Nothing on 23andme’s end failed unless you consider someone using a correct user/pass combo while not being the owner as a fail on the part of 23andMe rather than the end user.
Nothing on 23andme’s end failed unless you consider someone using a correct user/pass combo while not being the owner as a fail on the part of 23andMe rather than the end user.
Maybe the email address on file is also cracked but it'll make it harder, and it's more work for the attackers.
Github is like that right now, and it's quite a pita; sure, it's not a great idea to continually delete all cookies without exceptions, but in some cases it's currently hard to avoid it (low-end smartphones where Firefox is too heavy)
I sympathize, but at a certain point if you've gone out of your way to disable the features that the developers have added to make your life easier, you just don't get to complain about it.
You don't even need to rely on the cookie if you're worried about the ux for cookie clearers. You could also whitelist an IP address (or even a subnet) when they verify the email, and it would have been "good enough" to prevent this particular situation.
Personally I’d rather be a little bit annoyed when I log in to my account than have my DNA stolen or whatever.
> After disclosing the breach, 23andMe reset all customer passwords, and then required all customers to use multi-factor authentication, which was only optional before the breach.
As others have pointed out, there are also other options. Such as an email challenge when noticing high traffic, or damn, even when noticing a new login from a new device or IP that is unfamiliar. Many services do this all the time.
We’re talking about raw DNA data here that is accessible. You’d expect levels of security as implemented by banks if not better, not “Little Timmy’s first blog” levels of carelessness.
No, we’re not. Have you ever used 23andMe before?
They’ve temporary disabled it due to this data breach, but you were able to download your raw data[0] and then use it as you see fit.
I, for example, downloaded mine and used OSGenome[1] to crawl through it and parse it as well as Promethease[2].
So maybe save your downvote next time until you know what you’re talking about.
For another, I got the threads confused and thought you were talking about the accounts that shared access with compromised accounts. Sorry. Relax yourself before you jump to immediately into your persecution complex.
Fair point.
> For another, I got the threads confused and thought you were talking about the accounts that shared access with compromised accounts. Sorry. Relax yourself before you jump to immediately into your persecution complex.
Apology accepted. Perhaps it might be wise to dial the snark down a bit, regardless of if you’re confusing threads or not. It ads little to the discussion at hand and only elicits replies with a similar tone.
For example if i proxy my connections through a VPS or VPN i will OFTEN either be outright denied access, or at best get sent to a validation step (most often they shoot the email an verification code that i have to plug in).
I will often route traffic through a linode for reasons. And sometimes use a VPN here and there (ie: mullvad). In almost all cases this will trigger anti-spam measures on sites, some so intrusive its borderline unusable (ie: Youtube and google with recpatcha).
Require MFA to be enabled when it's an issue of indirect access to personal data of potentially millions of other users on the site. Any retort like "okay well that might just hurt the platform's ability to attract users with that sort of security prescription," gets cement shoes in the bay. There's absolutely no reason to allow known dated forms of authentication to access user data of other 23andMe subscribers. Of course people are lazy and won't enable it if nobody is telling them they have to, most people are completely ignorant to how rampant these kinds of stories are because they don't subscribe to tech news. Somebody needs to be the adult and force people into the correct lane.
There are many security tools that use AI to identify patterns of access and alert on changes.
So, yes, something like this could be detectable.
Totally fair, I haven't been following this really closely.
That being said, if someone re-uses passwords once they probably do it a bunch of times, so it's odd to me that they didn't have a process to detect reused passwords and force a change.
Orgs with this kind of data will at least track geolocation and maybe device information and require proof despite a correct password as well as attempts to access multiple accounts from an address block. Many also incorporate the have I been owned leaked password database .
The have to act responsible when handling and caring for this kind of data. It’s irresponsible not to.
FFS, default to magic link login via email if you have to. At least then you're relying on Google, Apple, or someone else for auth (in most cases of unsophisticated users).
So how did 23andme fail so hard here? Literally nothing you've suggested would have prevented this.
