5 ms·
If the customer loses the key to the encrypted data, then it's useless to everyone, including bad actors. This is not what happened here. 23&Me exercised poor
by buffington 3y ago
If the customer loses the key to the encrypted data, then it's useless to everyone, including bad actors.
This is not what happened here. 23&Me exercised poor security. I deal with financial data for my job, (like, transactional data, for most Americans), and I would consider that less sensitive than DNA data. We lock that transactional data up so tight it'd make your head spin. If it's data about an individual, in the wrong hands, it can do harm. If you're in the business of people's data, you cannot be stupid about protecting that data. 23&Me is (was) very much in the business of people's data, and could afford and attract the best talent to ensure the data was encrypted and protected.
They're reaping what they sowed.
- tzs 3y agoThey didn't require 2FA. That's the only arguably poor security I see. Is there something beyond that they should have done?
- aaomidi 3y agoI mean that only bad thing makes so much of a difference.
- surfingdino 3y agoEncryption at rest.
- tzs 3y agoWhat makes you think they didn’t have that? The bad guys obtained user passwords from breaches at other sites where some 23andMe users had accounts and had used the same email and password as their 23andMe account. They logged into those 23andMe accounts and obtained data that those accounts had access to.
- buffington 3y agoCredential stuffing attacks are detectable and preventable, which is what you're describing. When detected (trivial with the right tools), you can then require users to reset their passwords for the suspected accounts (with the traditional "check your email for reset link" dance).
- buffington 3y agoThere are many enterprise security tools that can detect compromised accounts. These tools monitor traffic and behavior and report or actively block traffic that doesn't look "normal." What looks "normal" depends on the org, but 23&Me knows what it is (or should, since it's a fundamental of running their business). Just as a made up example, they may know that 85% of users don't use VPNs, and typically have an IP address that geolocates within 100 miles of their mailing address (which 23&Me has on file). Users might also typically log in very infrequently between 12-4am (localized to their IP/mailing address). And when they do log in, 90% of the time it's to see the new content you just sent a marketing email about, with short session lengths as well. A user who logs in through an IP that geolocates well outside of their mailing address and methodically steps through every possibly thing you can click on at 3:15AM, is probably a bad actor who gained access through credential stuffing attacks. Off the shelf tools can automatically detect all of that kind of behavior, and more. They can look at the collective traffic patterns and see a bunch of users logging in from the same pool of IPs, or the same VPN, or around the same time, or using the site in the same way as others bearing similar attributes. They can stop wide spread coordinated attacks from botnets. The same tools can automatically detect and alert when credential stuffing attacks are happening, locking down accounts and requiring their passwords to be reset. Given the scale at which 23&Me operated, it's impossible that they weren't aware of these tools. Investing in the right tools is just one of many things they could have done. Even with those kinds of tools, you need to assume they're not enough (even if they are), so you encrypt everything at rest. Every decryption gets audited, and audit logs get fed into the same monitoring tools used to alert and stop abnormal behavior. It all sounds overkill, but remember: they lost 91% of their valuation. All it took was the wrong people getting in, and it tanked their entire business.
- elevatedastalt 3y agoWhat lock can protect people's data if the people hand the key over to the bad guy?
- surfingdino 3y agoThe damage is limited to the person who handed over the keys.
- beams_of_light 3y agoNot in this case.
- lm28469 3y agoIt works for your car keys, credit cards, phones. People who think the current system is the best system we can ever get really lacks imagination