At least a million data points from 23andMe accounts appear to have been exposed on BreachForums. While the scale of the campaign is unknown, 23andMe says it’s working to verify the data.

  • rcbrk
    link
    fedilink
    arrow-up
    31
    arrow-down
    1
    ·
    1 year ago

    Even though the company didn’t really do anything truly wrong in this case, as it’s simply users reusing passwords, they still should have been better/more proactive especially with such sensitive information

    There’s nothing special or new or unique or unforseen about the security requirements of 23andMe.

    They absolutely failed to implement an appropriate level of security measures for their service.

    Mandatory 2FA could’ve prevented this.

    • Parabola@lemmy.world
      link
      fedilink
      arrow-up
      6
      arrow-down
      1
      ·
      1 year ago

      Part of the issue is the average person using a service like this, and people comfortable with MFA don’t really overlap.

      • clanginator@lemmy.world
        link
        fedilink
        arrow-up
        14
        ·
        1 year ago

        I mean, too bad. You’re accessing the results of your genetic data that contain sensitive personal information on relatives as well as yourself. Banks require 2FA, and people figure out how to use that.

      • rcbrk
        link
        fedilink
        arrow-up
        7
        arrow-down
        1
        ·
        1 year ago

        Hence the key word: mandatory.

        • Parabola@lemmy.world
          link
          fedilink
          arrow-up
          1
          ·
          1 year ago

          Oh I didn’t miss that. Would it be a good business decision for nascar to force people wanting to buy live tickets to eat a vegan meal?

          • rcbrk
            link
            fedilink
            arrow-up
            1
            arrow-down
            1
            ·
            1 year ago

            “We sent you an SMS with a 4 digit number, please type it in this box” is a pretty low bar.