23andMe then claims that poor password practices are responsible for this data leak.
> “Therefore, the incident was not a result of 23andMe’s alleged failure to maintain reasonable security measures”
I've not run security at an org of their size, nor have i touched their service, but i have to imagine there were some patterns to this breach that would have been reasonable to account for ahead of time. Did those 14k accounts also have their email provider accounts compromised? Could a login ip-range check have prevented all of this? 2FA seems like an obvious answer here but clearly that was more than could be expected.
Nothing on 23andme’s end failed unless you consider someone using a correct user/pass combo while not being the owner as a fail on the part of 23andMe rather than the end user.
Maybe they could have detected the exfiltration, but maybe they couldn't. If the hackers were smart they would have properly distributed the calls and rate limited to avoid detection.
>effective access to 6.9 million accounts
The relatives feature lets you -- if you opt in -- see your DNA relatives and their very basic details, and vice versa. I have literal thousands listed, and those thousands, all over the globe and of mostly minuscule relations, can see mine. That really is being a bit overwrought as a facet of this.
I have no idea of the actual sophistication of the attackers here though: It's way too common to see big companies that have paid no attention to prevention, and therefore will only notice an attack if it becomes an accidental denial of service attack. Maybe 23andme are sophisticated and only the worst shared passwords got breached, or maybe they have minimal security.
- Did 23andMe enforced a strong password policy during the account creation with X minimum and combination of chars with complexity meter?
- Did they send a periodic reminder about account security, update passwords, secret questions and the likes?
- Did they enforce the 2FA?
- Failed authentication attempts count?
And those on top of my head, NIST, PCI and other standards have more details about those, in fact, the security level should be provided by such services should pass more than the “standards”, as once these data are leaked, you won’t be able to change it, so blaming that in the users shows the lack of accountability, glad I never trusted my DNA in any of these services.
(And yes, 2FA is the only real answer here, preferably YubiKeys to also defeat phishing)
The company was originally founded on unreasonable goals in the health industry, using DNA array testing to identify risky variants in individuals to help produce better treatments.
It took the CEO about a decade to learn enough to acknowledge that their approach would never have achieved this, because the mapping from genome to risk/treatment is a highly complex function and their mechanism was underpowered and they also repeatedly pissed off and ignored the FDA who then shut them down for a while. The only reason they survived this was, afaict, the CEO's ability to extract money from google to keep operating.
Eventually, the company found that they could do identity by descent really well, much more useful to customers than telling them their earwax properties, and their "recreational genomics" products were extremely popular- enough to sustain a service, but not really enough to sustain advanced research.
They finally got some pharma to give them a bunch of money for their data (basically all the genomic and phenotype data that they collected on their users) ostensibly to do translational health research, but this has not been very productive (and seems unlikely to be truly transformative).
In the meantime they have to keep runing their consumer platform and it clearly had security issues that permitted a large scale data extraction (that's on them, not the customers) and I jusrt can't see how they keep getting money to operate, because their track record in translating data to profit/medicine has been so skimpy.
My doctor scoffed at 23andme finding a dangerous genetic mutation and said its probably just a false positive. I had to spend $500 to get a single gene tested in a hospital, still came out positive.
So bang for your buck that $99 was a great deal for a full mapping, it feels like most of their issue is what the government allows them to show. Im pretty sure that SNPedia syncer isn't online anymore, but that was what made 23andme a great service for me
On the other hand, 23andMe should have definitely done much more to reduce the blast radius of this attack. Mandatory 2FA, disallowing known-compromised passwords, geolocation of login IPs, etc.
I guess the question shakes out to: where do we draw the line on personal responsibility vs. service responsibility? Services can't be responsible for 100% of user security. But they also can't be negligent in their own security and mitigations.
But other that that, I ... kind of agree with 23AndMe: users should be primarily responsible for their own accounts. I don't like the "assume all users are blubbering morons and treat them as such" security model, and then blame $corp for treating their users as adults. Again, 23AndMe could have done better, maybe, but I strongly disagree that they're primarily responsible – at best they're partly responsible.
And maybe 23AndMe also could/should have pushed 2FA harder, I don't have an account so don't know how hidden this feature was or not. All I know is that mandatory 2FA is a right pain for me, adds basically no security for me because I just store it in my password manager next to the password. For TOTP it's just an inconvenience, but I really dislike phone-number based 2FA – I've been locked out so many times...
