14 ms·
> 23andMe blamed the incident on its customers for reusing passwords, and an opt-in feature called DNA Relatives, which allows users to see the data of other op
by murphyslab 3y ago
> 23andMe blamed the incident on its customers for reusing passwords, and an opt-in feature called DNA Relatives, which allows users to see the data of other opted-in users whose genetic data matches theirs. If a user had this feature turned on, in theory it would allow hackers to scrape data on more than one user by breaking into a single user’s account.
23andMe's blame is an obfuscation of the problems which underlie this situation.
1. There is the matter of having insufficient granularity in their sharing options within the DNA Relatives program. It comes with two general levels, which is not enough.
2. 23andMe limits one to seeing the closest 1500 matches who have opted-in to DNA Relatives. That would have allowed a hacker to collect data on most people in the database despite having only a few thousand compromised accounts. (Haplogroups, ethnic origins predictions, names, profile data, a list of relatives, and information on geographic origins.)
3. The 1500 match limit would be helpful, in theory, however for some time (recently) it was possible to see profiles beyond those 1500 matches. I'm not certain if these were limited to only those who shared matching DNA segments but who fell outside of the 1500 match limit. And I can't be certain if this was part of the method exploited by these malicious actors.
- alwaysrunning 3y agoWow. What a shit company. It isn't the user's responsibility to secure the data that you store, it is 100% on you. If the user is reusing a pwd that might be the reason a single account got hacked but to beat a dead horse, you can mitigate that easily as a company. Karma seems to always work things out.
- BrandoElFollito 3y agoHow would you mitigate a password reuse?
- nextos 3y agoI also regret giving them my data. At work, we bought one of their first kits. We were doing genetics research and my boss got some for Christmas and gifted them to everyone in the group. Technically, 23andme is also pretty bad, which is hard to understand given that they employ very competent people and they are well funded. Seems like a space ripe for disruption. Their biggest competitor, DecodeME, never really aimed at B2C and just used customers to harvest data, then sold to a pharma. 23andme genetic risk scores are mediocre at best. Promethease makes better predictions. For example, in my case I have a high risk MHC allele, which is both trivial to predict and well understood since the 1980s. Never popped up on their reports, yet it is the first item you see if you feed your 23andme raw data to Promethease, or if you analyze the data yourself.
- lawlessone 3y ago> yet it is the first item you see if you feed your 23andme raw data to Promethease, or if you analyze the data yourself. If you had not mentioned this i would have thought they weren't testing people at all.
- ezfe 3y agoHave you deleted your data? They provide a clear button to do so...
- nextos 3y agoI eventually did, and also opted out from trials and sharing with pharmas prior to that.
- npongratz 3y agoDo you trust that your data, that they fully control on their system, is actually deleted? Including their backups that reside elsewhere? I just assume they set your record's "delete" field to "true" when you press that button. No way for us plebs to be certain about what they do.
- gwright 3y agoI'd be surprised to hear about anybody deleting records on backup systems (i.e., backups that exist for disaster recovery purposes). It would be pretty difficult to do that in a commercially viable way (but I'm open to hearing about some creative ideas).
- bombcar 3y agoThere are methods of doing it, but it is complex. Basically you either have hot backups you can delete from (this is bad for obvious reasons), or your backups expire in a given time (this is most common), or you have each record encrypted with an encryption key that is saved in other ways so you only have to destroy those to make the data irretrievable. Of course, that system has to be backed up, etc, etc.
- pbhjpbhj 3y agoSo companies shouldn't allow users to use poor passwords? Because it seemed harsh to me, maybe I don't care about them security of some data and so use a weak password; that's on me, surely?
- johncessna 3y agoAs someone who reads hackernews and works on security systems, yes, absolutely. Run their passwords through haveibeenpwned and disallow anything that shows up. Based on the feedback I hear from my non-tech friends and family, not allowing them to use their single password used for everything would be a good way to exclude those folks from using whatever service you're trying to sell them.
- pbhjpbhj 3y agoI was being argumentative there, I think the email-based auth is probably right for a site like this. Force complex passwords and people will often just do a reset every time anyway.
- Retr0id 3y agoCompanies have legal (and moral) obligations to protect user data. Those obligations don't go away for users that don't personally care.
- pbhjpbhj 3y agoPerhaps not legally, but morally? I'll have a good chin-scratch on that one. Thanks for your comment.
- bparsons 3y ago2FA is the standard these days for accessing PID. I can't think of data more sensitive or personal than your DNA.
- onthecanposting 3y agoPersonally I think this crime forum just democratized whatever unethical activity 23andme was probably doing anyway.
- 7moritz7 3y agoNot probably, they've certainly sold dna data https://www.forbes.com/sites/nicolemartin1/2018/12/05/how-dna-companies-like-ancestry-and-23andme-are-using-your-genetic-data/ https://www.forbes.com/sites/nicolemartin1/2018/12/05/how-dn...
- dekhn 3y agoI mean, the people whose data was sold did consent, and doing this was always 23&Me's mission. With the exception that the results have been less than stellar, I've generally thought having large-scale genomics data from consenting patients to work on human health problems is a generally good idea.
