I mean. If people reused passwords for 23andMe, is this really 23andMe's fault? Should they have required 2FA for everything? That's kind of a hard sell tbh.
I mean. If people reused passwords for 23andMe, is this really 23andMe's fault? Should they have required 2FA for everything? That's kind of a hard sell tbh.
They could've blocked source IPs making all the login requests, but that was probably being changed to not set off alarms. However, there wasn't enough information in the article to go on, but since they suffered so many breaches of user accounts, they probably had to do something wrong. I'm too busy to dig into the specifics.
Additionally, they don't support 2FA/MFA which of course would mitigate some of the risk of password re-use.
There's plenty of things they could have done to prevent this breach.
If an attacker works off lists of compromised usernames and passwords from various sites, for a given user there's always a chance that the first one they try is correct. Especially for the kind of user who recycles the exact same password on 50 different sites. (Incidentally, you should probably try to hack that kind of user first, and for each user, try their most-recycled passwords first.)
[edit]: there are other obvious heuristics that could have detected it, it does show they had either very basic or no intrusion detection, which, for a service of this nature, isn't really acceptable
Imagine you are a company with great password practices, how would you tell that a user re-used a password that was exposed in some other data breach without you being able to generally know what a user's password is? Well, of course, it's the same way that you verify their password when they login. You track (or more likely in this case, adhoc check) data breaches, when you find a matched email in the breach with one of your users, you check if the password from the breach would allow that user to login.
Absurd that they thought that we'd miss this part of the sentence.
If an average online gaming service or social network can manage sending 2FA codes over email or SMS when their users are logging in from a new device, the holder of a large chunk of the world's genetic data can as well.
Yes absolutely. If it were one account being compromised due to the user reusing a password, that would be the user's fault. But what happened is credential stuffing, and that is absolutely something a professional IT organization should be prepared to defend against.