23andMe tells victims it's their fault that their data was breached
techcrunch.com
techcrunch.com
23andMe then claims that poor password practices are responsible for this data leak.
> “Therefore, the incident was not a result of 23andMe’s alleged failure to maintain reasonable security measures”
I've not run security at an org of their size, nor have i touched their service, but i have to imagine there were some patterns to this breach that would have been reasonable to account for ahead of time. Did those 14k accounts also have their email provider accounts compromised? Could a login ip-range check have prevented all of this? 2FA seems like an obvious answer here but clearly that was more than could be expected.
Nothing on 23andme’s end failed unless you consider someone using a correct user/pass combo while not being the owner as a fail on the part of 23andMe rather than the end user.
Maybe the email address on file is also cracked but it'll make it harder, and it's more work for the attackers.
Github is like that right now, and it's quite a pita; sure, it's not a great idea to continually delete all cookies without exceptions, but in some cases it's currently hard to avoid it (low-end smartphones where Firefox is too heavy)
> After disclosing the breach, 23andMe reset all customer passwords, and then required all customers to use multi-factor authentication, which was only optional before the breach.
As others have pointed out, there are also other options. Such as an email challenge when noticing high traffic, or damn, even when noticing a new login from a new device or IP that is unfamiliar. Many services do this all the time.
We’re talking about raw DNA data here that is accessible. You’d expect levels of security as implemented by banks if not better, not “Little Timmy’s first blog” levels of carelessness.
No, we’re not. Have you ever used 23andMe before?
For example if i proxy my connections through a VPS or VPN i will OFTEN either be outright denied access, or at best get sent to a validation step (most often they shoot the email an verification code that i have to plug in).
I will often route traffic through a linode for reasons. And sometimes use a VPN here and there (ie: mullvad). In almost all cases this will trigger anti-spam measures on sites, some so intrusive its borderline unusable (ie: Youtube and google with recpatcha).
Require MFA to be enabled when it's an issue of indirect access to personal data of potentially millions of other users on the site. Any retort like "okay well that might just hurt the platform's ability to attract users with that sort of security prescription," gets cement shoes in the bay. There's absolutely no reason to allow known dated forms of authentication to access user data of other 23andMe subscribers. Of course people are lazy and won't enable it if nobody is telling them they have to, most people are completely ignorant to how rampant these kinds of stories are because they don't subscribe to tech news. Somebody needs to be the adult and force people into the correct lane.
There are many security tools that use AI to identify patterns of access and alert on changes.
So, yes, something like this could be detectable.
Orgs with this kind of data will at least track geolocation and maybe device information and require proof despite a correct password as well as attempts to access multiple accounts from an address block. Many also incorporate the have I been owned leaked password database .
The have to act responsible when handling and caring for this kind of data. It’s irresponsible not to.
FFS, default to magic link login via email if you have to. At least then you're relying on Google, Apple, or someone else for auth (in most cases of unsophisticated users).
So how did 23andme fail so hard here? Literally nothing you've suggested would have prevented this.
> So how did 23andme fail so hard here? Literally nothing you've suggested would have prevented this.
They made MFA mandatory after getting popped, at the same time they changed their Terms of Service to attempt to evade liability. Why did they wait to get popped? Either negligence or an active decision was made to avoid support costs and engineering time for mandatory MFA was made. Also, a magic link I suggested would've solved for this, unless attackers were going to get into everyone's inbox with leaked creds to get the link to login and get that session token. Definitely more effort than credential spraying 23andme login endpoints.
https://techcrunch.com/2023/11/07/23andme-ancestry-myheritag...
https://blog.23andme.com/articles/enhanced-customer-security...
They are doing this because when they have high assurance of your identity (and your account hasn't been taken over), that is the best time to issue the cryptographic credential (the Passkey) which improves go forward security of the account. Over time, accounts should filter over to Passkeys, and at some point, they will likely deprecate passwords (or require high confidence you are you to login with just username and password, vs a Passkey). I've had a discussion with someone on the project at Google, and they could only say "stay tuned" about what comes next. To be clear, I'm not divulging anything beyond what Google made public in their blog post and a bit of speculation on my part.
> Do you think google is deactivating people based on HIBP? If not why do you think everyone else should?
TLDR "password resets and account lockouts vs deactivating users" and "because it is good practice to protect your users and their data from compromise"
[1] https://blog.google/technology/safety-security/passkeys-defa...
[2] https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
[3] https://security.googleblog.com/2019/12/better-password-prot...
