23andMe responds to breach with new suit-limiting user terms
- Reference: 1702295165
- News link: https://www.theregister.co.uk/2023/12/11/in_brief_security/
- Source link:
In an [1]update on Tuesday to a blog post sharing details of the attack, 23andMe said the breach, first [2]reported in October, was enabled via credential stuffing, through which an attacker uses username and password combinations from other breaches to try breaking into unrelated accounts.
In other words, those hit were guilty of the cardinal sin of password reuse and not enabling multifactor authentication.
[3]
Data stolen, we're told, has been confirmed to come from "DNA relatives" profiles that indicate how folks may be related, of which 5.5 million sets of data were stolen. Data swiped in the breach included names, ancestry information, self-reported location, birth year, links to family trees, and anything that may have been included in self-descriptions added to user profiles.
[4]
[5]
An additional 1.4 million sets of Family Tree data was stolen as well, 23andMe said, which includes similar information as well as relationships to the individuals whose accounts were compromised.
In response, 23andMe seems very concerned at the potential legal ramifications of the breach, and has updated its terms of service in what appears to be an attempt to avoid a wave of lawsuits.
[6]
A side-by-side comparison of 23andMe's [7]new terms of service, dated November 30, and its [8]previous version from October 4 (prior to the breach), teased out a new dispute resolution period of 60 days during which aggrieved customers agree to "first attempt to negotiate any dispute informally … before either party initiates any arbitration or court proceeding."
[9]Hollywood plays unwitting Cameo in Kremlin plot to discredit Zelensky
[10]Five Eyes nations warn Moscow's mates at the Star Blizzard gang have new phishing targets
[11]Apple and some Linux distros are open to Bluetooth attack
[12]Cisco intros AI to find firewall flaws, warns this sort of thing can't be free
Per [13]Axios , 23andMe's terms also include a provision that means customers automatically accept changes to the terms and conditions unless they formally decline [14](email link) the terms in an email within 30 days of being notified of the changes.
Critical vulnerabilities of the week
With it being the end of the year, there's less to report, so lots of critical vulnerabilities that we'd normally include here have [15]been [16]covered already.
As usual, however, there's plenty of ICS advisories to report, though only a couple merit mention as critical threats.
CVSS 9.8 – [17]CVE-2023-3346 : A classic buffer overflow vulnerability in "all versions of Mitsubishi Electric CNC series devices" can cause DoS and allow RCE.
CVSS 8.1 – [18]Multiple CVEs : Sierra Wireless AirLink routers with ALEOS firmware versions prior to 4.9.9 and 4.17.0 contain several vulnerabilities that can lead to credential theft, DoS, RCE, and total takeover.
Hundreds of laptops stolen
A routine traffic stop in California's Yolo County has led to five arrests and the recovery of a cache of laptops stolen from "a well-known Bay Area tech company."
Sheriff's deputies in Yolo County, northwest of the city of Sacramento and north of San Francisco Bay and Silicon Valley, pulled a vehicle over for expired tags recently, and spotted laptops in the vehicle branded with the aforementioned – but unnamed – tech company on them, leading to further investigation.
"After weeks of thorough probing, detectives unraveled a sophisticated retail theft ring involving multiple individuals," the sheriff's department said in a Facebook [19]post Monday. "Executing search warrants across Woodland
a city in Yolo County
led to the apprehension of five suspects and the recovery of 114 stolen laptop computers."It's unclear if the laptops were tampered with to extract information, or if the miscreants were simply looking for hardware to flip for a quick profit.
Ransomware gang shakes down staffers... individually
Health care products and services firm Henry Schein has been reeling since an October cyber [20]attack allegedly perpetrated by the notorious AlphaV/BlackCat ransomware gang, and it's now sending letters to employees whose data – lots of it – has allegedly been stolen as a result of the hit.
[21]Letters are reportedly going out to some 29,112 Henry Schein employees past and present indicating that their names, DoBs, demographics, various forms of government-issued ID, financial information, employment details, photographs and more have been purloined by cybercriminals.
