dr: logging in from an ip address of a strange faraway country should not be its own security flag. /endrant
And most of the regularly used networks probably aren't using a static IP anyways.
Instead they could've monitored the password leaks to see if those got exposed
You can do better than email/sms, especially sms, but they're transitionary technologies. I login to way more things than most people do way more often. I don't use password authentication alone unless it's literally my only option.
IF they arrive right away, which isn't guaranteed for either method Also, do you seriously suggest every single user to set up some kind of x-platform scraping service (how would you scrape an SMS code to a computer's clipboard)???
"user hostile" means that you impose a cost on users without consent and in many cases without benefit
> I don't use password authentication alone unless it's literally my only option.
That's fine, but this isn't a conversation about you. I'm fine with a high-entropy auto-generated password for a huge bunch of services
>How would you scrape an SMS code to a computer’s clipboard
https://support.apple.com/en-us/guide/safari/ibrwa4a6c6c6/ma...
There’s no technical reason this same idea can’t work with every OS.
>impose a cost on users without consent
We have 1.3 million people who had their personal information leaked by an anti-Semite. More people are impacted by the breach in privacy than just the people who reused their passwords. The level of security was not appropriate to the context. Forcing costs on users can be good when said users are handling sensitive PII.
And until it gets to good and working on every OS you have no argument
> Forcing costs on users can be good when said users are handling sensitive PII.
No it can't, why do you think you can impose your personal oversensitive value judgements re. PII on every single user???
Why blame the users for a broken by design security model like password auth? Credential stuffing attacks are a known weakness. We cannot reasonably expect everybody to take precautions against them.
I've just become very irate at how people implement absolutely absurdly bad security and people just blame users when the inevitable happens. These attacks have happened for decades. It's not the fault of the users.
Because having to play a game of "Simon Says" every time I try to log into an account pisses off customers.
Humble Bundle, for example, lost several sales because you can't even buy a game for an e-mail address that has an account without logging into the account, which requires not just the password (stored in my password manager that I may not have with me everywhere I have my credit card), but also logging into my e-mail and clicking a link.
The EU has decided to force banks and payment providers to implement this nonsense because companies like e.g. PayPal decided to rather eat the cost of non-prevented fraud than putting an extra barrier in front of users and losing the users to competitors (by forcing everyone to do it, they prevented companies from competing on this aspect of UX).
I suppose massively increasing the liability would solve the problem by doing a little of both.
Loosening this requirement to new country / carrier would make life easier for users at small cost to security.
1. Solve CAPTCHA for log-in form
2. Log in with valid password
3. Open E-Mail client, maybe even log-into your e-mail with the same workflow if not done yet
4. Verify the IP via E-Mail
5. Surf to website log-in form again
6. Solve CAPTCHA for log-in form again
7. Log in again with a valid password
8. Verify with 2FA code
Thanks, I hate it. It feels like step 1 to 7 could be skipped.The opposite is the bigger WTF, why are the letting so many different people log in from the same IP at the same time. That’s a red flag on every fraud detection system I’ve seen. Not to mention there would be may failed logins for different accounts which is also a pretty strong warning.
Because they knew the password! That's what passwords are for. Please don't try to make life any more difficult for your users than it has to be.
Why is it so dumb? Because the vast, vast majority of people have no idea how any of this shit works. So, when a company demands that you sign up with your E-mail address and enter a password, a great many people are going to think they have to use their E-mail password too. This makes every one of these sites a gatekeeper to its users' E-mail accounts. If their security practices suck and they're hacked, or a disgruntled employee steals their records, or whatever... now a ton of their users' E-mail accounts are open for mining.
The failure to think this obvious scenario through is appalling. It's also appalling to see companies like Apple perpetrating this stupid behavior, especially AFTER the fact. Apple IDs originally did not have to be E-mail addresses. And later on, they did not have to be FUNCTIONING E-mail addresses. Now they've regressed all the way and they have to be both. And so Apple, per its usual M.O., has had to tack on various extra measures since then to try to shore up security.
In case you couldn't tell, I absolutely detest this policy.
Then don't let them use it. We don't let people drive who don't know how to safely operate a car. We don't let people make food in commercial kitchens without training. We let users run free with no knowledge, then build systems to stop them from hurting themselves, it's absurd.
2FA, or passwordless logins, are the solution. Forcing the user to change their password (at the most inconvenient of times - right after they logged in, but before they're able to use the site) is annoying at best, and does nothing at worst.
