At least a million data points from 23andMe accounts appear to have been exposed on BreachForums. While the scale of the campaign is unknown, 23andMe says it’s working to verify the data.

  • kungen@feddit.nu
    link
    fedilink
    arrow-up
    19
    arrow-down
    2
    ·
    1 year ago

    Though if neither a father nor his sons have submitted their DNA, the service will lack all that Y-DNA though, right? I’m glad I made the right decision to not send in my DNA to those sites, despite my sisters hounding me to do it after our dad refused, lol.

    It’s a shame though, because family genetic networking is interesting, but it just goes to show you can’t trust these companies. (Even though the company didn’t really do anything truly wrong in this case, as it’s simply users reusing passwords, they still should have been better/more proactive especially with such sensitive information)

    • rcbrk
      link
      fedilink
      arrow-up
      31
      arrow-down
      1
      ·
      1 year ago

      Even though the company didn’t really do anything truly wrong in this case, as it’s simply users reusing passwords, they still should have been better/more proactive especially with such sensitive information

      There’s nothing special or new or unique or unforseen about the security requirements of 23andMe.

      They absolutely failed to implement an appropriate level of security measures for their service.

      Mandatory 2FA could’ve prevented this.

      • Parabola@lemmy.world
        link
        fedilink
        arrow-up
        6
        arrow-down
        1
        ·
        1 year ago

        Part of the issue is the average person using a service like this, and people comfortable with MFA don’t really overlap.

        • clanginator@lemmy.world
          link
          fedilink
          arrow-up
          14
          ·
          1 year ago

          I mean, too bad. You’re accessing the results of your genetic data that contain sensitive personal information on relatives as well as yourself. Banks require 2FA, and people figure out how to use that.

        • rcbrk
          link
          fedilink
          arrow-up
          7
          arrow-down
          1
          ·
          1 year ago

          Hence the key word: mandatory.

          • Parabola@lemmy.world
            link
            fedilink
            arrow-up
            1
            ·
            1 year ago

            Oh I didn’t miss that. Would it be a good business decision for nascar to force people wanting to buy live tickets to eat a vegan meal?

            • rcbrk
              link
              fedilink
              arrow-up
              1
              arrow-down
              1
              ·
              1 year ago

              “We sent you an SMS with a 4 digit number, please type it in this box” is a pretty low bar.

    • macracanthorhynchus@mander.xyz
      link
      fedilink
      English
      arrow-up
      11
      ·
      1 year ago

      Y chromosomes have very little information on them, and the DNA there is pretty highly conserved. You’re not really keeping any secrets by hiding your Y chromosome away.

    • GentriFriedRice@lemmy.world
      link
      fedilink
      arrow-up
      6
      arrow-down
      1
      ·
      edit-2
      1 year ago

      It’s not really like they are storing DNA sequences anyways. They use a genotyping array which just reads ~650k single nucleotide polymorphisms (SNPs).

      An analogy would be 23andme has a 6.4mil page book of DNA for a single customer but they only know the position and letter of single character on every tenth page. Sure it’s enough to identify someone (You can confidently use 50 SNPs to identify these days) but it’s not like 23andme was ever storing a whole genome