Live data from Hacker News

Hackers got nearly 7M people's data from 23andMe

theguardian.com

11–20 of 41 posts

Re: Hackers got nearly 7M people's data from 23andMe

#11
post #4

Earlier quoted context omitted.

What would you suggest? Storing data on the blockchain where costs per GB are tens of orders of magnitude higher?

No, storing multiple copies on _encrypted_ data with private keys in possession of the owners of data, not companies processing / storing it. That way you could leave those files on an HTTP server and it would be safe. The driver for centralised storage of DNA and other data is the business model based on resale of the data in raw or processed form.

Until the customer loses the key, which is essentially what happened here...

Re: Hackers got nearly 7M people's data from 23andMe

#14
post #12

Are there any reports of anyone actually harmed by this, or is it all tiresome righteous indignation?

How would you correlate this breach with actual harm? If somebody, say, hacks into one of your other accounts, or opens credit in your name, it's not always obvious where they got your info.

Re: Hackers got nearly 7M people's data from 23andMe

#15
post #12

Are there any reports of anyone actually harmed by this, or is it all tiresome righteous indignation?

Are you saying you'd be ok a company leaking not just your sequenced DNA (and the avalanche of things that says about you), but who you're related to, by DNA?

Re: Hackers got nearly 7M people's data from 23andMe

#16
post #14
post #12

Are there any reports of anyone actually harmed by this, or is it all tiresome righteous indignation?

How would you correlate this breach with actual harm? If somebody, say, hacks into one of your other accounts, or opens credit in your name, it's not always obvious where they got your info.

Or if a neo-Nazi firebombs your house, your cousin's house, your parents' house, and some guy who you didn't know was your uncle since he was given up for adoption, but was also Jewish. How do you correlate that to a data breach?

That's why this data breach is so dangerous. It helps fill in nearly every stepping stone for bad actors, all the way to the baddest of them, to cause harm or exploit someone.

Re: Hackers got nearly 7M people's data from 23andMe

#17
post #11

Earlier quoted context omitted.

No, storing multiple copies on _encrypted_ data with private keys in possession of the owners of data, not companies processing / storing it. That way you could leave those files on an HTTP server and it would be safe. The driver for centralised storage of DNA and other data is the business model based on resale of the data in raw or processed form.

Until the customer loses the key, which is essentially what happened here...

If the customer loses the key to the encrypted data, then it's useless to everyone, including bad actors.

This is not what happened here. 23&Me exercised poor security. I deal with financial data for my job, (like, transactional data, for most Americans), and I would consider that less sensitive than DNA data. We lock that transactional data up so tight it'd make your head spin. If it's data about an individual, in the wrong hands, it can do harm. If you're in the business of people's data, you cannot be stupid about protecting that data. 23&Me is (was) very much in the business of people's data, and could afford and attract the best talent to ensure the data was encrypted and protected.

They're reaping what they sowed.

Re: Hackers got nearly 7M people's data from 23andMe

#18
post #13

Wait, people give their real name and DOB when registering with 23andMe? Not blaming the victim, just pointing out that if a company doesn't need to know your real name, why give it to them?

One might ask the same of us who use our initials on hacker news.

Re: Hackers got nearly 7M people's data from 23andMe

#19
post #10

Where is the wall to wall 24x7 coverage of this? I guess if it's not a company that is competing for eyeballs and clicks then it's not a big deal...

It was already extensively covered when it was new.

It probably died down because when you strip the sensationalism from the stories it comes down to this.

1. Bad guys took leaked emails and passwords that were leaked from other sites and tried them on 23andMe.

2. 14000 of those people in those leaks from other sites had 23andMe accounts and used the same email and password at 23andMe.

3. That gave the bad guys access to everything on those accounts.

4. 23andMe has an opt in feature that shows you all your relatives on 23andMe who have also opted in. "Relative" means people out to 4th cousins. Mine has 1500, although I suspect that the average is more like 700.

5. The majority of 23andMe users opt in to relative sharing. This is not surprising since finding relatives is one of the major reasons people use DNA testing services.

6. If you are on 23andMe and opted into relative sharing, and any one of your relatives who also opted in is one of the 14000 from #2, then the bad guys can see your name, geographical area, and DNA relationship to your relative from #2 on that person's relatives list.

7. That turns out to be about 7 million people.

Re: Hackers got nearly 7M people's data from 23andMe

#20
post #11

Earlier quoted context omitted.

Until the customer loses the key, which is essentially what happened here...

If the customer loses the key to the encrypted data, then it's useless to everyone , including bad actors. This is not what happened here. 23&Me exercised poor security. I deal with financial data for my job, (like, transactional data, for most Americans), and I would consider that less sensitive than DNA data. We lock that transactional data up so tight it'd make your head spin. If it's data about an individual, in…

They didn't require 2FA. That's the only arguably poor security I see. Is there something beyond that they should have done?
Post reply on HN