Author Topic: GEDmatch Security Breach 19 July 2020  (Read 2140 times)

Offline Liviani

  • RootsChat Veteran
  • *****
  • Posts: 576
    • View Profile
Re: GEDmatch Security Breach 19 July 2020
« Reply #9 on: Tuesday 21 July 20 12:52 BST (UK) »
Yes, I can see that. What does it do?

It's just a site with articles about the tech industry. It doesn't "do" anything else that I can see.
mtDNA subclade K1b2b. Father's Y-DNA I-S25383
GEDmatch kit; CF7867455
Father's kit; RY1336515
Mother's kit; AF2312865


Kincardineshire
Sheret, Hosie, Valentine, Crow, Beattie, McArthur, Wyllie.
Angus (Forfarshire)
Adam, Valentine, Ewan, Elder, Guild, Kydd, Bradford, Stronner, Gibson, Cloudsley, Evans, Stewart, Stott.
Perthshire
Small, Robertson, Murray, Kennedy, McGregor
Ross & Cromarty
Cameron, Stewart, Grant
Banffshire - Gamrie
Anderson, Massie

Offline Flemming

  • RootsChat Veteran
  • *****
  • Posts: 913
  • Census information Crown Copyright, from www.nationalarchives.gov.uk
    • View Profile
Re: GEDmatch Security Breach 19 July 2020
« Reply #10 on: Tuesday 21 July 20 12:53 BST (UK) »
Right, ok, thanks.

Offline confusion

  • RootsChat Senior
  • ****
  • Posts: 307
  • I was born poor - and still have all of it
    • View Profile
Re: GEDmatch Security Breach 19 July 2020
« Reply #11 on: Tuesday 21 July 20 20:01 BST (UK) »
If you have concerns you may send them an email directly and I am sure they can help with any questions. It looks like users who did not opt in for law enforcement matching were available for law enforcement matching and, conversely, all law enforcement profiles were made visible to GEDmatch users. I would check your profile when the site if back up just to make sure your settings are how you want them

Quote
FROM GEDMatch:
On the morning of July 19, GEDmatch experienced a security breach orchestrated through a sophisticated attack on one of our servers via an existing user account. We became aware of the situation a short time later and immediately took the site down. As a result of this breach, all user permissions were reset, making all profiles visible to all users. This was the case for approximately 3 hours. During this time, users who did not opt in for law enforcement matching were available for law enforcement matching and, conversely, all law enforcement profiles were made visible to GEDmatch users.
This was the extent of the breach. No user data was downloaded or compromised.
We have reported the unauthorized access to the appropriate authorities and continue to work toward identifying the individuals responsible for this violation.
Today, as we continued to investigate the incident and work on a permanent solution to safeguard against threats of this nature, we discovered that the site was still vulnerable and made the decision to take the site down until such time that we can be absolutely sure that user data is protected against potential attacks. We are working with a cybersecurity firm to conduct a comprehensive forensic review and help us implement the best possible security measures.
This is clearly disappointing for our company, as user privacy and data security are our top priorities. We apologize to our GEDmatch users and our law enforcement customers for the concern and frustration this situation has caused.
Thank you for your continued support of GEDmatch.
If you have questions, please reach out to us at gedmatch@verogen.com. We will update you as soon as we have more information to share.

Good luck with that one

Jim

Willey, Berry, Cox, Davis, Haddock, Hutton, Griffiths/Griffin, Tanner - Worcestershire
Cox, Dudley, Harris, Moore, Neville, Payne - Warwickshire
Chambers, Douds, Dryden, Given, Hamilton, Hassan, McPherson, McWhirter, Simpson, Taggart, Vauls, Whiteside - Ireland/Scotland, Northumberland
Challis, Halls, Heady, Grove, Lawrence - Essex
Foxwell, Imm, Ward - Gloucesteshire
Heady, Collis, Griffin - Hertfordshire
Hurling - Middlesex
Willey, Imm - Monmouthshire
Imm, Hamilton, Hedge, Majury, Sollis - US

Online LizzieL

  • RootsChat Marquessate
  • *******
  • Posts: 7,957
  • Census information Crown Copyright, from www.nationalarchives.gov.uk
    • View Profile
Berks / Oxon: Eltham, Annetts, Wiltshire (surname not county), Hawkins, Pembroke, Partridge
Dorset / Hants: Derham, Stride, Purkiss, Sibley
Yorkshire: Pottage, Carr, Blackburn, Depledge
Sussex: Goodyer, Christopher, Trevatt
Lanark: Scott (soldier went to Jersey CI)
Jersey: Fowler, Huelin, Scott


Offline davidft

  • RootsChat Marquessate
  • *******
  • Posts: 4,209
  • Census information Crown Copyright, from www.nationalarchives.gov.uk
    • View Profile
Re: GEDmatch Security Breach 19 July 2020
« Reply #13 on: Wednesday 22 July 20 10:35 BST (UK) »
This is interesting as i have just seen the email from GEDmatch.