[4] https://support.google.com/accounts/answer/98564?hl=en ("If there’s suspicious activity in your Google Account or we detect that your password has been stolen, we may ask you to change your password. By changing your password, you help make sure that only you can use your account.")
Other than allowing at least 14,000 login attempts from the same system without blocking suspicious activity. Nor using services like haveibeenpwned to prevent users from reusing passwords.
> Do they know about every breach out there without fail?
They know about a lot of them. I'd hazard a guess that at least three quarters of the affected accounts would have been in HIBP, probably far more.
A smart attacker would spread the logins out over a large number of devices and a long period of time to avoid detection.
That's an engineering fact. It would be good if it weren't true, just as it would be good if virtual memory were indistinguishable from RAM, but it just ain't so.
To be a responsible engineer, you've got to design and build for the real world, and that means not relying solely on username and password for extremely sensitive data.
This seems to be the big societal discussion, in the same way that people blame banks for them sending money to crypto and romance scammers overseas.
I think this would be far more akin to finding out someone has stolen a card number, which has happened in breaches, and used it to purchase a lot. Generally, we do expect recourse on the bank's end.
If someone gives their routing number and checking number to a scammer, that is also considered "using the platform in any way other than intended". In 99% of cases, you'd be providing that information to someone you had an actual business relationship with. My employer, for example, might have that info in order to process my direct deposit payments. A debtor may have that info in order to process ACH payments. Giving that info to a total stranger would be an issue but that wouldn't be the bank's fault. Neither would it be the bank's fault if you chose a poor or reused password.
That's what happened here. Users shared data with total strangers who requested their connection to their DNA data based on some percentage of shared DNA. Users accepted those requests. The users who reused their passwords had all their info accessible. The users who accepted sharing requests with those users had their shared info accessible. Both cases are "using the platform as intended".
Well not recognizing you have 14k logins coming from the same place, possibly with a lot coming from someplace else than the last login on the account, is definitely a failure on their part. That's why more and more websites send you emails to allow logins from a new location. Or have login rate-limiters (too many request from your network).
I wonder how easy it is to have the location (at least country) of a user from the breached data, to use bots in the appropriate country and evade "login from a new location" protections. I guess easy enough if whole accounts have leaked.
In 2024, if you want to access a highly sensitive database, you must be forced to setup MFA at the minimum. My opinion.
It seems the part where 14k leaked credentials provided access to millions of users data is where it becomes their responsibility. It means that people who were fully responsible still had their information leaked because of overexposure of the information.
We're talking about people who 'friended' others on 23andme, right? How is that responsible user behavior? I had an account with 23andme before I forced them to delete my data, which was not that difficult to do.
One of the things I remember was getting friend invites from random people who were distant cousins, and while I suppose that might be fun conceptually, I never did it because I didn't know any of these people. In what world does a "responsible" user who cares about their privacy add access to personal information, on a website that profiles your DNA, to people who are blood-related but still total strangers? I would call that highly irresponsible, personally. But that's just me, an idiot who avoided all of this by deleting my 23andme account half a decade ago.
14,000 users messed up. As a result, hackers were able to log in to 23andMe's computers as those users. (Is that the fault of those users? Absolutely.)
The hackers were able to use those logins to steal the data of 6.9 million users, approximately all of which did nothing wrong. How is that part not the fault of 23andMe?
>approximately all of which did nothing wrong
They shared some of their data with the users who messed up. All of their info wasn't accessible. The only data that was accessible was the data that was shared with these users - in other words, opting in to sharing data with total strangers (which could be argued but is the #1 use case for 23andMe).
So if you want to let user A share info with user B (and as you say, that's likely an essential use case for 23andMe), then 23andMe either 1) cannot let user B mess up, 2) cannot let user A share with user B, or 3) cannot protect user A.
Of those options, 1) is impossible, though they could perhaps have done more to make it harder. 2) ruins a major use case. That leaves 3)...
While there could be a raft of IPs working in concert, there should be enough commonality to simply be an annoying target, black-holing IPs that attempt more than a couple times.
Maybe they could have detected the exfiltration, but maybe they couldn't. If the hackers were smart they would have properly distributed the calls and rate limited to avoid detection.
>effective access to 6.9 million accounts
The relatives feature lets you -- if you opt in -- see your DNA relatives and their very basic details, and vice versa. I have literal thousands listed, and those thousands, all over the globe and of mostly minuscule relations, can see mine. That really is being a bit overwrought as a facet of this.