You cannot claim that just because some users are 'saved' as evidence that this is an effective security measure, because if a password was leaked, and not discovered, then this measure doesn't prevent it. But it is imposing a cost, which cannot be measured against effectiveness.
Change the whole process to 2FA is secure because there's provable guarantees for the costs imposed, and therefore, you can make an objective decision on whether it is worth implementing.
> You cannot claim that just because some users are 'saved' as evidence that this is an effective security measure
Why not? Saving people from insecurities is almost by definition a measure of effectiveness
> you can make an objective decision on whether it is worth implementing.
You can't since the value factors in your "provable guarantees" and costs involved are subjective and also depend on the users' characteristics
no it doesn't. The claim is that by removing publicly leaked passwords, the user is prevented from having their logins stolen. But you didnt know if that password was going to be used for stealing - it's an assumption. You also dont know if private leaks are already being used, and is undetected.
It's the same type pf claim that the TSA (transport security authority) is saving people from terrorism.
But you do know for a fact that these leaked passwords are used for stealing, so forcing a password change would prevent that, ergo, save some users from having their data stolen. Private leaks have no impact on this
no, the passwords are revealed, but it might not be used for stealing. And passwords that are stolen but not revealed publicly will continue.
My point is that the site will force an update, but the user's quota of inconvenience is used up - therefore, a more effective measure such as 2FA will be seen as unnecessary by the user, and thus, lower the user's security.
This is why the solution is to not spend the effort/cost on trying to detect password leaks. It is to make 2FA.
It’s very simple, and I believe has been an accepted best practice since like 2017. This is 100% on 23andme. They are responsible.
> this attack could be done on literally any website. The issue is people re-used passwords, and also did not have 2fa enabled.
While possible to execute at scale on some websites, this type of attack tends to be quite loud on the receiving end once appropriate metrics are selected for monitoring and alerting.
> "We do not have any indication at this time that there has been a data security incident within our systems."
They should probably work on that, given that those systems were used to extract their customer's data, and that they only noticed when their customer's data was being sold.
Given how far behind they are on disclosure I'd guess they may have only found out from media inquiries.
So... basically exactly what the title says. 23AndMe says user data stolen in a credential stuffing attack.
From a "computer science" perspective this makes sense: if I say you can view all my data, I lose control with who else you share that data with. But from a "human" perspective, most people don't think that if I give you access that I'm essentially giving access to the rest of the world.
These types of network permissions make any company who holds them a prime target because it means bad guys only need to hack a few accounts to get exponentially more data.
They would only see the subset of what your friend shared, the set configured by its author as visible to friends of friends, right?
Back in the late 00s/early 10s when lots of "Facebook apps" were a bit of a craze (think Farmville), you could give an app maker permission to view your personal data and all of the data that you could see about your friends. This is how Cambridge Analytics was able to build profiles of 87 million Facebook users when only a few hundred thousand actually installed the "your digital life" app: https://www.theguardian.com/news/2018/mar/17/cambridge-analy...
(as to how I verified: the file is still available on the leak site)
These are the headers:
profile_id; account_id; first_name; last_name; sex; birth_year; has_health; ydna; mdna; current_location; regions; subregions; population_ids
First entry is Elon;Musk;Male;1971;...But yes, for EM it said "Ashkenazi;Balkan;British Irish" - no percentages in there - and I believe 23andme has confirmed the authenticity of the data.
This means a typical Ashkenazi Jewish customer of 23andMe has a lot more relatives than most other customers, and so they'd be able to view that many more profiles.
If I live a hundred years I will never understand people’s obsession with the Jews
Turns out it didn't need to be that elaborate, you could just ask folks to mail it in ;)
https://www.pbs.org/newshour/amp/science/dna-ancestry-search...
Every time there's a breach, they pull a British Petroleum "we're reallllly sorrrrrry" and buy a bunch of people LifeLock. Its absolute bullshit.
I don't know the answer, but I would say your DNA sequence should be secured similarly to your bank account.
please don't kill me CIA! I swear I accidentally saw it.
welp! time to head back to my work.
> Three weeks ago, genetic testing firm 1Health.io agreed to pay the Federal Trade Commission (FTC) a $75,000 fine to resolve allegations that it failed to secure sensitive genetic and health data, retroactively overhauled its privacy policy without notifying and obtaining consent from customers whose data it had obtained, and tricked customers about their ability to delete their data.