I have not been on this site (Rootschat) for the last few days as my computer was telling me Rootschat security was out of date but looking at the dates of replies to messages on here it obviously was still working or people were ignoring the security message (assuming they got it). All a bit puzzling  ???
James Stott c1775-1850. James was born in Yorkshire but where? He was a stonemason and married Elizabeth Archer (nee Nicholson) in 1794 at Ripon. They lived thereafter in Masham. If anyone has any suggestions or leads as to his birthplace I would be interested to know. I have searched for it for years without success. Thank you.

Offline Liviani

  • RootsChat Veteran
  • *****
  • Posts: 576
    • View Profile
Re: GEDmatch Security Breach 19 July 2020
« Reply #14 on: Wednesday 22 July 20 10:37 BST (UK) »
This is interesting as i have just seen the email from GEDmatch.

I have not been on this site (Rootschat) for the last few days as my computer was telling me Rootschat security was out of date but looking at the dates of replies to messages on here it obviously was still working or people were ignoring the security message (assuming they got it). All a bit puzzling  ???

I had that security message as well. However, I am currently accessing this site from my phone and the security message doesn't appear there strangely.
mtDNA subclade K1b2b. Father's Y-DNA I-S25383
GEDmatch kit; CF7867455
Father's kit; RY1336515
Mother's kit; AF2312865


Kincardineshire
Sheret, Hosie, Valentine, Crow, Beattie, McArthur, Wyllie.
Angus (Forfarshire)
Adam, Valentine, Ewan, Elder, Guild, Kydd, Bradford, Stronner, Gibson, Cloudsley, Evans, Stewart, Stott.
Perthshire
Small, Robertson, Murray, Kennedy, McGregor
Ross & Cromarty
Cameron, Stewart, Grant
Banffshire - Gamrie
Anderson, Massie

Offline davidft

  • RootsChat Marquessate
  • *******
  • Posts: 4,209
  • Census information Crown Copyright, from www.nationalarchives.gov.uk
    • View Profile
Re: GEDmatch Security Breach 19 July 2020
« Reply #15 on: Wednesday 22 July 20 10:39 BST (UK) »
Yes thank you Liviani, I now see the problem was known to Rootschat and there are several posts in various places about it. Phew at least it was not me doing something wrong  ;)
James Stott c1775-1850. James was born in Yorkshire but where? He was a stonemason and married Elizabeth Archer (nee Nicholson) in 1794 at Ripon. They lived thereafter in Masham. If anyone has any suggestions or leads as to his birthplace I would be interested to know. I have searched for it for years without success. Thank you.

Offline Zaphod99

  • RootsChat Senior
  • ****
  • Posts: 272
  • Census information Crown Copyright, from www.nationalarchives.gov.uk
    • View Profile
Re: GEDmatch Security Breach 19 July 2020
« Reply #16 on: Wednesday 22 July 20 13:56 BST (UK) »
I just came to report this, but I am obviously the last to know.

Oddly, I used the site extensively at the weekend and passed on some match details to distant cousins. The following morning, Monday, I couldn't replicate my findings and had to retract what I had said. It was actually very disappointing. I now wonder if there was a co nection. I'll try again when it's back up.

Zaph

Offline Zaphod99

  • RootsChat Senior
  • ****
  • Posts: 272
  • Census information Crown Copyright, from www.nationalarchives.gov.uk
    • View Profile
Re: GEDmatch Security Breach 19 July 2020
« Reply #17 on: Wednesday 22 July 20 14:07 BST (UK) »
Having read the links listed earlier, I now wonder if my earlier research was correct. I don't see how the results could have changed, but I was so sure about what I told cousins. I was so mad at myself for being careless, but now I can't wait for Gedmatch to be up again to check. It was an exciting discovery that I made.

Z