News: 1704393010

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Infosec experts divided over 23andMe's 'victim-blaming' stance on data breach

(2024/01/04)


23andMe users' godawful password practices were supposedly to blame for the biotech company's October data disaster, according to its legal reps.

Nope, the biotech firm's infrastructure management was certainly not at fault in any way when 6.9 million users had their data compromised after some 14,000 accounts were broken into via credential stuffing.

Users recycling credentials compromised in separate, unrelated breaches has been pinpointed by 23andMe as the main reason why a boatload of data ended up in the hands of cybercriminals. The lack of mandatory 2/MFA or checks for compromised credentials used on the site, for example, is not cited as a significant influence.

[1]

The claims were made in a [2]letter [PDF] sent to the lawyers representing customers behind a lawsuit against 23andMe, alleging violations against the California Privacy Rights Act (CPRA), the California Confidentiality of Medical Information Act, the Illinois Genetic Information Privacy Act (GIPA), and various common laws.

[3]

[4]

The letter, which was first [5]reported by TechCrunch, read: "As set forth in 23andMe's October 6, 2023 blog post, 23andMe believes that unauthorized actors managed to access certain user accounts in instances where users recycled their own login credentials – that is, users used the same usernames and passwords used on 23andMe.com as on other websites that had been subject to prior security breaches, and users negligently recycled and failed to update their passwords following these past security incidents, which are unrelated to 23andMe. Therefore, the incident was not a result of 23andMe's alleged failure to maintain reasonable security measures under the [6]CPRA ."

Hassan Zavareei, one of the lawyers representing the plaintiffs in the case, said the company is neglecting customers and downplaying the seriousness of the incident.

[7]

The [8]blog post referenced in the letter, last updated on December 5, differs very little from the wording of the company's lawyers, making all the same points, just without playing the blame game so directly.

There is no reference to user negligence or failure in the blog, and its most recent update is concluded with a list of the additional measures the company has implemented to protect users from attacks in the future.

From a PR perspective, the response from the biotech company was described as striking completely the wrong tone. Yvonne Eskenzi, co-founder of infosec PR agency Eskenzi, said: "From a crisis comms standpoint, 23andMe's response to its breach misses the mark completely.

[9]

"The decision to blame the victims has fuelled negative press, dodged responsibility, and failed to express any compassion towards those impacted. While this is probably heavily driven by the company's legal department, the letter's tone will likely anger customers and fuel backlash. Ultimately, in many cases, the average person may not know that their password has been compromised elsewhere. It is up to an organization to make sure that its security measures are robust enough to mitigate any end-user risk. Publicly downplaying the risk and deflecting blame is undoubtedly poor PR."

In the infosec industry, experts appear to be divided on the matter, although the majority opposed the stance of 23andMe.

"Organizations should take responsibility for any cyber breaches that occur within their infrastructure," said James McQuiggan, security awareness advocate at KnowBe4.

"In today's society, multi-factor authentication should be the standard of access, authentication, and authorization when accessing sensitive information like personally identifiable information. This feature significantly reduces the risk of a successful attack due to credential stuffing and password reuse by its users."

Prior to the [10]data breach in October , 23andMe did not mandate the use of 2FA, but said it has supported authenticator app-based 2FA since 2019.

Many others opposed the company's stance, including Rachel Tobac, CEO at SocialProof Security and member of CISA's Technical Advisory Council, who said the implementation of tools to check whether credentials have been compromised would be an effective countermeasure.

"Most organizations still allow users to sign up and continue to use passwords on their platform that have been known as compromised and could be used against their users in a credential stuffing attack on their platform," she [11]said . "I recommend discussing integrating HaveIBeenPwned ASAP into your sign-up/sign-on flows to limit this real risk."

The average internet user is unlikely to be aware of the different tools available to check the safety of their [12]reused credentials , relying on the platforms they engage with to alert them in the same way they typically do for weak passwords during the sign-up phase.

[13]Infostealer malware, weak password leaves Orange Spain RIPE for plucking

[14]Formal ban on ransomware payments? Asking orgs nicely to not cough up ain't working

[15]23andMe responds to breach with new suit-limiting user terms

[16]Cybercrim claims fresh 23andMe batch takes leaked records to 5 million

Arguably, even fewer may be aware of the full consequences of reusing compromised credentials, or what a credential stuffing attack is, even if they had been made aware they were previously compromised.

The recommendation to implement the [17]HaveIBeenPwned API was one many commentators echoed, and 2FA not being the default setting was another prominent criticism.