If you take away $75K from their engineering budget they will only do a worse job, and more data will leak.
Provide the security expert to them at no cost, taxpayer funded, as a collective effort to stop identity leaks.
If they took away $75K I might be forced to lay off someone, possibly one who could have fixed the problem.
A few stolen identities, some bank fraud, but largely the systems in place can handle it. It’s caught at the other end.
If you want big fines, prove big consequences.
Besides, if you can find a specific person who was specifically harmed by this exact breach, I bet you could sue for damages, and get more than $75k.
The $75k fine is exactly proportional to the complete lack of concrete harm done. Nobody gets fined for cars existing.
The average person has around 200 3rd cousins.
One of my 200 third cousins did a 23andMe swab. I then committed a crime, possibly on the other side of the country*.
Law enforcement collects DNA evidence. What now?
* edit: Previously this said "or world" but that felt unreasonable for the question
Basically they send in the genetic material and create an account on the site, then see which relatives it matches with and go from there.
https://geneticaffairs.com/faq.html
> Genetic Affairs is able to retrieve DNA matches for several DNA matching companies. To download DNA matches of these companies we need to store your login credentials. See the next section concerning the secure storage of these credentials.
> Since we have to use login information for 23andme and FamilyTreeDNA, we use an isolated database in which we encrypt and store the passwords of these websites. This database is only available in a private network in the cloud and not exposed to the Internet.
It's not on 23andMe, or anyone (other than the user) for that matter, to ensure the passwords used by the user are not copied passwords from other credentials.
Seems to me like passwords need to be regulated on a governmental level, but that's a can of worms of an idea that I am not ready to defend.
Credential stuffing is most preventable by the user (who can simply not reuse passwords), but platforms have a responsibility as well. They can at least mitigate it through rate limiting, and mostly stop it with 2FA requirements.
If an attacker is able to exfiltrate millions of records from a platform with credential stuffing, that means they tried to login to multiple millions of accounts. It shouldn't be difficult for a service to detect and stop such a sustained level of load on its login infrastructure. You can't get millions of proxies.
I work on combating credential stuffing on a regular basis... it's quite challenging.
They could have prevented that by not keeping the data longer than needed to send it to the user.
I don't really think this needs to be regulated; government-standard guidelines are probably sufficient, with companies knowing that deviating will expose them more to litigation in the event of a problem.
Not trying to argue with you, I did read your last sentence, just tossing in another POV.
Sort of a "negative security externality"...
It's simply easier for me, as a human, to remember that my password for all websites is Hunter2, rather than spend the extra time, create a password manager account, store passwords, utilize best password management practices, etc. Not saying this is what I do, but for many people, this is how they remember their password(s).
Maybe I should have changed the "tricked into" to "trick themselves", but I'm just a human and this was easier for me.
In my opinion, it is, actually, on 23andMe. At my tiny startup, I implemented a simple check against Troy Hunt’s compromised password database.[1] If I can do it, 23andMe can.
If anyone reading this is in the business of making web apps and there’s literally anything of value behind your login, prioritize this mitigation. OWASP recommends it too. [2]
1. https://haveibeenpwned.com/Passwords
2. https://cheatsheetseries.owasp.org/cheatsheets/Credential_St...
Seriously — what are people going to do with it? It's illegal for insurance companies to discriminate. I'd post it myself on GitHub if anyone showed the slightest interest in using it.
You're confident enough that nothing can be done, to the point that you'd take the risk for no upside. That... doesn't sound rational to me?
We know now, they are going to leak it.
Everyone is going to know that I'm an Ashkenazi Jew who is more likely going to have blue or brown eyes and hair loss.
Whooops.
We know where Meryem was born (govt records which you probably helped make public), we can read James' twitter feed and we know the relatives of political figures (except for all the illegitimate children).
So yea... I'm still not seeing the issue here.
We are assuming James posted such details to a public twitter feed. That does not account for the others who did not. The issue in Meryem's case is that obtaining birth records is not guaranteed (especially from a foreign country), and that birth location isn't the same as genetic ancestry. Regarding Alex:
> except for all the illegitimate children
That is part of my point. If my absent parent were actually some famous politician, I would personally not want to have that information leaked. Some might not care - that's great. My point is a simple one - just because having private medical info exfiltrated is not really a big deal for many people, doesn't mean that it's ok to give a pass to the parties responsible for the exfiltration.