I have no idea of the actual sophistication of the attackers here though: It's way too common to see big companies that have paid no attention to prevention, and therefore will only notice an attack if it becomes an accidental denial of service attack. Maybe 23andme are sophisticated and only the worst shared passwords got breached, or maybe they have minimal security.
- Did 23andMe enforced a strong password policy during the account creation with X minimum and combination of chars with complexity meter?
- Did they send a periodic reminder about account security, update passwords, secret questions and the likes?
- Did they enforce the 2FA?
- Failed authentication attempts count?
And those on top of my head, NIST, PCI and other standards have more details about those, in fact, the security level should be provided by such services should pass more than the “standards”, as once these data are leaked, you won’t be able to change it, so blaming that in the users shows the lack of accountability, glad I never trusted my DNA in any of these services.
(And yes, 2FA is the only real answer here, preferably YubiKeys to also defeat phishing)
How many computers do you use normally? How hard would it be to link them to your accounts?
I use private browsing exclusively, so, I’d hope that’s difficult link to me reliably.
[0] https://www.theguardian.com/technology/2023/dec/29/google-la...
Literally every time I pay for something via PayPal on my computer, I need to pull out my phone, find the authenticator app, open it, scroll to PayPal, tap it, see if there's enough time for this code or if I should wait for the next one, type the 6 digits into the site...
I mean it takes half a minute, and this easily gets repeated several times a day if you engage in a lot of transaction-type things. And it's no faster if it's by SMS or by e-mail because I'm still spending 15 seconds waiting for the message, and then opening it, typing, then going back to delete the message so it doesn't clutter my inbox -- half a minute total again.
Tangentially, I really wish authenticator apps continued to show the previous code for 30 seconds so I can continue to refer to it for apps that don't allow copy and paste.
In my experience on most services (not sure about paypal specifically) there's a grace period where a code that just 'expired' is still valid for another ~10-30 seconds? So... at least you can skip that part.
I haven't tried PayPal specifically, but websites will usually still accept the previous code for at least a few seconds after a new one rolls over
I wish I could just put my phone on an NFC reader when a site requires 2FA, and then all I have to do is to confirm on the phone itself.
My account (now removed) relied on a long, unique, generated password + Apple SSO. I don't see how I could've made my 23andMe account more secure (I'm in the 6mm pool of users, not the original 14k).
It's not the only answer. You can also use tools that detect and reject insecure passwords, integrate with HaveIBeenPwned to force-roll passwords that have been previously compromised, etc.
2FA would solve a lot of the problem, but it's not the only option that could have mitigated this.
Mandatory 2FA is sufficient, but not very user-friendly.
Ideally MFA should be based on the accounts / sessions risk and not mandatory
And I agree that mandatory 2FA isn't a good answer either. As someone who uses long, random passwords on all websites, I like to be able to choose whether to add 2FA on top.
I didn't say it was sufficient to prevent this. I said it was another tool that would have mitigated some of this (and which presumably 23&Me did not implement).
This is a serious HIPAA violation not just a security breach. This defense of theirs isn’t a smart strategy if they want to stay in business not to mention the impending lawsuits.
*edit* forgot the link
[1] https://www.ftc.gov/business-guidance/resources/complying-ft...
[2] https://www.ftc.gov/legal-library/browse/rules/health-breach...
Most people misunderstand HIPAA, and think it applies in situations it doesn't. This is not a situation where HIPAA applies.
HIPAA is NOT a privacy law. It's a law that mandates portability of medical data, some details of which overlap with privacy.
- https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7883355/
So while 23&me is not under HIPAA compliance rules, they are still under the purview of the FTC according to this. Which would mean that the FTC can examine their security posture and determine if it's adequate or what have you. Odds are they will just be slapped with a fine and back to business as usual. Which kind of makes me upset because we are dealing with DNA and ePHI whether they are HIPAA or not.
For some kind of admin account with privileged access to other users' data, then it definitely affects others.
One might expect increasing mandatory security measures correlating with increased potential damage of a breach. Similar to safety measures on mass transit vs. personal vehicles.
I’m sure most people on HN have great passwords stored in password managers, but 99.9% of users are not like that, so mandatory 2FA does not only make sense, it’s the only reasonable choice for sensitive information.
The company was originally founded on unreasonable goals in the health industry, using DNA array testing to identify risky variants in individuals to help produce better treatments.
It took the CEO about a decade to learn enough to acknowledge that their approach would never have achieved this, because the mapping from genome to risk/treatment is a highly complex function and their mechanism was underpowered and they also repeatedly pissed off and ignored the FDA who then shut them down for a while. The only reason they survived this was, afaict, the CEO's ability to extract money from google to keep operating.