"Password reuse is a well-known security faux pas but it continues to occur and is often seen as a two-way street especially if second-layer authentication is not available," said Jake Moore, global cybersecurity advisor at ESET.

"Furthermore, access to large amounts of data must never be stood behind a password alone due to this age-old issue. The most successful way to counterattack password stuffing is to implement MFA by default for all users and accept the risk of losing users who are not willing to accept this protection feature."

Not all industry pros were aligned in their thinking, though. Infosec consultant Paul Moore, for example, said "passwords are chosen relative to the importance of the data it protects."

"If you reuse a weak password to 'protect' your 23andMe data, you have to accept some, if not all liability when the inevitable happens... assuming that's the point of entry," he [18]posted to X. "Firms can only do so much."

Robert Graham, cybersecurity expert and owner of Errata Security, also took to the platform backing 23andMe, [19]saying : "It's the customer's fault that they got hacked. It's something the customer did, not something 23andMe did. If you deliberately drive into a tree with your Toyota, it's not Toyota's fault you crashed your car," before being pulled apart in the replies.

The Register approached 23andMe for comment but it did not respond. ®

Get our [20]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZZc4nX@9QQDde10zCjysKAAAAEM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.documentcloud.org/documents/24252535-response-letter-to-tycko-zavareei-llp

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZZc4nX@9QQDde10zCjysKAAAAEM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZZc4nX@9QQDde10zCjysKAAAAEM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://techcrunch.com/2024/01/03/23andme-tells-victims-its-their-fault-that-their-data-was-breached/

[6] https://www.theregister.com/2023/01/31/calif_ag_mobile_app_developers/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZZc4nX@9QQDde10zCjysKAAAAEM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://blog.23andme.com/articles/addressing-data-security-concerns

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZZc4nX@9QQDde10zCjysKAAAAEM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2023/12/11/in_brief_security/

[11] https://twitter.com/RachelTobac/status/1742653980252217684

[12] https://www.theregister.com/2020/05/05/logmein_password_survey/

[13] https://www.theregister.com/2024/01/04/orange_spain_outage_breach/

[14] https://www.theregister.com/2024/01/03/ban_ransomware_payments/

[15] https://www.theregister.com/2023/12/11/in_brief_security/

[16] https://www.theregister.com/2023/10/19/latest_23andme_data_leak_takes/

[17] https://www.theregister.com/2021/06/01/in_brief_security/

[18] https://twitter.com/Paul_Reviews/status/1742860262720340358

[19] https://twitter.com/ErrataRob/status/1742760868968853505

[20] https://whitepapers.theregister.com/



MOH

So that's two security "experts" who might struggle to find work in the near future

Jou (Mxyzptlk)

Future managers!

So "forced password change policy" is back in the game?

Jou (Mxyzptlk)

Including the 20 previously used passwords? And they all time out at different times? And all those sites check against each other if the hash has already been used, so mutli-use of a password is not possible any more? And add a technique where it is possible to check the similarity of a password without knowing the password just from the hash? (wargh, this is getting out of hand....)

I just never understand

IGotOut

why people want pay to give the single most unique piece of data they have, to get some psuedo science saying 10 generations ago a relative managed to have sex with someone from another country.

Re: I just never understand

Anonymous Coward

Well, one of my co-workers discovered a still-living cousin. Which was a very good outcome in her situation.

And another one discovered her dad had been fooling around. Not so good.

Re: I just never understand

Anonymous Coward

One of my favorite things to come out of DNA testing was the White supremacists that found they had Black relatives.

Re: I just never understand

jmch

"the single most unique piece of data they have"

... That they are leaving behind on every utensil and piece of cutlery they use ands literally continuously discarding millions of copies a day everywhere they go...

Obtaining a specific person's DNA is trivial unless they take up some pretty paranoid security procedures

Re: I just never understand

aerogems

Fuck you! I'm living in my hermetically sealed hamster ball!

Re: I just never understand

cosmodrome

Obtaining, yes. But obtaining millions of samples, analyzing and putting them into a database on the web? Not so much. Selling them in the dark net even less.

"infosec" PR companies

cosmodrome

Why would anyone with a brain even listen to "infosec PR experts"? It's not their job to prevent security breaches but to downplay the damage and white wash their customers' vests. They are *not* security experts, they're primarily PR droids.

* * * * * THIS TERMINAL IS IN USE * * * * *