Comment on 23andMe tells victims it's their fault that their data was breached | TechCrunch

reverendsteveii@lemm.ee ⁨10⁩ ⁨months⁩ ago

“users negligently recycled and failed to update their passwords following these past security incidents, which are unrelated to 23andMe…Therefore, the incident was not a result of 23andMe’s alleged failure to maintain reasonable security measures,”

This is a failure to design securely. Breaking into one account via cred stuffing should give you access to one account’s data, but because of their poor design hackers were able to leverage 14,000 compromised accounts into 500x that much data. What that tells me is that, by design, every account on 23andMe has access to the confidential data of many, many other accounts.

source
Sort:hotnewtop