Live data from Hacker News

Hackers got nearly 7M people's data from 23andMe

theguardian.com

21–30 of 41 posts

Re: Hackers got nearly 7M people's data from 23andMe

#22
post #11

Earlier quoted context omitted.

Until the customer loses the key, which is essentially what happened here...

If the customer loses the key to the encrypted data, then it's useless to everyone , including bad actors. This is not what happened here. 23&Me exercised poor security. I deal with financial data for my job, (like, transactional data, for most Americans), and I would consider that less sensitive than DNA data. We lock that transactional data up so tight it'd make your head spin. If it's data about an individual, in…

What lock can protect people's data if the people hand the key over to the bad guy?

Re: Hackers got nearly 7M people's data from 23andMe

#23
post #12

Are there any reports of anyone actually harmed by this, or is it all tiresome righteous indignation?

Are you saying you'd be ok a company leaking not just your sequenced DNA (and the avalanche of things that says about you), but who you're related to, by DNA?

The company did not leak it. People reuse passwords. "Hackers" just tried passwords from earlier dumps and accessed profiles of people who reused the same password with 23&Me

Re: Hackers got nearly 7M people's data from 23andMe

#24
post #20

Earlier quoted context omitted.

If the customer loses the key to the encrypted data, then it's useless to everyone , including bad actors. This is not what happened here. 23&Me exercised poor security. I deal with financial data for my job, (like, transactional data, for most Americans), and I would consider that less sensitive than DNA data. We lock that transactional data up so tight it'd make your head spin. If it's data about an individual, in…

They didn't require 2FA. That's the only arguably poor security I see. Is there something beyond that they should have done?

I mean that only bad thing makes so much of a difference.

Re: Hackers got nearly 7M people's data from 23andMe

#25
The tricky thing in the case of DNA is, if your relatives were to do a 23andMe, then they inevitably also give away large parts of your DNA. They tracked down the Golden State Killer merely by matching the DNA of a relative. It's a dilemma between one's right to privacy and another one's autonomy.

Re: Hackers got nearly 7M people's data from 23andMe

#26
post #20

Earlier quoted context omitted.

If the customer loses the key to the encrypted data, then it's useless to everyone , including bad actors. This is not what happened here. 23&Me exercised poor security. I deal with financial data for my job, (like, transactional data, for most Americans), and I would consider that less sensitive than DNA data. We lock that transactional data up so tight it'd make your head spin. If it's data about an individual, in…

They didn't require 2FA. That's the only arguably poor security I see. Is there something beyond that they should have done?

Encryption at rest.

Re: Hackers got nearly 7M people's data from 23andMe

#27

Earlier quoted context omitted.

If the customer loses the key to the encrypted data, then it's useless to everyone , including bad actors. This is not what happened here. 23&Me exercised poor security. I deal with financial data for my job, (like, transactional data, for most Americans), and I would consider that less sensitive than DNA data. We lock that transactional data up so tight it'd make your head spin. If it's data about an individual, in…

What lock can protect people's data if the people hand the key over to the bad guy?

The damage is limited to the person who handed over the keys.

Re: Hackers got nearly 7M people's data from 23andMe

#28
post #18
post #13

Wait, people give their real name and DOB when registering with 23andMe? Not blaming the victim, just pointing out that if a company doesn't need to know your real name, why give it to them?

One might ask the same of us who use our initials on hacker news.

It's crucial to include your birth year to confuse the hackers (numbers in names are really confusing, they will give up in no time)

Re: Hackers got nearly 7M people's data from 23andMe

#29

Earlier quoted context omitted.

If the customer loses the key to the encrypted data, then it's useless to everyone , including bad actors. This is not what happened here. 23&Me exercised poor security. I deal with financial data for my job, (like, transactional data, for most Americans), and I would consider that less sensitive than DNA data. We lock that transactional data up so tight it'd make your head spin. If it's data about an individual, in…

What lock can protect people's data if the people hand the key over to the bad guy?

It works for your car keys, credit cards, phones. People who think the current system is the best system we can ever get really lacks imagination

Re: Hackers got nearly 7M people's data from 23andMe

#30
post #19
post #10

Where is the wall to wall 24x7 coverage of this? I guess if it's not a company that is competing for eyeballs and clicks then it's not a big deal...

It was already extensively covered when it was new. It probably died down because when you strip the sensationalism from the stories it comes down to this. 1. Bad guys took leaked emails and passwords that were leaked from other sites and tried them on 23andMe. 2. 14000 of those people in those leaks from other sites had 23andMe accounts and used the same email and password at 23andMe. 3. That gave the bad guys acces…

So, 2FA would've prevented this? Crazy that 23andMe didn't have one mandatory.
Post reply on HN