Comment on 23andMe tells victims it's their fault that their data was breached | TechCrunch

<- View Parent
sudneo@lemmy.world ⁨5⁩ ⁨months⁩ ago

Credential stuffing is an attack which is well known and that organizations like 23andme definitely should have in their threat model. There are mitigations, such as preventing compromised credentials to be used at registration, protecting from bots (as imperfect as it is), enforcing MFA etc.

This is their breach indeed.

source
Sort:hotnewtop