6 ms·
In 2023 an org of their size and with such sensitive data needs to give a bit more of a fuck about who is accessing users' accounts. Mass leakage of potentially
by uses 3y ago
In 2023 an org of their size and with such sensitive data needs to give a bit more of a fuck about who is accessing users' accounts. Mass leakage of potentially reused credentials is an ancient concept at this point and should have been on their radar as an attack to protect their users' data against. Basically, they shouldn't have just been relying on passwords to authenticate users. Many orgs of their size and with much less sensitive information than the literal genetic data of their users do a lot better.
- dpkonofa 3y agoAnd how would they know that when the access was done via the correct user/pass combo for accounts where the users chose not to enable MFA?
- disgruntledphd2 3y agoI mean, the right thing would have been to force password changes for the breached accounts. This is doable through have I been owned etal, right?
- dpkonofa 3y agoHow would they know which passwords were breached? The data leak was from a different site and not from 23andme. Additionally, current evidence suggests that the breach was not known on haveibeenpwned prior to it being used and the reused credentials were tested over a period of months using a botnet.
- deleted 3y ago[deleted]
- disgruntledphd2 3y ago> Additionally, current evidence suggests that the breach was not known on haveibeenpwned prior to it being used Totally fair, I haven't been following this really closely. That being said, if someone re-uses passwords once they probably do it a bunch of times, so it's odd to me that they didn't have a process to detect reused passwords and force a change.
- tsimionescu 3y agoWhy is that an option, given how sensitive the data is? Why are they not actively monitoring HIBP for their users?
- dpkonofa 3y agoYou don’t know that they weren’t. HIBP is not omniscient. It doesn’t automatically get a list of leaked account info unless that info is published publically. Based on the current evidence I’ve seen so far, that’s not the case. It seems like the breached data was sold privately on the dark web and was tested for months via a botnet. It also seems like the leaked data included either IPs or last known login location info which means someone with a sizable enough botnet could have used that info to login from nearby locations, thereby bypassing any prompts triggered by “new locations”.
- TheCapn 3y agoWould be interesting to know how they were testing authentication. Were they using a botnet of any sort? Otherwise for every "valid" user/pass combo from an external leak they tested there'd be several failures. A single (or multiple) hosts smashing auth attempts should raise flags. They didn't "Brute force" one user account at a time, but they did brute force the authentication system in general.
- dpkonofa 3y agoThe current info that's been released seems to indicate that they used a botnet over the course of several months and had access to the "last known login location". So there wasn't any "smashing" happening and no "you're signing in from a different location" blocks either.
- evan_ 3y agoIf the user logs in from a device we haven't seen before, or they haven't logged in for more than a year (or six months, or two weeks etc), send them an email challenge. Maybe the email address on file is also cracked but it'll make it harder, and it's more work for the attackers.
- g-b-r 3y agoKeep in mind that will force everyone who doesn't keep cookies to have to do that at every login. Github is like that right now, and it's quite a pita; sure, it's not a great idea to continually delete all cookies without exceptions, but in some cases it's currently hard to avoid it (low-end smartphones where Firefox is too heavy)
- JeremyNT 3y agoIt's a perfectly reasonable compromise though if you can't force MFA for some reason. There are many sites which do this today. You don't even need to rely on the cookie if you're worried about the ux for cookie clearers. You could also whitelist an IP address (or even a subnet) when they verify the email, and it would have been "good enough" to prevent this particular situation.
- g-b-r 3y agoYes true (if you do use cookies though it's probably better to let the user disable the check, after explaining the risks)
- evan_ 3y agoThat's true. Also, if I cut my keyboard in half, it's a lot harder to use Google Docs. I sympathize, but at a certain point if you've gone out of your way to disable the features that the developers have added to make your life easier, you just don't get to complain about it.
- g-b-r 3y agoAt least don't tell me it's "developers making my life easier"...
- rsanek 3y agoThey have an email right? Many services automatically detect suspicious logins and asks for additional verification even if the user hasn't specifically turned on MFA.
- dpkonofa 3y agoThat’s the problem. There wasn’t anything suspicious. From what I’ve read, the “hackers” used a botnet, aided with location/IP data from the leak. There would be nothing suspicious about a login with the correct email and password coming from the right location.
- octopoc 3y agoIf they don't have MFA enabled, don't let them see other people's DNA. That way person A choosing bad security only endangers person A.
