💥 Fed cuts sparks mid cap boom! ProPicks AI scores with 4 stocks +23% each. Get October’s update first.Pick Stocks with AI

Assessing the 23andMe data breach: a deep dive into security gaps and recommendations

Published 27/10/2023, 02:10 pm
© Reuters.  Assessing the 23andMe data breach: a deep dive into security gaps and recommendations

The recent data breach at prominent genetic testing service, 23andMe, has exposed not just user data but also critical vulnerabilities in the framework of digital genetic databases.

While the breach itself is disconcerting, what it reveals about the cybersecurity posture of online services that handle sensitive data is even more unsettling.

The data obtained in this breach did not include genetic information but revealed details such as display names, birth years, and sexes of the users.

What happened?

Ealier this month, 23andMe acknowledged the data breach in a blog post, identifying "credential stuffing" as the method of intrusion. In this type of attack, cybercriminals exploit leaked usernames and passwords from previous breaches to gain unauthorised access.

Initially, the breach affected specific ethnic groups, with one million accounts of Ashkenazi Jewish descent and 100,000 of Chinese descent being targeted.

Later revelations indicated a wider impact, with an additional four million general accounts compromised.

It was noted that the compromised accounts had enabled the optional "DNA Relatives" feature, making the data richer and potentially more exploitable.

Security implications

The absence of a comprehensive federal framework to safeguard users of such genetic testing sites leaves a gaping hole in cybersecurity policy.

From a cybersecurity perspective, the optional nature of security features like two-factor authentication (2FA) comes across as a lackadaisical approach to a multi-layered problem.

Security shortcomings and recommendations drawn from the attack are:

  • Lax authentication mechanisms: The attack vector exploited the weakest link in cybersecurity—human error. 23andMe should enforce two-factor authentication (2FA) for all users.
  • Optional security features: Offering essential security measures like 2FA as optional extras undermines data protection. These features should be mandatory.
  • User behavior: 23andMe's current approach puts the burden of security on the user. This is not sustainable. The service should routinely educate its user base on the necessity of employing strong, unique passwords.
  • Periodic security audits: The lapse points to a glaring need for regular security audits to preemptively identify vulnerabilities.

Recommendations for users:

  • Unique passwords: Use a password manager to ensure every account has a unique, strong password.
  • Two-factor authentication: Always opt for additional layers of security, such as 2FA.
  • Optimal use of features: If you are not using features like "DNA Relatives," it is advisable to disable them to reduce your data footprint.

Final thoughts

The 23andMe incident underscores the importance of robust cybersecurity practices in safeguarding sensitive personal data.

While individual user measures can mitigate some risks, the onus of ensuring comprehensive security must lie with the service provider.

Periodic assessments, regular updates, and a mandatory multi-factor authentication policy could provide a more robust security framework.

In an era where data is as valuable as any currency, taking a proactive rather than reactive approach to cybersecurity is not just advisable, but imperative.

Read more on Proactive Investors AU

Disclaimer

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.