20 ms·
So 23andMe failed to identify brute force and credential stuffing access of 14,000 accounts. They also have a feature that grants those 14k compromised accounts
by liquidise 3y ago
So 23andMe failed to identify brute force and credential stuffing access of 14,000 accounts. They also have a feature that grants those 14k compromised accounts effective access to 6.9 million accounts.
23andMe then claims that poor password practices are responsible for this data leak.
> “Therefore, the incident was not a result of 23andMe’s alleged failure to maintain reasonable security measures”
I've not run security at an org of their size, nor have i touched their service, but i have to imagine there were some patterns to this breach that would have been reasonable to account for ahead of time. Did those 14k accounts also have their email provider accounts compromised? Could a login ip-range check have prevented all of this? 2FA seems like an obvious answer here but clearly that was more than could be expected.
- hnarn 3y agoA service that handles sensitive personal data should absolutely have mandatory 2FA. Calling anything else “reasonable security measures” is laughable.
- yreg 3y agoI don't think 2FA should be mandatory. Leave that decision to me, the user.
- meepmorp 3y agoThe potential impact of a breach doesn't just affect you, and their security decisions should be made with a wider consideration of concerns than the short lived frustrations of users.
- mfashby 3y agoIt varies, I guess. For a normal end-user account on a system where no interaction between users is possible, it pretty much just affects you. For some kind of admin account with privileged access to other users' data, then it definitely affects others. One might expect increasing mandatory security measures correlating with increased potential damage of a breach. Similar to safety measures on mass transit vs. personal vehicles.
- autoexec 3y agoAgreed! Any service with mandatory 2FA isn't one I want to use. I'm just fine with passwords so far.
- hnarn 3y agoYour liberty starts where mine ends. By the same logic password complexity should be left up to the users as well, but what responsibility is this user willing to shoulder when they are the reason sensitive information leaks? I’m sure most people on HN have great passwords stored in password managers, but 99.9% of users are not like that, so mandatory 2FA does not only make sense, it’s the only reasonable choice for sensitive information.
- reactordev 3y agoThis. Saying “It’s not our fault, it’s yours.” isn’t going to fly when the government comes looking. I remind everyone that there’s a new law about data breaches in effect. [1] The FTC will want to know what their security posture is and whether that meets HIPAA compliance rules or not. If not, they may lose their HIPAA compliance and be barred from applying, rendering their whole operation illegal under the FTC (s/you can only collect health information under HIPAA/you can but you still need to notify the FTC when you’re breached/). This is a serious HIPAA violation not just a security breach. This defense of theirs isn’t a smart strategy if they want to stay in business not to mention the impending lawsuits. *edit* forgot the link [1] https://www.ftc.gov/business-guidance/resources/complying-ftcs-health-breach-notification-rule-0 https://www.ftc.gov/business-guidance/resources/complying-ft... [2] https://www.ftc.gov/legal-library/browse/rules/health-breach-notification-rule https://www.ftc.gov/legal-library/browse/rules/health-breach...
- gosub100 3y agoIn the unlikely event hackers were prosecuted for actually breaking into them, I wonder if there is any material in this release the defendants could use to their benefit: "the purported victim here says in their own words their system was secured properly".
- reactordev 3y agoThe sad reality is they will be audited, found lacking, slapped with a small fine, told to implement 2FA as a requirement for all accounts, and go about their business. That’s been the precedent the last decade.
- dekhn 3y ago23&Me is not subject to HIPAA, unless they are acting as a health care provider, or business associate (not sure but I don't think they are in this context). Most people misunderstand HIPAA, and think it applies in situations it doesn't. This is not a situation where HIPAA applies. HIPAA is NOT a privacy law. It's a law that mandates portability of medical data, some details of which overlap with privacy.
- H8crilA 3y agoImagine you already know the passwords for many emails, or likely password patterns, from other sources. That's the kind of the attack we're talking about here. Also, those attacks are normally performed very slowly, and probably through botnets. (And yes, 2FA is the only real answer here, preferably YubiKeys to also defeat phishing)
- browningstreet 3y ago2FA is so, so, so very tiring.. all day long, 2FAing. We need to move past it. And no, I don't have an answer for it.