Eventually, the company found that they could do identity by descent really well, much more useful to customers than telling them their earwax properties, and their "recreational genomics" products were extremely popular- enough to sustain a service, but not really enough to sustain advanced research.
They finally got some pharma to give them a bunch of money for their data (basically all the genomic and phenotype data that they collected on their users) ostensibly to do translational health research, but this has not been very productive (and seems unlikely to be truly transformative).
In the meantime they have to keep runing their consumer platform and it clearly had security issues that permitted a large scale data extraction (that's on them, not the customers) and I jusrt can't see how they keep getting money to operate, because their track record in translating data to profit/medicine has been so skimpy.
My doctor scoffed at 23andme finding a dangerous genetic mutation and said its probably just a false positive. I had to spend $500 to get a single gene tested in a hospital, still came out positive.
So bang for your buck that $99 was a great deal for a full mapping, it feels like most of their issue is what the government allows them to show. Im pretty sure that SNPedia syncer isn't online anymore, but that was what made 23andme a great service for me
My DNA was also scanned[1] and saved by a hospital before having my first child - as most people with my heritage do. So thats 3 times in my life I did genetic testing. Which one is more prone to be hacked - Mount Sinai, LabCorp, 23andme? Who knows
[1] https://womenshealth.labcorp.com/providers/carrier-screening...
They shouldn't scoff at it, but getting a proper test before any treatment or major changes is still the right thing.
I had my blood taken and a whole genome sequence- a 50GB file of reads off the machine, along with variant call files that should show how I differ from the reference genome, and another variant file that called out risky variants. You can download the files (https://my.pgp-hms.org/profile/hu80855C).
When you did UYG you'd go to this fancy spa in La Jolla and they give you an iPad with the files and you also talk to some genetic counselors.
I made a number of interesting observations when talking ot the counselors. The first is that they said they were confused by my report because it said I had absolutely no known risk variants (apoe, bcl, etc) and they had never seen that before. They also said, when they see some rare v ariants that they would just google for the variant and read random papers. What they said convinced me that genetic counselors, and genome tests in general, have limited applicability- there are a few genes where variants are clearly associated with negative disease outcomes, and the tests for those are very valuable (This is especially true for cancer, but other diseases as well) because they are clinically actionable.
But it also showed to me that counselors are making up garbage, because scanning the raw literature for variants and assuming that because a person has that variant they will be at risk, is not a good assumption. In my mind, the variations on polygenic risks scores have convinced me that we need to build large-scale (whole-genome) models of disease that use nonlinear functions trained on extremely large-scale datasets (like UKBB) to build up wholistic predictive models that do a better job of encapsulating the complexity of biology and its relation to disease, to the point where we can actually start making useful treatments and cures for a wide-range of genetically determined diseases.
This is exactly where AI is going in the biomedical space. However, there's more than just the genome, you need to integrate multi-omics and some of the necessary tech hasn't been invented yet.
IBD is pretty reliable and it tends to get better over time (hence the late-arriving signal of french ancestry). I don't understand the "lack of transparency" and the accuracy comment you made: they didn't have the knowledge before, so presumably they reported "european" rather than a wrong country?
So basically a little family of people who wanted to see the company succeed. I think they've been given their time to succeed and at best, have reached a sort of steady state where they are not going out of business, but also aren't achieving the interesting mission they were based on.
Our main healthcare "privacy" law in US, HIPAA, is structured to protect insurance firms' right to our private health data (while otherwise sensibly restricting access to it). It is not a given that private finance firms ought to have legally protected, virtually exclusive access to our sensitive health information, but they do in America. Facts like this make me skeptical that GINA was written and is enforced in good faith.
Sorry but you have no idea what you are talking about. Big corporations are absolutely terrified of accidentally using health data illegally, no insurance company in the US would touch this with a 10000 foot pole.
On the other hand, 23andMe should have definitely done much more to reduce the blast radius of this attack. Mandatory 2FA, disallowing known-compromised passwords, geolocation of login IPs, etc.
I guess the question shakes out to: where do we draw the line on personal responsibility vs. service responsibility? Services can't be responsible for 100% of user security. But they also can't be negligent in their own security and mitigations.
23andMe could have done a better job communicating the risks of sharing your data with random strangers on the internet, but it's also not unreasonable for them to put some level of blame on users. If you wanted to treat that information as secure, you shouldn't have opted in to sharing it with an arbitrary number of strangers.
