5 ms·
"23andMe blamed the incident on customers reusing passwords" I'm not sure how they worded this but it's their shortcoming, not their customers. Customers reuse
by dizzydes 3y ago
"23andMe blamed the incident on customers reusing passwords"
I'm not sure how they worded this but it's their shortcoming, not their customers. Customers reuse passwords and will continue to do so. For sensitive PII it's far easier to enforce 2FA or Google SSO than to change customer behaviour.
- LegitShady 3y agoThey do have it but they probably have millions of accounts that were created before that feature and never logged back in and set it up. It's also through an auth app and not texts which is more secure but more of a hassle for not allowing users which might affect adoption.
- toomuchtodo 3y agoIt is very inexpensive to check your customer passwords against HIBP [1] or strongly encourage MFA. They choose not to. [1] https://haveibeenpwned.com/API/Key https://haveibeenpwned.com/API/Key (23andme customer using Apple SSO, have strong opinions on customer IAM, passwords must die)
- henryfjordan 3y agoDoesn't that require you to know the password in plaintext?
- toomuchtodo 3y agoDepending on your use case and implementation details, not necessarily. https://www.troyhunt.com/understanding-have-i-been-pwneds-use-of-sha-1-and-k-anonymity/ https://www.troyhunt.com/understanding-have-i-been-pwneds-us...
- hakcermani 3y ago.. can't those old accounts be flagged to require email verification to log in ?
- Scoundreller 3y agoOh, you lost your email account access? Please send a matching DNA sample and $99 to unlock your account. I mean, 23andme has one of the ultimate methods of account recovery available to it. (ignoring that people tend to leave copies of their DNA everywhere, but then you could just mail that in under a John Doe and find out all the same info anyway).
- deleted 3y ago[deleted]
- sschueller 3y agoIt could be easier and cheaper for some to get someone's hair or saliva than cloning a SIM card...
- Scoundreller 3y agoMy point of view here is someone that’s lost their access to 23andme, not using it for SSO for other services. While I get the social media aspects of 23andme, if one can get your DNA, they could submit that to 23andme and find out everything you already knew. I wonder how they handle duplicate submissions?
- Zetobal 3y agoThe Facebook way...sign up with email, get instantly restricted, need to verify with a mobile number to unlock.
- suprjami 3y agoWhatever way you put this, handling the support load of the few customers who can't log in - and by this argument aren't ever logging in anyway - is better than having this degree of PII leaked and the company reputation ruined.
- mcpackieh 3y agoMost old accounts would probably never try to log in again anyway. After you learn that you're 3/64-ths Irish you've gotten what you wanted, why log in again? Yeah I know there's the whole genetic disorder screening thing which might receive more updates in the future, but I think most of their customers probably did this for the novelty of knowing where they came from.
- littlestymaar 3y ago> created before that feature Which feature? Unless they didn't ask their user's email (which I'd find surprising), they could have added e-mail based TFA any day without asking their users to do anything.
- deleted 3y ago[deleted]
- theogravity 3y agoAgreed. They could have done email link verification which wouldn't require the user to set up 2FA on their side.
- 7373737373 3y agoOr provided their users with randomly generated, secure passwords themselves I saw this idea somewhere on here a few months ago, and since then, granting users the ability to set their own passwords seems like a dumb thing to do!
- amanaplanacanal 3y agoThere was a time when random passwords seemed like a bad thing, because users would write them down, and that was an obvious risk. We are way past that of course, but that line of thinking is still informing security decisions.
- hnlmorg 3y agoDepends on what you’re trying to protect against and who your average user is. Forcing passwords onto users is a sure fire way to get people to write their passwords down and constantly get locked out of their account. In some circumstances that’s not a problem. For local domain access, that’s completely unworkable. For websites it makes a little more sense since users can use password reset via email, but if you’re going to expect people to rely on that then you might as well allow them to set a password and use email as 2FA.
- wubrr 3y agoEh, millions of accounts hacked via credential stuffing on one platform because of reused passwords? I don't buy it for one second.
- slg 3y agoAnd even if it is true, that is still the fault of 23andMe. It is kind of a fool me once scenario. Some occasional password stuffing is excusable and can be blamed on users' laziness. Millions of accounts hijacked through password stuffing and something is fundamentally wrong with 23andMe's approach to security for not identifying such a large scale attack.
- wubrr 3y ago100%
- astroid 3y agoIt wasn't millions of accounts, it was an undefined number relying on scraping dna relatives after the breach. This article mentioned it, but last week I saw a better more detailed explanation. Regardless, the key quote from the linked article: "23andMe blamed the incident on its customers for reusing passwords, and an opt-in feature called DNA Relatives, which allows users to see the data of other opted-in users whose genetic data matches theirs. If a user had this feature turned on, in theory it would allow hackers to scrape data on more than one user by breaking into a single user’s account."
- dboreham 3y agoRelated: what fool decided to call compromised credentials "stuffing"? Nothing is being stuffed.
- nyc_data_geek1 3y agoThey failed to enforce MFA.