Hi everyone,
I know, I'm early this week. I have a full day offsite with my colleagues tomorrow, so I wanted to make sure I got this week's issue finished first :-) Enjoy the read, and have wonderful Friday and weekend!
P.S.: If you're looking for the Breaches section, I've placed it near the end of the newsletter together with the "Issues and fixes" section, just as an experiment to see if that works better for your reading flow.
AWS, Cloudflare and Google have released coordinated announcements to discuss a new DDoS (distributed denial of service) technique named 'HTTP/2 Rapid Reset'. They've been under several attacks since August, with the biggest reaching a whopping 398 million requests per second. To put that into perspective, as stated in the article: the entire Internet sees between 1 and 3 billion requests per second.
The attacks were executed with a relatively small botnet, so we'll very likely see even bigger attacks occur soon. Even more fun is the fact that there isn't really a fix for it, as it abuses a feature of the HTTP2 protocol and can't just be "patched", only mitigated by various anti-DDoS techniques.
The article does a good job of explaining the issue. If you want to dive deeper, here are the posts from all three companies:
This could have been an entry in the breaches section, but it's about a company that analyses and stores genetic information, and that triggers me.
Much is still unclear, but it seems that the data (but not the DNA info? Although the attacker does claim that) of 7 million people was scraped through the DNA Relatives feature of 23andMe, an opt-in feature to find relatives. The leaked dataset explicitly includes the information on 1.3 million people of Ashkenazi (Jewish) and Chinese descent.
Initial access was supposedly gained through credential stuffing, i.e. exploiting password re-use. The company seems to indicate that that is not their fault, but that is just not true. You can mitigate credential stuffing attacks by pro-actively finding re-used passwords and resetting the account, for example. And one can definitely argue that genetic information warrents that kind of proactivity.
The article also includes a warning of a researcher that the (limited) profile of a 23andMe user can be accessed by replacing the ID in the URL.