If 23andMe had made any claim that they took steps to force users to secure their accounts properly or that they implemented measures to prevent data exfiltration then perhaps you could argue that you should have been able to rely on those claims, but as far as I can tell 23andMe made no such claims.
Legally, logically, and ethically this is an absurd argument on its face.
Also, the turfer comment makes you seem like a conspiracy theorist. There’s nothing untoward or off about the replies you’ve received so far that is off enough to suggest astroturfing.
We can argue about whether the office building should have had better security and noticed weird people around, but ultimately it's the accountant's negligence that allowed my info to be compromised, and if I suspected they weren't the best with their security, I should have factored that into who I decided to share my info with.
The only way you’d be affected by this is if you used the same password on multiple sites (where one of those sites actually had a breach) or if you shared your DNA profile (since it is opt-in) with someone that reused passwords. In the latter case, only the info you shared with that person would be accessible to someone using a compromised account.
In other words, if you shared your info with someone you didn’t know and didn’t trust, your info can be used by bad actors.
I think this is why we were all so surprised when Venmo took off in popularity, with everybody's transactions made public by default...
So while I agree with you that those users are not responsible for the accounts that were actually compromised, they were fully responsible for sharing their data on that service without fully thinking the implications through. 23andMe is not blameless--it's their poor security controls that allowed it to happen in the first place--but I strongly feel people do not take security and privacy as seriously as they should and as a result do share at least some of the blame.
Password rotations are dumb and do not improve security.
NIST, Microsoft, etc. didn't decide to change their minds (to now explicitly discourage arbitrary expiration) out of the blue.
See:
https://web.archive.org/web/20180603140100/https://www.cs.un...
>Using this framework, we confirm previous conjectures that the effectiveness of expiration in meeting its intended goal is weak.
Also see:
https://people.scs.carleton.ca/~paulv/papers/expiration-auth...
>in sum, these security-specific observations and the results in Section 3 suggest the security benefit of password aging policies are at best partial and minor. Combining this with the well-known and widely experienced (negative) usability impact of password aging policies, and results [18] mentioned earlier on high predictability of new passwords from knowledge of old, the burden appears to shift to those who continue to support password aging policies, to explain why, and in which specific circumstances, a substantiating benefit is evident.
And:
https://discovery.ucl.ac.uk/id/eprint/20247/2/CACM%20FINAL.p...
>Although change regimes are employed to reduce the impact of an undetected security breach, our findings suggest that they reduce the overall password security in an organization.
There have been several more, and I'm sure that NIST and others did their own additional analysis prior to changing their recommendations which may not have been made public.
It's like Cambridge Analytica- each compromised account let them dump data for hundreds to thousands of people
And you opted-in to share your DNA data.
But yes, the entire business model of 23andMe makes me uncomfortable. But it's a bit removed from the password security stuff I wanted to focus on, especially as the password security stuff is applicable to any type of service.
I call BS. If the service thinks the user's password is acceptable to perform authentication, how should a user know they are actually wrong about that?
Either it is flawed, and therefore the service's job to catch, or it is acceptable. But the service doesn't get to say afterwards "haha, that was really dumb of you, you should have used a stronger password".
You are missing the category of attack that happened here.
The password was acceptable. But the users used the acceptable password on multiple websites. A different website was breached, and the password was leaked.
It is not 23andMe's responsibility to check if other services are breached, cross-reference the users in that other service, get the leaked password list, and then see if those leaked passwords are currently in-use on their website on accounts that are used on both sites.
However, as noted in my top-level comment, they should be checking against known-compromised passwords at password creation/change time, and disallow those.
To play devil's advocate here, why not? Plenty of companies (e.g., Tumblr) specifically do this and require email verification + password change if yours was breached.
It would make the world a better and more secure place if companies took proactive security measures. There is even a financial incentive for them to do so because it mitigates risk.
I _absolutely_ agree. I just do not think it is possible to require every company to monitor every data breach, check those breaches for emails that are in-use on their service, check the passwords (not always possible), and then require a change if the password matches.
>Plenty of companies (e.g., Tumblr) specifically do this and require email verification + password change if yours was breached.
You're saying that if HackerNews was hacked and my password was leaked, that Tumblr will ingest the breach data, cross-reference if I have a Tumblr account, and then have me change my Tumblr password? Are you sure? Do they have a documented process on how they do this?
