So the database that is for sale is just a list of emails/passwords from other breaches that worked on 23andme, along with the data that 23andme had on those users. Not exactly a 23andme breach.
So the database that is for sale is just a list of emails/passwords from other breaches that worked on 23andme, along with the data that 23andme had on those users. Not exactly a 23andme breach.
For such a mature business (that is publicly-traded, no less!) it is shameful to allow credential stuffing on the scale of millions of accounts.
Is that really feasible today? With widespread use of phones and laptops, most people probably have at least a handful of different IP addresses they regularly use (home WiFi, work WiFi, cellular connection) and then they randomly connect from new up addresses like those from libraries, coffee shops, commute, etc
I think most “normal” apps and websites today allow any random IP to log in without jumping through extra hoops.
Only companies with big budgets (Apple, Google, etc) make regular users jump through extra hoops.
Banks, B2B have users that need extra hoops as well.
But 23andMe. I would not expect them to take any extra steps.
This alerts if there is a sudden login without my knowledge and one click to disable.
23&me could have definitely done that to alert logins.
It is 100% on 23&me even though used id/passwords were used.
Genetic data is by definition extremely personal.
All of whom I already mentioned in the comment you are responding to
GoG and Steam do "email 2fa" and while it's annoying they do it anyway as they are a "risky" target, IIUC.
When, five to ten years ago, everyone started sending email conformations "is this really you??" when logging in with the correct username and password on the first try, I always contacted support if that can be turned off. I figured the only way they were going to know it's a pain is if people complain. I have yet to learn of the first site where this is actually a choice...
Come to think of it, why haven't I made a Thunderbird plugin yet that recognises these emails and either sends the code to the browser or autotypes it. The credentials are filled in automatically, why not also their stupid email? Does this exist already?
The only ones requiring an SMS for me are organisations with a bank license, which are obviously a minority of all the services out there.
(Fwiw, I avoid all of the above besides Spotify, but a lot of code happens to be on github, audio books are invariably ~3x cheaper on amazon compared to buying from the publisher directly, many game developers insist that you let steam take a cut and don't let you buy it from them directly... that's how come I know these things all insist on sending emails.)
Strange answer. What do you actually mean by this? "furtherance of their repressive tactics" can mean just about anything - which government are you talking about, and which tactics?
Any government with racist tendencies might make use of this data and decide someone has $GENE which is primarily seen in $ETHNIC_GROUP so should be treated as poorly as the government treats $ETHNIC_GROUP
tl;dr: logging in from an ip address of a strange faraway country should not be its own security flag. /endrant
And most of the regularly used networks probably aren't using a static IP anyways.
Instead they could've monitored the password leaks to see if those got exposed
You can do better than email/sms, especially sms, but they're transitionary technologies. I login to way more things than most people do way more often. I don't use password authentication alone unless it's literally my only option.
IF they arrive right away, which isn't guaranteed for either method Also, do you seriously suggest every single user to set up some kind of x-platform scraping service (how would you scrape an SMS code to a computer's clipboard)???
"user hostile" means that you impose a cost on users without consent and in many cases without benefit
> I don't use password authentication alone unless it's literally my only option.
That's fine, but this isn't a conversation about you. I'm fine with a high-entropy auto-generated password for a huge bunch of services
>How would you scrape an SMS code to a computer’s clipboard
https://support.apple.com/en-us/guide/safari/ibrwa4a6c6c6/ma...
There’s no technical reason this same idea can’t work with every OS.
>impose a cost on users without consent
We have 1.3 million people who had their personal information leaked by an anti-Semite. More people are impacted by the breach in privacy than just the people who reused their passwords. The level of security was not appropriate to the context. Forcing costs on users can be good when said users are handling sensitive PII.
And until it gets to good and working on every OS you have no argument
> Forcing costs on users can be good when said users are handling sensitive PII.
No it can't, why do you think you can impose your personal oversensitive value judgements re. PII on every single user???
Why blame the users for a broken by design security model like password auth? Credential stuffing attacks are a known weakness. We cannot reasonably expect everybody to take precautions against them.
I've just become very irate at how people implement absolutely absurdly bad security and people just blame users when the inevitable happens. These attacks have happened for decades. It's not the fault of the users.
Because having to play a game of "Simon Says" every time I try to log into an account pisses off customers.
Humble Bundle, for example, lost several sales because you can't even buy a game for an e-mail address that has an account without logging into the account, which requires not just the password (stored in my password manager that I may not have with me everywhere I have my credit card), but also logging into my e-mail and clicking a link.
The EU has decided to force banks and payment providers to implement this nonsense because companies like e.g. PayPal decided to rather eat the cost of non-prevented fraud than putting an extra barrier in front of users and losing the users to competitors (by forcing everyone to do it, they prevented companies from competing on this aspect of UX).
I suppose massively increasing the liability would solve the problem by doing a little of both.
Loosening this requirement to new country / carrier would make life easier for users at small cost to security.
