Hope this isn’t a repeated submission. Funny how they’re trying to deflect blame after they tried to change the EULA post breach.

  • TheEighthDoctor@lemmy.world
    link
    fedilink
    English
    arrow-up
    26
    arrow-down
    14
    ·
    1 year ago

    And I agree with them, I mean 23andMe should have a brute-force resistant login implementation and 2FA, but you know that when you create an account.

    If you are reusing creds you should expect to be compromised pretty easily.

    • rockSlayer@lemmy.world
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      7
      ·
      edit-2
      1 year ago

      Is it also the User’s fault for the 6,898,600 people that didn’t reuse a password and were still breached?

      • Zoolander@lemmy.world
        link
        fedilink
        English
        arrow-up
        10
        arrow-down
        4
        ·
        1 year ago

        They weren’t breached. The data they willingly shared with the compromised accounts was available to the people that compromised them.

        • SpaceNoodle@lemmy.world
          link
          fedilink
          English
          arrow-up
          4
          arrow-down
          8
          ·
          1 year ago

          Pretty sure nobody clicked a button that said “share my data with compromised accounts.”

          • Zoolander@lemmy.world
            link
            fedilink
            English
            arrow-up
            8
            arrow-down
            4
            ·
            1 year ago

            There was a button that said “share my data with this account”. If that person went and shared that info publicly, how is that any different? The accounts accessed with accessed with valid credentials through the normal login process. They weren’t “breached” or “hacked”.

      • pearsaltchocolatebar@discuss.online
        link
        fedilink
        English
        arrow-up
        11
        arrow-down
        5
        ·
        1 year ago

        Yes, because you have to choose to share that data with other people. 23andMe isn’t responsible if grandma uses the same password for every site.

        • rockSlayer@lemmy.world
          link
          fedilink
          English
          arrow-up
          6
          arrow-down
          8
          ·
          1 year ago

          23andMe is responsible for sandboxing that data, however. Which they obviously didn’t do.

          • pearsaltchocolatebar@discuss.online
            link
            fedilink
            English
            arrow-up
            6
            arrow-down
            2
            ·
            1 year ago

            Did you not read my comment? Users opt in to sharing data with other accounts, which means if one account is compromised, then every account that allowed them access would have their data compromised too. That’s not on the company, because they feature can’t work without allowing access.