They're blaming customers for not having good cybersecurity practices instead of themselves for not having good cybersecurity practices.

you are viewing a single comment's thread
view the rest of the comments
[–] 13 points 2 years ago (4 children)

23andMe can have all of the security practices they want, but they can't stop users from reusing passwords from other sites.

  • source
  • hideshow 4 child comments
  • [–] 17 points 2 years ago (3 children)

    Uhh yeah you can..

    Mandatory 2FA with phone and password retry count. If it's targeted using breach data of email/passwords then the 2FA should still stop the majority...

  • source
  • parent
  • hideshow 3 child comments
  • [–] 2 points 2 years ago (2 children)

    Shouldn’t service providers be hashing the plaintext passwords that show up in dark web leaks to see if matching users reused those passwords?

  • source
  • parent
  • hideshow 2 child comments