> So how did 23andme fail so hard here? Literally nothing you've suggested would have prevented this.
They made MFA mandatory after getting popped, at the same time they changed their Terms of Service to attempt to evade liability. Why did they wait to get popped? Either negligence or an active decision was made to avoid support costs and engineering time for mandatory MFA was made. Also, a magic link I suggested would've solved for this, unless attackers were going to get into everyone's inbox with leaked creds to get the link to login and get that session token. Definitely more effort than credential spraying 23andme login endpoints.
https://techcrunch.com/2023/11/07/23andme-ancestry-myheritag...
https://blog.23andme.com/articles/enhanced-customer-security...
There are lots of commenters here on HN in this story saying they don't think sites should make 2FA mandatory. There are lots of usability problems with 2FA as well -- if you lose a device or when traveling.
You're basically saying that sites that allow you to log in with just a password, if you choose, shouldn't be allowed to exist. That seems unreasonable to me.
I'm saying sites that host information of value, such as genetic information, should not be allowed to support login with just a password. That seems reasonable to me, and a regulatory gap to be closed. If you don't want to use MFA or other secure auth systems on Reddit or Twitter, by all means, I'd agree that secure auth for low value systems might be overly burdensome to a user population. There are well worn paths if you lose MFA (remote identity proofing, mailing an OTP to known addresses, dinging a credit card $1, etc) that are all reasonable and affordable to implement.
Is your argument that the data 23andme hosts is not of value or sensitive and it should not matter if their security story is lacking ("just passwords are fine, yolo")?
EDIT: I think we fundamentally disagree on the issue.
But that isn't obviously reasonable to me, that we need a law for that.
What if I don't think a bunch of estimates based on a bunch of my gene readings is all that valuable? Why not let me choose to use just a password?
But if I do think it's super valuable, then I can use 2FA. (And also obviously choose not to share any of my information with anyone else on the site.)
Why should it be the government's job to remove that choice from me?
And since this is a specific access pattern for 23andme, I agree we shouldn't involve government here.
They are doing this because when they have high assurance of your identity (and your account hasn't been taken over), that is the best time to issue the cryptographic credential (the Passkey) which improves go forward security of the account. Over time, accounts should filter over to Passkeys, and at some point, they will likely deprecate passwords (or require high confidence you are you to login with just username and password, vs a Passkey). I've had a discussion with someone on the project at Google, and they could only say "stay tuned" about what comes next. To be clear, I'm not divulging anything beyond what Google made public in their blog post and a bit of speculation on my part.
> Do you think google is deactivating people based on HIBP? If not why do you think everyone else should?
TLDR "password resets and account lockouts vs deactivating users" and "because it is good practice to protect your users and their data from compromise"
[1] https://blog.google/technology/safety-security/passkeys-defa...
[2] https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
[3] https://security.googleblog.com/2019/12/better-password-prot...
[4] https://support.google.com/accounts/answer/98564?hl=en ("If there’s suspicious activity in your Google Account or we detect that your password has been stolen, we may ask you to change your password. By changing your password, you help make sure that only you can use your account.")
Did you even look at their provided links? You took the time to create a new account, why not actually look at the provided links to see what is being claimed in the first place?
I highly doubt you read the link, otherwise you wouldn’t have gone through the whole sign up process just to prove something isn’t a “default” according to you. You’d have just referenced the article and made the exact same point.
Other than allowing at least 14,000 login attempts from the same system without blocking suspicious activity. Nor using services like haveibeenpwned to prevent users from reusing passwords.
> Do they know about every breach out there without fail?
They know about a lot of them. I'd hazard a guess that at least three quarters of the affected accounts would have been in HIBP, probably far more.
HIBP only knows about breaches that are made public. Based on the current evidence, this was not a breach that was made public. It was a breach being sold.
How would you detect that these requests are coming from the same "system?"
A smart attacker would spread the logins out over a large number of devices and a long period of time to avoid detection.