Edit: I've spent some time now looking at the Tumblr website and do not see any indication that they do this, but would be happy to be corrected. Or a link to any company that does this, it doesn't need to be Tumblr.
But other that that, I ... kind of agree with 23AndMe: users should be primarily responsible for their own accounts. I don't like the "assume all users are blubbering morons and treat them as such" security model, and then blame $corp for treating their users as adults. Again, 23AndMe could have done better, maybe, but I strongly disagree that they're primarily responsible – at best they're partly responsible.
And maybe 23AndMe also could/should have pushed 2FA harder, I don't have an account so don't know how hidden this feature was or not. All I know is that mandatory 2FA is a right pain for me, adds basically no security for me because I just store it in my password manager next to the password. For TOTP it's just an inconvenience, but I really dislike phone-number based 2FA – I've been locked out so many times...
I'm skeptical that 6.9 M users opted-in to an off-by-default setting. That seems absurdly high for any opt-in feature that involves nebulous user value. I don't use 23andme, but I'd love it if someone had screenshots of this supposed "opt-in" before the data breach.
Also, how far does the sharing go? How far removed from a family member does a user have to be to see their info? Going from 14k to 6.9M seems like it must have been more than just immediate family, given the small family size common today.
They have ~14M users total, so this is 50% of them opting in. That seems entirely reasonable.
They didn't, unless I'm misunderstanding. They just got some names and a number indicating the degree of genetic similarity or something like that, right?
The opt in is a prompt presented during onboarding with language that mainly focuses on “connecting and “exploring” who you’re related to.
The prompt is similar in mobile but here[0] is a screenshot of what it looks like on the web.
The fine print talks a little about what you’re sharing.
Where the lie comes in is that after selecting “Get Started” it also automatically enables sharing your ancestry report and the other default privacy settings are very permissive and work on an opt-out basis.
If doesn’t, for example, then give you through the settings and asks what you want to share. It enables everything by default.
0: https://int.customercare.23andme.com/hc/article_attachments/...
Looking at mine, it shows me 4th cousins and closer. So way more than immediate family.
The user value isn't nebulous. If you are curious about your ancestry, you might also be curious to see what people you discover or see if your family tree is your real family.
Why people don't get that TOTP is just "strong unique password" you can enforce from the service provider side is beyond me.
1. Fraud detection on the metadata like IP address, access timing, access patterns etc. eg: Why is a person from UK logging in from China IP?
2. IMO orgs should be importing and refusing known leaked credentials and the top 1000 passwords. This could happen both at password set time ("You cannot use that password as it's a known leaked credential, click here for more info about the breach"), or at login time "You're using a leaked credential, please follow the password reset flow".
And then we get to the other side of this where people get locked out of accounts because they went on vacation and bothered to check their email.
And often times these "person from UK logging in from a China IP" are massively wrong. For the longest time my home IP was showing up as from another country in most GeoIP databases. They're routinely trash.
I assume most people are the same.
Therefore, I'm not sure what significant information an attacker could have gotten on me. Anyone care to enlighten me?
Which is probably mostly already pretty discoverable through public records, obituaries, and genealogy sites.
It's not like 23andMe is telling you that your third cousin has some specific genetic risk for a disease, right?
So… about that: https://ibb.co/hRmgRQy
Edit: Keep in mind the default is “Yes”
This is someone who tried to connect with me and it says.
"By connecting you will be able to explore each other's personal and genetic information, which may reveal surprises. Learn how sharing works."
And if one clicks on the learn link, one sees.
"Establishing a sharing connection on 23andMe allows users to view one another's profile names and information (including profile sex), information from compatible reports, your predicted relationship, and the number and location of overlapping DNA segments. A sharing connection does not allow either person to search or download the other person's raw data, access their DNA Relatives list, or if applicable, view reports that require an additional consent, or view and download the other person’s Reports Archive."
I never established any sharing connections and assume the same for most.
Blocking the credential stuffing attacks? They probably did have mitigation efforts, but you can only be so aggressive before the false positives start blocking significant numbers of legitimate customers, who have no recourse except to wait out a temporary ban. And some credential stuffing attacks are extremely sophisticated, such that even best in class security companies can't always effectively block them.
Mandatory MFA? Great on paper, except that 10% of people hate the extra steps (probably with great overlap between the people reusing passwords) and will complain and/or disable it if given the chance. Another 20% have invalid or out of date contact details (an old employer's email address, a landline phone number that can't receive SMS, etc.), and they'll be locked out of their accounts.