Your original comment was all about hypotheticals, so yes, it opens up the discussion to assumptions.
Agreed that, in general, it sucks that stuff leaks out. That said, every time someone brings up 23andme, it feels like one of those "the govt is going to shut down in a week if we don't do something!" type of headlines that seem to be on repeat... where in the end it turns out that at the last minute, something is done to prevent it, and everything turns into a giant nothing burger.
> More that govt's, in general, have a habit of leaking personal information for their own benefit.
I 100% agree with this.
Cheers!
For how long ? Being jewish on record in Germany in 1930 was fine, in 1940 not so much
Data is forever, laws, regulations, governments, &c. aren't
If you want to take that bet, let me know and I will send you my contact info.
Get back to your crystal ball and tell me when the war in Ukraine will end and how much will a btc be worth in 5 and 10 years
If people in this forum believe Musk when he says fully autonomous vehicles will be there in two years (since 2012) and that the AI singularity is coming this decade, the possibility of genetic testing being extended to pre conditions isn't so crazy
Genetic data will definitely be used to limit freedom of movement somewhere on Earth in the next 25 years. We’ve already been mass-swabbing for COVID for the past three years, so it won’t be that big a change.
well well well
A concrete example: What could the consequences in today's USA political climate be of having a massive database be with columns: Firstname, Lastname, y_chromosome_present.
Only for health insurance. Other types of insurance companies are free to use that data to discriminate against you, include life, disability, and long-term care insurance.
Source: https://www.linkedin.com/feed/update/urn:li:share:7116053429...
And all their relatives (who share a lot of their DNA after all)
Is 23andMe going to actually be held responsible?
I think both our industry and our information infrastructure would be vastly better if companies were forced to be serious about security when they are collecting and holding private data.
This not only affects users, but the user's relatives/loved ones as well.
Again, just as I understand it, that's why nobody gets in trouble for this shit. It's not really fair to blame any one particular person. Whether or not that can be remedied by modifying the corporate system we operate in somehow, I don't know. Probably yes, but that's not my skillset at all.
edit: but in any case, this was due to people re-using passwords, so I doubt you could realistically blame the company.
> It's not really fair to blame any one particular person
These are literally the very circumstances that we were presented with as reason why executive compensation is astronomical. It's all that responsibility they have to assume in times like these, right? They're supposed to fall on their sword, and whoever replaces them is supposed to make damn sure shit like this doesn't happen on their watch. The pay and parachutes ensure they land on their feet.
The reason nothing ever changes is because these clowns never get in trouble. If you want that $10M salary, you better make sure everyone under you is doing their part to ensure events like this don't happen-- or you get dethroned.
Does China still sell melamine-tainted baby formula? We've been conditioned to just let our leaders stay in command after plowing into icebergs-- while they blame and execute the engineers shoveling coal below deck.
The solution isn't to randomly start blaming CEOs for things they had no realistic control over, it's to swing in the other direction of putting more money towards workers by taking it away from pure growth-oriented goals.
My perception is that it’s really really hard to differentiate between someone who’s genuinely a force to be reckoned with and someone who’s just in the right place at the right time. After their first success they can hop around between companies from executive role to executive role playing it safe and riding the gravy train just by not fucking it up. I’d be interested if anyone can provide examples of executives that consistently trigger inflections in a company’s performance within say 2 years of joining across multiple companies. I’m genuinely curious.
Intent is not a sufficient legal standard to address this epidemic of negligence. We need Strict Liability for data protection.
Separate from that, if there's laws and regulations, the company could also be hit with fines. Officials could also investigate individual culpability for bad behavior by people within they company, but that possibility doesn't mean that any kind of holding companies responsible would be unfair.
Goes to your head when you're the largest generation during your formative years. Nobody has any choice but to do what you say.
So you take what you can get and screw over everyone else coming after you.
And then you belittle them for resenting you over it.
Or externalities.
23andme kept the upside benefits - making money, but doesn't have to realize the downside risk - facilitating future conflict.
If anyone thinks that's facetious, I encourage them to read Erin Kissane's description of what went down in Myanmar - https://erinkissane.com/meta-in-myanmar-part-i-the-setup. And then think about how they did that without DNA data.
> The researcher added that he discovered another issue where someone could enter a 23andme profile ID, like the ones included in the leaked data set, into their URL and see someone’s profile.