1. Solve CAPTCHA for log-in form
2. Log in with valid password
3. Open E-Mail client, maybe even log-into your e-mail with the same workflow if not done yet
4. Verify the IP via E-Mail
5. Surf to website log-in form again
6. Solve CAPTCHA for log-in form again
7. Log in again with a valid password
8. Verify with 2FA code
Thanks, I hate it. It feels like step 1 to 7 could be skipped.The opposite is the bigger WTF, why are the letting so many different people log in from the same IP at the same time. That’s a red flag on every fraud detection system I’ve seen. Not to mention there would be may failed logins for different accounts which is also a pretty strong warning.
Because they knew the password! That's what passwords are for. Please don't try to make life any more difficult for your users than it has to be.
Why is it so dumb? Because the vast, vast majority of people have no idea how any of this shit works. So, when a company demands that you sign up with your E-mail address and enter a password, a great many people are going to think they have to use their E-mail password too. This makes every one of these sites a gatekeeper to its users' E-mail accounts. If their security practices suck and they're hacked, or a disgruntled employee steals their records, or whatever... now a ton of their users' E-mail accounts are open for mining.
The failure to think this obvious scenario through is appalling. It's also appalling to see companies like Apple perpetrating this stupid behavior, especially AFTER the fact. Apple IDs originally did not have to be E-mail addresses. And later on, they did not have to be FUNCTIONING E-mail addresses. Now they've regressed all the way and they have to be both. And so Apple, per its usual M.O., has had to tack on various extra measures since then to try to shore up security.
In case you couldn't tell, I absolutely detest this policy.
Then don't let them use it. We don't let people drive who don't know how to safely operate a car. We don't let people make food in commercial kitchens without training. We let users run free with no knowledge, then build systems to stop them from hurting themselves, it's absurd.
“ The compromised accounts had opted into the platform's 'DNA Relatives' feature, which allows users to find genetic relatives and connect with them.
The threat actor accessed a small number of 23andMe accounts and then scraped the data of their DNA Relative matches, which shows how opting into a feature can have unexpected privacy consequences.”
Edit: maybe you are right about the lack of genetic info, if this account is correct (unless the researcher didn’t pay full price, and only got the metadata): https://therecord.media/scraping-incident-genetic-testing-si...
https://customercare.23andme.com/hc/en-us/articles/227968028...
> did not have 2fa enabled
be allowed to coexist with
> pretty extensive and personal data
In the meantime plain old high-entropy passwords with a good manager gives me all those features and a simplicity that's hard to beat.
In my 30+ years of computing I've suffered more harm from failures of other companies than I have from any failure of my own diligence. The whole lesson learned is to reduce trust in them and, maybe I'm wrong, but everything I've read about passkeys and the like seems to put me at liberty of the companies developing and pushing the implementations of them down my throat. It will take a lot of trust before I give up my ability to copy/paste my credentials.
Bitwarden has a few blogs if you search for bitwarden passkeys, but from skimming one it didn't seem to go into technical details (though I didn't watch the videos). I guess you could look through the PRs: https://github.com/bitwarden/clients/pulls?q=is%3Apr+passkey... but I don't really feel like doing that.
Yes it is. It's their fault for giving the user a choice. Google requires (some) users to enable 2FA, why can't 23andme?
Maybe that's the next big thing - local, personal companies that are your "online power of attorney" that have the right to reset your shit, make claims about your identity. I have no idea. But the current state of things is just a mess.
The account recovery process should be setup at the start of the 2FA setup - e.g., you get emailed a bunch of backup codes (easiest way imho).
The site should not be using their own 2FA app, but use a standard OTP implementation, and let the user use their own OTP app (most people default to google's authy, but there's a couple out there that are common too).
Or, as an alternative, delegate the login to email and use a password-less login mechanism (effectively delegating the account security to the email's security). I argue this is actually more convenient, but some people (esp. young people?) have an aversion to email which i don't understand.
Therefore, backup codes are no less secure than that.
Uhaul does this and it’s maybe the only good I can say about Uhaul. I think the catch is that some people don’t use email (or much of anything) on their mobile phones. Most will get sms immediately wherever they are at. Not everyone uses email that way.
Maybe for some irrelevant social media site I can understand doing password-only auth because who cares, but this has your DNA on it. Even if the person who has all their personal information leak doesn't care, they fucked over their entire family. I guess that's not 23andMe's fault though because they were just satisfying a rational user aversion!
Not only that, but the aversion to using methods of logon other than passwords are less rooted in passwords being easy, and more in passwords being STANDARD. Passkeys for instance are faster to use than passwords. The ONLY thing that makes passwords "Easy" is peoples refusal to start using something better because of one-time switching costs and inertia.
Which is bad, obviously, but I think everyone is catastrophising it.
if they can’t take responsibility for it, then they’re too irresponsible to make money it.
it would be entirely reasonable for them to say “we don’t want anything to do with this data, we don’t want to profit from it, we don’t want to use it in anyway, therefor we will not retain it at all.”
babying the user by taking responsibility for the very data they profit from? unreal.
i would absolutely argue that having my
1) genetic ancestry,
2) full name,
3) date of birth,
etc… is sensitive information.
even removing genetic information, if a company is too irresponsible to catch millions of users info being stolen, then they’re too irresponsible to have that data.
again, either it’s important to your business or it isn’t. if it isn’t important, then refuse to store it.