- deleted 3y ago[deleted]
- manxman 3y agoLook at the leadership’s connection with google and this becomes easier to understand. Then again we walk about touching things, leaving convenient DNA samples for anyone to collect throughout the day. It’s only because sequencing is relatively high cost at present that we have the illusion of privacy. Once we go in equivalent terms from mainframes to single board computers in the DNA world, then anyone can pretty much have at your personal genome. Would love to see how the criminal forensic science guys adapt their narrative to this impending reality.
- Phemist 3y agoThe 23andme page on "DNA relatives" says this though: > If you choose to participate in the DNA Relatives feature, you have multiple privacy options to suit your individual preferences. For complete privacy, you can opt out of DNA Relatives entirely. How is a feature opt-in if you need to opt-out to get "complete privacy"? What does complete privacy mean in this case and how does it compare to privacy that you can reasonably expect? I call bullshit on their statement that the feature is opt-in.
- kube-system 3y agoWhen you sign up they present you with the option to fill out a profile for use of the DNA relatives feature. You can either fill it out and join, or click a different button saying you don't want to join.
- Freedom2 3y agoMaybe before, but that wasn't my friend's experience when signing up.
- stainablesteel 3y agothere's laws around this topic and what is accessible for the sake of murder and kidnapping cases that requires people opt in, so i don't think that would be the case
- ianferrel 3y agoI think this might just be a slight difference in language usage. "opt-in" and "opt-out" as adjectives mean "something that is default off/on (respectively) that you can choose to select the other mode". But "opt in" and "opt out" as verbs mean "choose to/not to participate". So you can in fact "opt out" of an "opt-in" feature. It means choosing to keep the default of not opting in.
- deadbeeves 3y agoThat's a misuse of those terms. If you're presented with a switch that's in the the on position you don't switch it off, it's arguable that you've opted to leave it on. If you never realized the switch existed it would definitely be incorrect to say that you've opted to leave it off, since you can't make decisions about things you don't know exist. Yet, both cases would appear the same if all you know is which users had an opt-out setting in the in position.
- rurp 3y agoUsing opt-in for features that worsen user privacy or security is gross behavior. It should be disqualifying for any company that handles sensitive information and they deserve all of the blame for the negative effects that follow. Trying to weasel out of that blame makes the company even more sleazy.
- thfuran 3y agoYou'd prefer they be opt out so privacy is only available to the most attentive?
- anon373839 3y agoThere is confusion about the terms “opt-in” and “opt-out” which companies have gladly exploited. See Google Fi recently with a disclosure stating that Google will “opt you in” to their customer data-selling policy.
- bee_rider 3y agoI think we shouldn’t describe this as a confusion or ambiguity or anything like that. “Opt you in” is simply a nonsense phrase. Opting in means to proactively agree to something. It is impossible to be opted into something. They are just lying, and you know they know they are doing something unethical, because they wouldn’t need to make up nonsense phrases otherwise.
- jeffybefffy519 3y agoIts just a DNA based social network…
- labster 3y agoWhere you get to waive privacy for all of your close relatives.
- trident5000 3y agoThe issue is 23andMe is a honey pot. Thats fundamentally whats at play here.
- bertil 3y agoWhat do you mean by honey pot? I only know the meaning where it is a deliberate thing to attract bad actors. Is the entire company not meant to provide genetic information?
- api 3y agoThe entire Internet is a honey pot. You get something shiny, companies and governments get increasingly intrusive amounts of data about you.
- trident5000 3y agoA honey pot is just a place where sensitive and valuable information is centrally stored. They can be unavoidable but need to be well protected. Most companies fail at this. All it takes is one employee to pip install the wrong library or fall victim to a phishing attack or 3rd party vendor attack and its over. And on a long enough time scale, it happens.
- BHSPitMonkey 3y agoGP is correct, you are using the term to mean something different from everyone before you: https://en.wikipedia.org/wiki/Honeypot_%28computing%29 https://en.wikipedia.org/wiki/Honeypot_%28computing%29 TL;DR: A honeypot is like a bait car in a police sting operation; It's something that looks like a vulnerable system with something of value to attackers, but in reality is a fake meant to catch intruders or collect data on them.
- ohhnoodont 3y agoI also don't understand why more companies don't also implement reasonable rate-limiting and abuse detection. A suite of hacked accounts should not be able to scrape millions of users worth of data.
- deleted 3y ago[deleted]
- fyrn_ 3y agoThis doesn't sense, hackers don't have to use your intended API. They probably got access the the database directly.
- ohhnoodont 3y agoAccording to the article this data was acquired by scraping data from a subset of compromised accounts.
- herbst 3y agoThere is no reason to not rate limit your user frontend. I have several pages with rate limits because of prior bot attacks and I regularly rate limit pages against bots with 'interesting data' for scraping
- kevinventullo 3y agoMan #2 reminds me a lot of the mechanism by which Cambridge Analytica exfiltrated so much Facebook data. I wonder if the 23andMe CEO will be dragged in front of congress for the next 10 years.
- autoexec 3y agowould it matter if they did? Who at facebook or Cambridge Analytica is behind bars right now because of what they did?