Amazingly incompetent.
23andMe has a feature that lets you see people you're related to and view their profiles. My guess is this feature had few rate limits and allowed you to view the profiles of people very distantly related. So perhaps with a couple thousand valid account logins you could eventually look up the profiles for 1.3M users.
> The information that has been exposed from this incident includes full names, usernames, profile photos, sex, date of birth, genetic ancestry results, and geographical location.
Not good. Really not good.
This is why I never volunteer any PII to link with my DNA. Sampling DNA is not that hard (we leave traces literally everywhere) but credibly linking it to PII is another thing.
In other news, this is surprisingly not very well known but california takes, and saves, a DNA sample of any baby born in a CA hospital. There is no consent nor opt-out, not even notification. You can write a letter to have the sample destroyed and sometime later you'll get confirmation of such. You can only hope that it wasn't sequenced and saved already and/or that it was properly destroyed.
https://www.cbsnews.com/news/california-biobank-dna-babies-w...
huh. "many states" do it, I had no idea. Apparently all 50 states are required to do a genetic screening but I guess above and beyond that some states save the sample.
I wonder what would happen if a parent or family member physically intervened to prevent taking the sample.
(Or you know, give you a certificate that says they destroyed it.)
If you sell your DNA profile to someone, they are free to give or sell it to someone else. At best that's a breach of contract, but what are you going to do? A successful class action only changes the price retroactively.
(I am told some people sell their DNA data at a negative price, which I suspect may be the same people who pay to have to have a remotely controlled microphone at home. That I don't understand, and accept that I probably never will. But it doesn't change the underlying premise and market dynamic. The above is still true.)
When the evil kind of hackers disrupted a children's hospital, did someone ask how they could be as evil as that, then had the idea, "Hey, how about selling a list of Jewish people specifically?"
(They have to know that no one's going to buy that for marketing, but rather for targeting due to hatred and insanity.)
Really? If the article is accurate, 23andMe did not have a security breach; credentials leaked in other breaches were used to compromise accounts that reused those credentials on 23andMe. Now certainly 2FA would have been advisable, but I think it's a bit much to suggest this rises to the level of criminality.
I didn't have any of the known genetic markers for Parkinson's at the time and requested they destory my data and sample.
From the ancestry standpoint, I think it's only useful for a very limited set of individuals/scenarios. In my case, I'm 90% Eastern European which is... kind of basic considering I know where I was born. Yeah, I share a lot of my DNA with all the people who were born in roughly the same geographic area. Big fucking surprise?
I never used 23andme and not planning to (the example is from a close friend of mine who did). I think the privacy concerns far outweigh the benefits.
But I am interested in genetic testing so if anyone has any pointers for a privacy conscious, not-for-profit (maybe in academia?), non-Law Enforcement friendly entity and preferably does it anonymously, please let me know.
[1]: "Why You Should Be Careful About 23andMe’s Health Test" - https://archive.ph/lpaUU
There’s a lot of health information that’s useful. Propensity to alcohol dependency, propensity for fat retention, propensity for diabetes and high blood pressure etc. You can also download your SNPs and use that information on other sites that give you a lot more, less verified information.
Not really. And they're inaccurate. Did they even publish their baselines?
> Propensity to alcohol dependency, propensity for fat retention, propensity for diabetes and high blood pressure
These should be between you and your GP. And I can tell you that you have a propensity to many addictions, just by assuming you're human. Don't test them. Don't rely on 23andme to validate "No propensity for gambling addication? Casinos, here I come!"
If people were regularly surreptitiously collecting DNA samples from "the wild" at similar scale, this would be a different conversation.
It is amusing to me that this idea was being celebrated here just a few days ago [1].
Looking at the data: name, location, dna group. Not very worried
The 23andMe founder (and current CEO) Anne Wojcicki is the sister of Susan Wojcicki, until recently a long time Youtube CEO.
Anne is also the ex-wife of Google/Alphabet founder Sergey Brin. Google/Alphabet is also an investor in 23andMe. Youtube is an Alphabet company.
It’s amusing and ironic to me that the co-founder of a gene-testing company has such an interconnected family network within the tech industry.
It was sort of cool that as a 23andme employee some time back (10-12 yrs?), you could use some of Google's amenities because of these relationships.
Apart form that the "research" they do it dubious AF and can't be trusted at all. There are cases where people send in DNA of a banana and get some made up human genetic history back.