> Not too different from services requiring 2FA
That is another practice I find awful for the above reason.
It's a virtue that a car continues to operate when all the warning signs and buzzers are going off; this means that the human in charge is left in ultimate control of the situation and there doesn't need to be any complex umbrella structuring of liability -- this allows a driver to safely drive away from a dangerous tidal wave/assault/lava flow/whatever even if their seat belt sensor is broken ; this is very important for numerous reasons.
If you think that means the company can be held liable, I'd honestly start leaking my information on the internet if I were you. You have millions of dollars of lawsuits to go win apparently.
If you don't think so, then I think you're beyond reprehensible, and so will the courts. There is no disclaimer that can protect you. Good gravy, this is the easy part.
> this attack could be done on literally any website. The issue is people re-used passwords, and also did not have 2fa enabled.
While possible to execute at scale on some websites, this type of attack tends to be quite loud on the receiving end once appropriate metrics are selected for monitoring and alerting.
> "We do not have any indication at this time that there has been a data security incident within our systems."
They should probably work on that, given that those systems were used to extract their customer's data, and that they only noticed when their customer's data was being sold.
Given how far behind they are on disclosure I'd guess they may have only found out from media inquiries.
It’s very simple, and I believe has been an accepted best practice since like 2017. This is 100% on 23andme. They are responsible.
They have a large set of different emails + passwords, and a large set of IPs.
Each IP can check a single set of credentials, so you never get a single IP in a short timeframe with too many login attempts, and never trying to brute force a single account. If the attacker rented time on the botnet for a long enough period, they can fly under the radar for quite a while. 23andme sees lots of failed logins, but no real way to pin it down.
reCAPTCHA would be the answer here. What's interesting/concerning is that it appears Google's reCAPTCHA (assuming 23andme was using it, and they should've been) was defeated.
I think for sensitive data where you want to protect the user, it makes even more sense to just generate passwords for them. It’s even simpler than 2FA. Some online casinos do this.
The thing that worries me more is the possibility that newer AI tools are allowing attackers to beat reCAPTCHA with automation. If that's the case, a lot of folks are going to be caught with their pants down.
Edit: looks like it's more than a possibility[1].
2FA, or passwordless logins, are the solution. Forcing the user to change their password (at the most inconvenient of times - right after they logged in, but before they're able to use the site) is annoying at best, and does nothing at worst.
You cannot claim that just because some users are 'saved' as evidence that this is an effective security measure, because if a password was leaked, and not discovered, then this measure doesn't prevent it. But it is imposing a cost, which cannot be measured against effectiveness.
Change the whole process to 2FA is secure because there's provable guarantees for the costs imposed, and therefore, you can make an objective decision on whether it is worth implementing.
> You cannot claim that just because some users are 'saved' as evidence that this is an effective security measure
Why not? Saving people from insecurities is almost by definition a measure of effectiveness
> you can make an objective decision on whether it is worth implementing.
You can't since the value factors in your "provable guarantees" and costs involved are subjective and also depend on the users' characteristics
no it doesn't. The claim is that by removing publicly leaked passwords, the user is prevented from having their logins stolen. But you didnt know if that password was going to be used for stealing - it's an assumption. You also dont know if private leaks are already being used, and is undetected.
It's the same type pf claim that the TSA (transport security authority) is saving people from terrorism.
But you do know for a fact that these leaked passwords are used for stealing, so forcing a password change would prevent that, ergo, save some users from having their data stolen. Private leaks have no impact on this
no, the passwords are revealed, but it might not be used for stealing. And passwords that are stolen but not revealed publicly will continue.
My point is that the site will force an update, but the user's quota of inconvenience is used up - therefore, a more effective measure such as 2FA will be seen as unnecessary by the user, and thus, lower the user's security.
This is why the solution is to not spend the effort/cost on trying to detect password leaks. It is to make 2FA.
So... basically exactly what the title says. 23AndMe says user data stolen in a credential stuffing attack.
The included one on macOS is hidden in some setting panel.
For non-technical people the best authentication method is probably their phone (Passkeys, or tokens sent to their email address).
It's not a solved problem, even if a rudimentary password manager is in most browsers.
Personally I don't know a single person outside of my tech bubble that uses passwords that you can't keep in your head, or write down on a piece of paper on their desk.
As it's not possible to remember n passwords for n sites, if one of them gets hacked "darn secure" isn't so secure any more. The main point of password managers is that you don't have to remember your password and if it leaks out on one site, it doesn't matter as it's only used on that one site.
As long as you stay in the Mac/iOS walled garden, you really don’t need to access the Settings page/app. Safari and most apps will happily pull the user/pwd from the manager for you. I’ve used for a few years now (after tiring of the mediocre UX of several other managers).