10 ms·
Unless I'm reading this wrong all that happened was someone had an existing leaked database of emails/passwords and then tried them on 23andme, and if they work
by Urgo 3y ago
Unless I'm reading this wrong all that happened was someone had an existing leaked database of emails/passwords and then tried them on 23andme, and if they worked they took the data they could get. Yes, 23andme has some pretty extensive and personal data, but this attack could be done on literally any website. The issue is people re-used passwords, and also did not have 2fa enabled.
So the database that is for sale is just a list of emails/passwords from other breaches that worked on 23andme, along with the data that 23andme had on those users. Not exactly a 23andme breach.
- teaearlgraycold 3y agoUse a password manager with long, random passwords. Pick your own passwords and you're leaving your door unlocked.
- dewey 3y agoI don't think you have to tell that to people on HN, but regular people will not be able to use most password managers. Not even 1Password is really user-friendly and it's the most mainstream one. The included one on macOS is hidden in some setting panel. For non-technical people the best authentication method is probably their phone (Passkeys, or tokens sent to their email address).
- randerson 3y agoMost (all?) major browsers now have built-in password managers which are intuitive enough for regular people and provide sufficient security against these attacks.
- dewey 3y agoAnd yet, passwords get guessed, stolen, re-used all the time. If you talk to regular people they still use pet names + a number because they want to be able to type it in everywhere. It's not a solved problem, even if a rudimentary password manager is in most browsers. Personally I don't know a single person outside of my tech bubble that uses passwords that you can't keep in your head, or write down on a piece of paper on their desk.
- hunter2_ 3y agoThere's a simple trick to having a password that's easy to type, easy to remember, and is pretty darn secure: repetition. Just take your pet's name or whatever, type it several times, and then finish it off with a number or whatever. Should be resistant to typical dictionary and brute force attacks.
- teaearlgraycold 3y ago[flagged]
- dewey 3y agoAnd you already identified the main problem with this strategy: "repetition". As it's not possible to remember n passwords for n sites, if one of them gets hacked "darn secure" isn't so secure any more. The main point of password managers is that you don't have to remember your password and if it leaks out on one site, it doesn't matter as it's only used on that one site.
- alistairSH 3y agoThe included one on macOS is hidden in some setting panel. As long as you stay in the Mac/iOS walled garden, you really don’t need to access the Settings page/app. Safari and most apps will happily pull the user/pwd from the manager for you. I’ve used for a few years now (after tiring of the mediocre UX of several other managers).
- Kiro 3y agoGood luck trying to convince anyone who is not already using it. I've tried super hard to get my friends and family to use a password manager but they brush it off as a joke. Even when they lose their account it doesn't seem to bother them. They just create a new one. It's a dead race.
- ellisv 3y agoThis has been my experience as well. You can even show them that they have been a part of breaches but not even that is motivating enough.
- sib 3y agoIn this case, unfortunately, at least as it's being described publicly, your detailed information was at risk if someone you are (even distantly) related to failed use a long, random, unique password.
- placesalt 3y agoI guess one question is: should > did not have 2fa enabled be allowed to coexist with > pretty extensive and personal data
- ApolloFortyNine 3y agoIt's the user's data, its not on 23andme to baby the user. If the user wants to trade ease of login with risk of getting hacked, that's not 23andme's fault.
- wilg 3y agoPasskeys, baby!
- keep_reading 3y agoTry convincing all the anti-passkey folks first
- rkagerer 3y agoGive me an implementation I can self-host, without Google, Apple, etc. having effective control (including claws in my relevant software supply chain) and with an easy user experience, where I can maintain secure backups (on my own infrastructure, thank you) and smooth transition to future devices, and ideally, if needed, securely export root keys (cause if I don't control them then someone else owns them), and maybe I'll be interested. In the meantime plain old high-entropy passwords with a good manager gives me all those features and a simplicity that's hard to beat. In my 30+ years of computing I've suffered more harm from failures of other companies than I have from any failure of my own diligence. The whole lesson learned is to reduce trust in them and, maybe I'm wrong, but everything I've read about passkeys and the like seems to put me at liberty of the companies developing and pushing the implementations of them down my throat. It will take a lot of trust before I give up my ability to copy/paste my credentials.
- elabajaba 3y ago
- bostonsre 3y agoShouldn't they have noticed that an ip or a set of ips were trying to log into a bunch of different accounts?
- Urgo 3y agoDepends on how they tried to get in. They could have used a large amount of residential proxies to get around this.
- mrguyorama 3y agoIf someone is trying to log in to "Account A" from fifty different places, that should be a red flag
- mullingitover 3y agoThey're not. They have a large set of different emails + passwords, and a large set of IPs. Each IP can check a single set of credentials, so you never get a single IP in a short timeframe with too many login attempts, and never trying to brute force a single account. If the attacker rented time on the botnet for a long enough period, they can fly under the radar for quite a while. 23andme sees lots of failed logins, but no real way to pin it down. reCAPTCHA would be the answer here. What's interesting/concerning is that it appears Google's reCAPTCHA (assuming 23andme was using it, and they should've been) was defeated.
- hombre_fatal 3y agoCaptcha still means you get to do the cred stuffing attack, just potentially more slowly which still doesn’t protect the user. I think for sensitive data where you want to protect the user, it makes even more sense to just generate passwords for them. It’s even simpler than 2FA. Some online casinos do this.
- mullingitover 3y ago
- pama 3y agoI don’t think you are reading this correctly. People could access (most importantly) the full raw DNA profile. And many of those breached were from people who opted in a “Relatives” feature even if their account was secure.
- ellisv 3y agoI don't see where in the article is suggests that the attackers were able to obtain the raw genotype data of anyone other than the compromised account.