Yeah, there are ways to mitigate these downsides. And I'm not arguing that 23andme found the appropriate balance between "customer satisfaction" and "customer security." But I can see how a mostly reasonable organization could end up in this position. And it's mainly the risk of terrible press and upset customers that allows other companies to justify more security-oriented policies, so let them have it.
23andme is also unique in their ability to create security questions to authenticate users who get locked out. "What is your date of birth and can you form a sideways U shape with your tongue?"
This is data that appears in the ancestry data for the 14 000 compromised accounts. Your data only appears in another account's ancestry data if you opted in to sharing ancestry data and they are a relative of yours. I think most people opt in, because (1) finding out about your ancestry and relatives is one of the main reasons people use services like 23andMe, and (2) even people who started using it just for the health data often get curious and start using the ancestry stuff too.
23andMe counts anyone who is a 4th cousin or closer as a relative, which results in some big relative lists. Mine has 1500 other 23andMe users in it, but that might be above average. Based on 23andMe having 14 million customers, 14 000 accounts being compromised, and 6.9 million accounts having data taken via the relatives lists of those 14 000 compromised accounts, and assuming that everything that I don't have any data on is is pretty evenly distributed (the statistical equivalent of a spherical cow) I'd guess that the average is around 700.
If that's even in the right ballpark then when you opt in to sharing this data you are opting in to share it with several hundred people, mostly complete strangers to you, mostly scattered all over the US and a few foreign countries.
At that point I'm not sure if the different between just sharing it with them and sharing it with the world is meaningful.
to me, the takeaway is that we need to roll out passkeys as quickly as possible.
(1) the bar to do better is quite a bit below "best practices".
Not only that but they're should have been far better protected against even poor password management by users given the type of sensitive information they're handling.
23andMe's argument seems ridiculous on its face.
It is your job as a service provider to not allow access to anyone but the authorized user, how you do it is an implementation detail. You can't throw up your hands and say "well we decided that doing that is too hard so we're defining the authorized user as anyone who knows the password."
How would they know this?
The only way they could have not known is if they failed to employ or consult with the appropriate professional expertise in this area.
Gashibyu@gyoryana3: is that recycled, or freshly minted?
> This password wasn't found in any of the Pwned Passwords loaded into Have I Been Pwned. That doesn't necessarily mean it's a good password, merely that it's not indexed on this site.
But I doubt it's a common practice to do this kind of check.
> literally thousands of other services doing everything from providing their own password checker through to checking their customers' passwords on every registration, login or password change to see if it's previously been breached
(https://www.troyhunt.com/open-source-pwned-passwords-with-fb...)
The check has low value.
HaveIBeenPwned only provides value when it positively informs about a pwned password, otherwise it says nothing useful.
If you're already rejecting weak passwords using some heuristics, then the remaining passwords are unlikely to show up on that site, because, strong passwords are unlikely to be pwned, even if reused and subject to a breach.
sn*wfl@ake1Every single password that's ever been leaked should not be used by anyone ever again.
If "Yes," then you have shared users who are reusing passwords.
On the other hand, I remember thinking ten years ago or whatever: "23AndMe sounds cool, I'd love to know about my ancestry and genetic risk factors, but that's a crazy amount of intensely personal data to trust a corporation with, so I guess I won't do that." And I'm as dumb as a rock, so if I made that decision with the same information as everyone else, it must have been pretty obvious what the consequences could be.
Any kind of storage is a non-starter.
(but also re 'whole point', not sure about split btwn people who want their own genetic profile vs searching for long-lost twin)
See: https://whoareyoumadeof.com/blog/need-a-dna-centimorgan-char...
> 6.9 million accounts had information stolen because they were "relatives" of 14,000 users? Something doesn't add up there.
It adds up. The key is that for the attackers to get my data they only have to compromise 1 of my 1500 relatives.
14 000 out of 14 000 000 accounts were compromised, so 1 in a 1000.
In other words the attacked has 1500 chances to roll a 1 on a d1000 if they want to get my data. The probability they can do that is 1-(1-0.001)^1500 which is 0.78.
If everyone had about as many relatives as I do, we'd expect the attackers to get data on nearly 11 million people from those 14 000 compromised accounts. Getting "only" 6.9 million suggests that on average people have a little under 700 relatives.
This is a tough population to increase the security for. They are highly vulnerable to social engineering, reuse passwords, use weak passwords, and struggle mightily with 2FA or other methods. But that's the gig, it's on 23andMe to solve it.
https://ia904506.us.archive.org/10/items/gov.uscourts.cand.3...
