all 8 comments

sorted by: hot top controversial new old
[–] 20 points 2 years ago

People should have woken up to password security being their responsibility after story after story on how bad actors will own your email account, wait for a large e-transfer to appear in your inbox, then steal it by using the same email password on your bank's site. It was an unavoidable story at least in Canada.

Having said that, is there not an onus on 23 to detect someone scraping millions of profiles from a feature ostensibly for looking at a few close relatives? Surely looking at 492 "relatives" on one account in quick succession isn't normal behaviour.

I'm just glad I didn't end up ordering a kit when they were being hyped massively.

  • source
  • [–] 17 points 2 years ago* (2 children)

    Yeah this is like 85% the users fault. If the website stores passwords in plaintext, it's their fault. If the user used "password" as a password it's their fault. The site could have been more helpful by having a cool down between incorrect passwords and monitor of failed attempts. Also maybe limiting the data shared between relatives. But like with Facebook, if you gain access to someone's account you will see their friends too.

  • source
  • hideshow 2 child comments
  • [–] 13 points 2 years ago (2 children)

    It is. It was from people reusing passwords that were compromised.

  • source
  • hideshow 2 child comments
  • [–] 1 point 2 years ago

    Apparently you failed to read and/or comprehend the article.

    “From these 14,000 initial victims, however, the hackers were able to then access the personal data of the other 6.9 million million victims because they had opted-in to 23andMe’s DNA Relatives feature. This optional feature allows customers to automatically share some of their data with people who are considered their relatives on the platform.”

  • source
  • parent
  • [–] 11 points 2 years ago

    After disclosing the breach, 23andMe reset all customer passwords, and then required all customers to use multi-factor authentication, which was only optional before the breach.

    Last I checked, that is still optional but highly recommended.

  • source