- pama 3y agoThe pics of the offer and pricing suggests uniform DNA info rather than names or passwords for some and raw DNA profiles for others. Also this from the article: “ The compromised accounts had opted into the platform's 'DNA Relatives' feature, which allows users to find genetic relatives and connect with them. The threat actor accessed a small number of 23andMe accounts and then scraped the data of their DNA Relative matches, which shows how opting into a feature can have unexpected privacy consequences.” Edit: maybe you are right about the lack of genetic info, if this account is correct (unless the researcher didn’t pay full price, and only got the metadata): https://therecord.media/scraping-incident-genetic-testing-site https://therecord.media/scraping-incident-genetic-testing-si...
- lozenge 3y ago23andme doesn't sequence DNA, it just checks some genomes. https://customercare.23andme.com/hc/en-us/articles/227968028-How-23andMe-Personal-Genetic-Service-Works https://customercare.23andme.com/hc/en-us/articles/227968028...
- beaugunderson 3y ago23andMe uses a SNP array, or SNP chip, to look at SNPs (single-nucleotide polymorphisms, or more generally, single nucleotides that vary within a population). Basically what it gives you is a diff against a reference genome. So yes, while not a full genome sequence you can still get a VCF file out of it, impute sites that are not on the chip, use it for genealogy analysis, look at someone's disease carrier status, genetic disease likelihood, etc.
- somsak2 3y agoEven if this is the case, 23andMe should have done better here. Why are you letting people log into an account from a brand-new IP with no additional verification? You have their email, you could have at least done 2FA with that. And as other commenters mentioned, CAPTCHA would have also made this slower / more expensive. At my employer, we use both, and so it is not the case that this "could be done on literally any website." For such a mature business (that is publicly-traded, no less!) it is shameful to allow credential stuffing on the scale of millions of accounts.
- codetrotter 3y ago> Why are you letting people log into an account from a brand-new IP with no additional verification? Is that really feasible today? With widespread use of phones and laptops, most people probably have at least a handful of different IP addresses they regularly use (home WiFi, work WiFi, cellular connection) and then they randomly connect from new up addresses like those from libraries, coffee shops, commute, etc I think most “normal” apps and websites today allow any random IP to log in without jumping through extra hoops. Only companies with big budgets (Apple, Google, etc) make regular users jump through extra hoops. Banks, B2B have users that need extra hoops as well. But 23andMe. I would not expect them to take any extra steps.
- chii 3y ago2FA would've prevented those logins. I think sites should very much start mandating 2FA imho.
- nojvek 3y agoMany sites like Google including my banking sites send me an email when a new IP / location is used for login. This alerts if there is a sudden login without my knowledge and one click to disable. 23&me could have definitely done that to alert logins. It is 100% on 23&me even though used id/passwords were used. Genetic data is by definition extremely personal.
- codetrotter 3y ago
- rendaw 3y agoIf it was a known leaked database, they should have invalidated the passwords from the database before attackers exploited them.
- Urgo 3y agoWhile it's probably not a horrible idea to do something like this I don't think any or at least many does this currently? It wasn't a 23andme database that the attacker used, it was just some other random site/sites. So every time any website is hacked should every other website invalidate the credentials of those users on their site too?
- chii 3y agoIt is a lot of hassle, and the user isn't really protected because the invalidation relies on public releases of email/password combinations; there's obviously going to be plenty of private releases, which means it's actually just security theatre. 2FA, or passwordless logins, are the solution. Forcing the user to change their password (at the most inconvenient of times - right after they logged in, but before they're able to use the site) is annoying at best, and does nothing at worst.
- eviks 3y agoHow is it a theater to save a lot of users, but not all?
- chii 3y agoa theatre is where you have the feeling of security, but you don't really have it in reality. You cannot claim that just because some users are 'saved' as evidence that this is an effective security measure, because if a password was leaked, and not discovered, then this measure doesn't prevent it. But it is imposing a cost, which cannot be measured against effectiveness. Change the whole process to 2FA is secure because there's provable guarantees for the costs imposed, and therefore, you can make an objective decision on whether it is worth implementing.
- ShadowBanThis01 3y agoAnd this is why you should never force people to use their E-mail address as a user ID.
- adameasterling 3y agoWebsites should mitigate credential stuffing by checking against known cracked passwords. All you have to do is download Troy Hunt’s hashed password database, check it when someone logs in and if it’s cracked do your email password reset flow. Or you can use their API. It’s very simple, and I believe has been an accepted best practice since like 2017. This is 100% on 23andme. They are responsible. 1. https://haveibeenpwned.com/Passwords https://haveibeenpwned.com/Passwords
- 2devnull 3y agoThis and noticing a bunch of accounts are suddenly being logged into in mass in a way that is obviously an attack. It cannot be hard to detect such an event if you cared to notice. So it’s 100% negligence and 100% the result of putting profits over safety. A terrible management failure.
- rsaxvc 3y agoYou're not wrong that this wasn't a sophisticated attack. What's disappointing is that it worked well at scale. > this attack could be done on literally any website. The issue is people re-used passwords, and also did not have 2fa enabled. While possible to execute at scale on some websites, this type of attack tends to be quite loud on the receiving end once appropriate metrics are selected for monitoring and alerting. > "We do not have any indication at this time that there has been a data security incident within our systems." They should probably work on that, given that those systems were used to extract their customer's data, and that they only noticed when their customer's data was being sold. Given how far behind they are on disclosure I'd guess they may have only found out from media inquiries.
- michaelcampbell 3y ago> Unless I'm reading this wrong all that happened was someone had an existing leaked database of emails/passwords and then tried them on 23andme, and if they worked they took the data they could get. So... basically exactly what the title says. 23AndMe says user data stolen in a credential stuffing attack.