Almost all of them are in N.D. Cal but there is one filed in N.D. Ill. and one in C.D. Cal.
In all honesty, you can hardly make this claim unless they properly communicated and mandated (at least in writing, since I can't imagine how it could be actually enforced) that users chose/pick passwords different from other platforms. Or at the least enforce an aggressive password change schedule, etc...
You can check passwords against known-compromised lists and then tell the user "sorry, please use a different password". This is something that is a recommended best practice, and has been for at least a few years.
>Or at the least enforce an aggressive password change schedule
This has been explicitly not recommended since at least 2016 by NIST. Research has shown this leads to password fatigue, which results in weaker passwords that are just iterated on (password1 -> password2 -> password3).
I would have never guessed people would be interested in such useless information.
But 23andMe's cutesy haplogroup classifications, their faux historical narratives, the ridiculous litany of "health conditions" they warn me about, it's bunk, 100% bunk. Plus, no medical professional will accept this data as diagnostic, so why bother?
The data breach by which attackers get their hands on passwords isn't the fault of the users.
Only the consequence of that breach to some of the users is their own fault.
Much like Uber, self-enshitification was obviously the "???" part of the underpants gnomes' plans.
I mean. If people reused passwords for 23andMe, is this really 23andMe's fault? Should they have required 2FA for everything? That's kind of a hard sell tbh.
They could've blocked source IPs making all the login requests, but that was probably being changed to not set off alarms. However, there wasn't enough information in the article to go on, but since they suffered so many breaches of user accounts, they probably had to do something wrong. I'm too busy to dig into the specifics.
If an attacker works off lists of compromised usernames and passwords from various sites, for a given user there's always a chance that the first one they try is correct. Especially for the kind of user who recycles the exact same password on 50 different sites. (Incidentally, you should probably try to hack that kind of user first, and for each user, try their most-recycled passwords first.)
Additionally, they don't support 2FA/MFA which of course would mitigate some of the risk of password re-use.
There's plenty of things they could have done to prevent this breach.
Imagine you are a company with great password practices, how would you tell that a user re-used a password that was exposed in some other data breach without you being able to generally know what a user's password is? Well, of course, it's the same way that you verify their password when they login. You track (or more likely in this case, adhoc check) data breaches, when you find a matched email in the breach with one of your users, you check if the password from the breach would allow that user to login.
[edit]: there are other obvious heuristics that could have detected it, it does show they had either very basic or no intrusion detection, which, for a service of this nature, isn't really acceptable
Absurd that they thought that we'd miss this part of the sentence.
If an average online gaming service or social network can manage sending 2FA codes over email or SMS when their users are logging in from a new device, the holder of a large chunk of the world's genetic data can as well.
Yes absolutely. If it were one account being compromised due to the user reusing a password, that would be the user's fault. But what happened is credential stuffing, and that is absolutely something a professional IT organization should be prepared to defend against.
I don't care if something like GDPR states they must. I do not trust corps to actually go through the hassle/expense of it.
> After disclosing the breach, 23andMe reset all customer passwords, and then required all customers to use multi-factor authentication, which was only optional before the breach.
Add in all the people who struggle to use 2FA of any kind. At my first employer, I was there when they implemented it and it basically destroyed an entire week of productivity as so many people struggled to grasp how to set up a token in the authenticator app and use the token. I would be curious to know what the stats are on how 2FA impacts use and churn of users.
Ultimately, companies like this are making the choice of information safety vs profits - it’s a tale as old as the free market.
[0] https://www.washingtonpost.com/technology/2023/10/12/23andme...
[1] https://customercare.23andme.com/hc/en-us/articles/212170688...
> 23andMe and the contracted genotyping laboratory will retain your Genetic Information, Date of Birth, and sex as required for compliance with legal obligations, pursuant to the federal Clinical Laboratory Improvement Amendments of 1988 and California laboratory regulations.
> 23andMe will retain limited information related to your data deletion request, such as your email address and Account Deletion Request Identifier, as necessary to fulfill your request and for the establishment, exercise or defense of legal claims.
And that's why I don't use 23andMe, even though I'm quite interested in the product and was super tempted to buy. Just because it's not future-proof, and that's a deal breaker.
If you know of a DNA sequencing service that can do its job, send the result, then destroy every sample and every bit of information they had (save, possibly, for the payment receipt), please let me know. Don't care about ancestry, relatives and other social stuff, just the raw genetic data.
Luckily I’m also in the NIH All of Us program and they’re at least better about data safety (for now?).