> The term computer system may refer to a nominally complete computer ... or to a group of computers that are linked and function together
The only thing that I added was "that are distinguishable" because you implied that the server ought to be able to tell that this is a coherent attack by a single system and not just normal traffic from unrelated systems.
If victim hosts do not have enough information to recognize the disparate computers as part of a botnet, then from the perspective of the attacked host the computers are separate systems.
I try to assume that people are interacting in good faith, but it's getting very difficult. Have a nice day!
That said, I'm shadow banned so you should probably ignore my advice on HN guidelines.
That's an engineering fact. It would be good if it weren't true, just as it would be good if virtual memory were indistinguishable from RAM, but it just ain't so.
To be a responsible engineer, you've got to design and build for the real world, and that means not relying solely on username and password for extremely sensitive data.
This seems to be the big societal discussion, in the same way that people blame banks for them sending money to crypto and romance scammers overseas.
I think this would be far more akin to finding out someone has stolen a card number, which has happened in breaches, and used it to purchase a lot. Generally, we do expect recourse on the bank's end.
If someone gives their routing number and checking number to a scammer, that is also considered "using the platform in any way other than intended". In 99% of cases, you'd be providing that information to someone you had an actual business relationship with. My employer, for example, might have that info in order to process my direct deposit payments. A debtor may have that info in order to process ACH payments. Giving that info to a total stranger would be an issue but that wouldn't be the bank's fault. Neither would it be the bank's fault if you chose a poor or reused password.
That's what happened here. Users shared data with total strangers who requested their connection to their DNA data based on some percentage of shared DNA. Users accepted those requests. The users who reused their passwords had all their info accessible. The users who accepted sharing requests with those users had their shared info accessible. Both cases are "using the platform as intended".
Well not recognizing you have 14k logins coming from the same place, possibly with a lot coming from someplace else than the last login on the account, is definitely a failure on their part. That's why more and more websites send you emails to allow logins from a new location. Or have login rate-limiters (too many request from your network).
I wonder how easy it is to have the location (at least country) of a user from the breached data, to use bots in the appropriate country and evade "login from a new location" protections. I guess easy enough if whole accounts have leaked.
In 2024, if you want to access a highly sensitive database, you must be forced to setup MFA at the minimum. My opinion.
It seems the part where 14k leaked credentials provided access to millions of users data is where it becomes their responsibility. It means that people who were fully responsible still had their information leaked because of overexposure of the information.
We're talking about people who 'friended' others on 23andme, right? How is that responsible user behavior? I had an account with 23andme before I forced them to delete my data, which was not that difficult to do.
One of the things I remember was getting friend invites from random people who were distant cousins, and while I suppose that might be fun conceptually, I never did it because I didn't know any of these people. In what world does a "responsible" user who cares about their privacy add access to personal information, on a website that profiles your DNA, to people who are blood-related but still total strangers? I would call that highly irresponsible, personally. But that's just me, an idiot who avoided all of this by deleting my 23andme account half a decade ago.
14,000 users messed up. As a result, hackers were able to log in to 23andMe's computers as those users. (Is that the fault of those users? Absolutely.)
The hackers were able to use those logins to steal the data of 6.9 million users, approximately all of which did nothing wrong. How is that part not the fault of 23andMe?
>approximately all of which did nothing wrong
They shared some of their data with the users who messed up. All of their info wasn't accessible. The only data that was accessible was the data that was shared with these users - in other words, opting in to sharing data with total strangers (which could be argued but is the #1 use case for 23andMe).
So if you want to let user A share info with user B (and as you say, that's likely an essential use case for 23andMe), then 23andMe either 1) cannot let user B mess up, 2) cannot let user A share with user B, or 3) cannot protect user A.
Of those options, 1) is impossible, though they could perhaps have done more to make it harder. 2) ruins a major use case. That leaves 3)...
While there could be a raft of IPs working in concert, there should be enough commonality to simply be an annoying target, black-holing IPs that attempt more than a couple times.