- dpkonofa 3y agoYou can't see just anyone's DNA. You have to opt-in to the program and share it with specific users, in nearly every case someone who is a distant relative that is tantamount to a stranger.
- MichaelZuo 3y agoI think folks are just angry that it turns out some small fraction of their distant cousins are incompetent at password security.
- croutonwagon 3y agoMany orgs will use location and connection types to filter this. For example if i proxy my connections through a VPS or VPN i will OFTEN either be outright denied access, or at best get sent to a validation step (most often they shoot the email an verification code that i have to plug in). I will often route traffic through a linode for reasons. And sometimes use a VPN here and there (ie: mullvad). In almost all cases this will trigger anti-spam measures on sites, some so intrusive its borderline unusable (ie: Youtube and google with recpatcha).
- starttoaster 3y ago> where the users chose not to enable MFA? Require MFA to be enabled when it's an issue of indirect access to personal data of potentially millions of other users on the site. Any retort like "okay well that might just hurt the platform's ability to attract users with that sort of security prescription," gets cement shoes in the bay. There's absolutely no reason to allow known dated forms of authentication to access user data of other 23andMe subscribers. Of course people are lazy and won't enable it if nobody is telling them they have to, most people are completely ignorant to how rampant these kinds of stories are because they don't subscribe to tech news. Somebody needs to be the adult and force people into the correct lane.
- _tom_ 3y agoIt's fairly common to do traffic analysis, and look for behavior that is not typical. Things like a sudden jump in the data being downloaded, access from other countries, changes in IP addresses, log ins from new sites. There are many security tools that use AI to identify patterns of access and alert on changes. So, yes, something like this could be detectable.
- flandish 3y agoSimple. Require MFA.
- SAI_Peregrinus 3y agoNIST SP 800-63B "Digital Identity Guidelines" specifically requires preventing users from setting passwords which are known to be commonly-used, expected, or compromised.
- dpkonofa 3y agoHow would you know they're compromised before you know they're compromised? According to the info I've read about this, the site and database that was breached was not published publicly but was sold privately on the dark web.
- Fatnino 3y agoThey should have worked with haveibeenpwnd to proactively warn their users who are detected to have been using recycled and leaked passwords.
- dpkonofa 3y agoThat assumes that haveibeenpwnd knew about this leak which would only be possible if the leaked data was posted publicly. It doesn't seem to have been as the hacker was looking to sell the information.
- turquoisevar 3y agoThey had no issue making MFA mandatory after the fact, so they should’ve had no issues making it mandatory before the fact. > After disclosing the breach, 23andMe reset all customer passwords, and then required all customers to use multi-factor authentication, which was only optional before the breach. As others have pointed out, there are also other options. Such as an email challenge when noticing high traffic, or damn, even when noticing a new login from a new device or IP that is unfamiliar. Many services do this all the time. We’re talking about raw DNA data here that is accessible. You’d expect levels of security as implemented by banks if not better, not “Little Timmy’s first blog” levels of carelessness.
- dpkonofa 3y ago> We’re talking about raw DNA data here that is accessible No, we’re not. Have you ever used 23andMe before?
- turquoisevar 3y agoYes we are and yes I have. Have you? They’ve temporary disabled it due to this data breach, but you were able to download your raw data[0] and then use it as you see fit. I, for example, downloaded mine and used OSGenome[1] to crawl through it and parse it as well as Promethease[2]. So maybe save your downvote next time until you know what you’re talking about. 0: https://ibb.co/yQc9xXP https://ibb.co/yQc9xXP 1: https://github.com/mentatpsi/OSGenome https://github.com/mentatpsi/OSGenome 2: https://promethease.com https://promethease.com
- dpkonofa 3y agoFor starters, I didn't downvote you and couldn't even if I wanted to since HN doesn't allow you to downvote replies to your own comments. For another, I got the threads confused and thought you were talking about the accounts that shared access with compromised accounts. Sorry. Relax yourself before you jump to immediately into your persecution complex.
- 3y ago
- mc32 3y agoTotally agree. Orgs with this kind of data will at least track geolocation and maybe device information and require proof despite a correct password as well as attempts to access multiple accounts from an address block. Many also incorporate the have I been owned leaked password database . The have to act responsible when handling and caring for this kind of data. It’s irresponsible not to.