I'm skeptical that 6.9 M users opted-in to an off-by-default setting. That seems absurdly high for any opt-in feature that involves nebulous user value. I don't use 23andme, but I'd love it if someone had screenshots of this supposed "opt-in" before the data breach.
Also, how far does the sharing go? How far removed from a family member does a user have to be to see their info? Going from 14k to 6.9M seems like it must have been more than just immediate family, given the small family size common today.
1. Fraud detection on the metadata like IP address, access timing, access patterns etc. eg: Why is a person from UK logging in from China IP?
2. IMO orgs should be importing and refusing known leaked credentials and the top 1000 passwords. This could happen both at password set time ("You cannot use that password as it's a known leaked credential, click here for more info about the breach"), or at login time "You're using a leaked credential, please follow the password reset flow".
I assume most people are the same.
Therefore, I'm not sure what significant information an attacker could have gotten on me. Anyone care to enlighten me?
Blocking the credential stuffing attacks? They probably did have mitigation efforts, but you can only be so aggressive before the false positives start blocking significant numbers of legitimate customers, who have no recourse except to wait out a temporary ban. And some credential stuffing attacks are extremely sophisticated, such that even best in class security companies can't always effectively block them.
Mandatory MFA? Great on paper, except that 10% of people hate the extra steps (probably with great overlap between the people reusing passwords) and will complain and/or disable it if given the chance. Another 20% have invalid or out of date contact details (an old employer's email address, a landline phone number that can't receive SMS, etc.), and they'll be locked out of their accounts.
Yeah, there are ways to mitigate these downsides. And I'm not arguing that 23andme found the appropriate balance between "customer satisfaction" and "customer security." But I can see how a mostly reasonable organization could end up in this position. And it's mainly the risk of terrible press and upset customers that allows other companies to justify more security-oriented policies, so let them have it.
This is data that appears in the ancestry data for the 14 000 compromised accounts. Your data only appears in another account's ancestry data if you opted in to sharing ancestry data and they are a relative of yours. I think most people opt in, because (1) finding out about your ancestry and relatives is one of the main reasons people use services like 23andMe, and (2) even people who started using it just for the health data often get curious and start using the ancestry stuff too.
23andMe counts anyone who is a 4th cousin or closer as a relative, which results in some big relative lists. Mine has 1500 other 23andMe users in it, but that might be above average. Based on 23andMe having 14 million customers, 14 000 accounts being compromised, and 6.9 million accounts having data taken via the relatives lists of those 14 000 compromised accounts, and assuming that everything that I don't have any data on is is pretty evenly distributed (the statistical equivalent of a spherical cow) I'd guess that the average is around 700.
If that's even in the right ballpark then when you opt in to sharing this data you are opting in to share it with several hundred people, mostly complete strangers to you, mostly scattered all over the US and a few foreign countries.
At that point I'm not sure if the different between just sharing it with them and sharing it with the world is meaningful.
to me, the takeaway is that we need to roll out passkeys as quickly as possible.
23andMe's argument seems ridiculous on its face.
How would they know this?
On the other hand, I remember thinking ten years ago or whatever: "23AndMe sounds cool, I'd love to know about my ancestry and genetic risk factors, but that's a crazy amount of intensely personal data to trust a corporation with, so I guess I won't do that." And I'm as dumb as a rock, so if I made that decision with the same information as everyone else, it must have been pretty obvious what the consequences could be.
Any kind of storage is a non-starter.
This is a tough population to increase the security for. They are highly vulnerable to social engineering, reuse passwords, use weak passwords, and struggle mightily with 2FA or other methods. But that's the gig, it's on 23andMe to solve it.
https://ia904506.us.archive.org/10/items/gov.uscourts.cand.3...
Almost all of them are in N.D. Cal but there is one filed in N.D. Ill. and one in C.D. Cal.
In all honesty, you can hardly make this claim unless they properly communicated and mandated (at least in writing, since I can't imagine how it could be actually enforced) that users chose/pick passwords different from other platforms. Or at the least enforce an aggressive password change schedule, etc...
I would have never guessed people would be interested in such useless information.
The data breach by which attackers get their hands on passwords isn't the fault of the users.
Only the consequence of that breach to some of the users is their own fault.
Much like Uber, self-enshitification was obviously the "???" part of the underpants gnomes' plans.
I mean. If people reused passwords for 23andMe, is this really 23andMe's fault? Should they have required 2FA for everything? That's kind of a hard sell tbh.
[0] https://www.washingtonpost.com/technology/2023/10/12/23andme...
[1] https://customercare.23andme.com/hc/en-us/articles/212170688...