[22]
To make matters worse, talks between HS and AlphaV [23]allegedly broke down last month, causing AlphaV to re-encrypt the company's systems and knock applications offline [24]again [PDF]. It looks like AlphaV either never lost access despite HS's claims to have taken "precautionary action" after the October attack, or easily broke back in.
This isn't Henry Schein's first run-in with what looks like weak security practices. In 2016, the company [25]had to pay a quarter of a million dollars to the US FTC to settle claims it misled customers about its data encryption capabilities and exposure of customer medical records. ®
Get our [26]Tech Resources
[1] https://blog.23andme.com/articles/addressing-data-security-concerns
[2] https://www.theregister.com/2023/10/19/latest_23andme_data_leak_takes/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZXdAN3qefnAmQfGrrsSXjgAAAAI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZXdAN3qefnAmQfGrrsSXjgAAAAI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZXdAN3qefnAmQfGrrsSXjgAAAAI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZXdAN3qefnAmQfGrrsSXjgAAAAI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.23andme.com/legal/terms-of-service/full-version/
[8] https://www.23andme.com/legal/terms-of-service/full-version/4.1/
[9] https://www.theregister.com/2023/12/09/russia_cameo_ukraine_propaganda/
[10] https://www.theregister.com/2023/12/08/five_eyes_star_blizzard_warning/
[11] https://www.theregister.com/2023/12/06/bluetooth_bug_apple_linux/
[12] https://www.theregister.com/2023/12/06/cisco_ai_security/
[13] https://www.axios.com/2023/12/07/23andme-terms-of-service-update-data-breach
[14] mailto:arbitrationoptout@23andme.com
[15] https://www.theregister.com/2023/12/01/iphones_macs_patch/
[16] https://www.theregister.com/2023/12/05/cisa_coldfusion_government/
[17] https://www.cisa.gov/news-events/ics-advisories/icsa-23-208-03
[18] https://www.cisa.gov/news-events/ics-advisories/icsa-23-341-06
[19] https://www.facebook.com/photo?fbid=763192672516611
[20] https://investor.henryschein.com/news-releases/news-release-details/henry-schein-provides-information-cybersecurity-incident
[21] https://apps.web.maine.gov/online/aeviewer/ME/40/6a08eecd-1ccf-451e-a419-a0b873114853.shtml
[22] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZXdAN3qefnAmQfGrrsSXjgAAAAI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[23] https://twitter.com/AlvieriD/status/1720123823062671564
[24] https://investor.henryschein.com/static-files/d6b69e82-44ea-4ad4-b70b-0abd82d8e400
[25] https://www.ftc.gov/news-events/news/press-releases/2016/01/dental-practice-software-provider-settles-ftc-charges-it-misled-customers-about-encryption-patient
[26] https://whitepapers.theregister.com/
They'll need to - they won't be able to apply the new T&C if they didn't follow their own policy. That'd get shredded by any lawyer in court.
The whole "send the email and gamble they don't send an objection" trick is far more likely to work in aggregate, even if a few savvy folk spot the problem.
Plus the lawyers will have a field day with working out if this is even legit in all the numerous different jurisdictions.
As for over here? Well as I understand it, in France, mandatory arbitration is only for non-domestic/consumer contacts (if both parties agree) and it must be separate to the main contact (thus allowing one the option to disagree without breaking the main contact). I think Germany is stricter in this respect, and I suspect both country's legal systems would frown upon something inserted into a contract that appears designed to impede a person's access to legal remedies.
However, as always, lawyers are expensive and looking stuff up in Google will get you a bunch of answers that contradict each other. ;) So don't assume this even remotely resembles legal advice.
That whole (extremely long) dispute section is just an indictment on US consumer laws. It's a series of hoops to jump through which are clearly discriminatory and designed purely to impede the consumer's ability to take legal action. Of course any well run company will put such a system in place if they can get away with it.
The equivalent section in 23andme's European TOS pretty much just says: Let us know if you have any complaint but your statutory rights aren't affected so go to court if you must, whatever.
https://www.23andme.com/en-gb/legal/terms-of-service/#dispute-resolution-arbitration
23AndMe's action is very shady indeed. Most people won't notice that, and I doubt they've sent an email to anyone whose data was nicked informing them of the change to the Ts&Cs.