- rafaelmn 3y agoPasskeys ?
- marcosdumay 3y agoIt just needs to be done correctly, not as a "gimme your phone number, peasant" excuse for data mining. How many computers do you use normally? How hard would it be to link them to your accounts?
- littlecranky67 3y agoProblem is using multiple browsers, or when a privacy-conscious user decides to delete internet history.
- oarsinsync 3y ago> How many computers do you use normally? How hard would it be to link them to your accounts? I use private browsing exclusively, so, I’d hope that’s difficult link to me reliably.
- marcosdumay 3y agoWell, you if want to both refuse that a site reliably identify you and have a flawless process for identifying you, you'll have a hard time.
- dpkonofa 3y agoThere was no brute forcing done. The credentials were from other sites that were leaked via Tor and the users on 23andMe used the same email/password combo. That’s why you don’t reuse passwords, when possible. Nothing on 23andme’s end failed unless you consider someone using a correct user/pass combo while not being the owner as a fail on the part of 23andMe rather than the end user.
- drcongo 3y agoHow does something leak on Tor?
- MattGaiser 3y ago> Nothing on 23andme’s end failed unless you consider someone using a correct user/pass combo while not being the owner as a fail on the part of 23andMe rather than the end user. This seems to be the big societal discussion, in the same way that people blame banks for them sending money to crypto and romance scammers overseas.
- llm_nerd 3y agoIt's hard to detect credential stuffing. If people reuse passwords[1] they are going to have a bad time. Maybe they could have automatically locked accounts that appear in compromises, and while they should do that, I wouldn't go so far as saying they must do that. Maybe they could have detected the exfiltration, but maybe they couldn't. If the hackers were smart they would have properly distributed the calls and rate limited to avoid detection. >effective access to 6.9 million accounts The relatives feature lets you -- if you opt in -- see your DNA relatives and their very basic details, and vice versa. I have literal thousands listed, and those thousands, all over the globe and of mostly minuscule relations, can see mine. That really is being a bit overwrought as a facet of this.
- robobro 3y agoWhat is [1] referencing?
- mvdtnz 3y agoThere are lots of ways to mitigate against credential stuffing. There are methods to detect botnets accessing your system at scale. There are products like HIBP that can help prevent credential re-use. You can prevent logins from unusual locations with an additional factor ("it looks like you're accessing this website from Croatia when you've only ever logged in from California, check your email for a confirmation code"). You can force MFA if you want to go nuclear.
- hibikir 3y agoI've done identity for bigger places that have credential attacks all the time. There's sophisticated attackers that are aware of each victim's location and can get through geolocation anomaly detection, and there's such thing as hitting the jackpot through lucky credential stuffing, so any check for failed attempts doesn't hit. It's not possible to detect everything. There's a whole lot things a serious place will do to detect naive attacks though, so a whole lot of volume there fails. It might even be good to let an obvious stuffer keep attacking you, and help us mark the accounts they have working credentials for, so we can instantly lock them and ask for password changes. I have no idea of the actual sophistication of the attackers here though: It's way too common to see big companies that have paid no attention to prevention, and therefore will only notice an attack if it becomes an accidental denial of service attack. Maybe 23andme are sophisticated and only the worst shared passwords got breached, or maybe they have minimal security.
- tamimio 3y agoIn security, it should be ALWAYS assumed that the users are naive and will use the least possible means for an account security, it is the responsibility of the service provider to enforce these policies, let’s see: - Did 23andMe enforced a strong password policy during the account creation with X minimum and combination of chars with complexity meter? - Did they send a periodic reminder about account security, update passwords, secret questions and the likes? - Did they enforce the 2FA? - Failed authentication attempts count? And those on top of my head, NIST, PCI and other standards have more details about those, in fact, the security level should be provided by such services should pass more than the “standards”, as once these data are leaked, you won’t be able to change it, so blaming that in the users shows the lack of accountability, glad I never trusted my DNA in any of these services.
- notfed 3y agoRequiring 2fa is the only real answer here here, your other suggestions are unnecessary red tape. (A strong password can still be reused. Periodic reminders will 100% be ignored. Failed auth count is silly because it falls back to 2fa, so just always require 2fa?)