Hope this isn’t a repeated submission. Funny how they’re trying to deflect blame after they tried to change the EULA post breach.

  • Hegar@kbin.social
    link
    fedilink
    arrow-up
    0
    arrow-down
    2
    ·
    6 months ago

    Yeah, 23AndMe has some culpability here, but the lions share is still in the users themselves

    Tell me you didn’t read the article without telling me.

    If 14,000 users who didn’t change a password on a single use website they probably only ever logged into twice gives you 6.9 million user’s personal info, that’s the company’s fault.

    • JohnEdwa@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      2
      ·
      edit-2
      6 months ago

      You didn’t read it either. They gained access to shared information between the accounts because both accounts had enabled “share my info with my relatives” option.

      Logging into someones Facebook and seeing their friends and all the stuff they posted as “friends only” and their private DM discussions isn’t a hack or a vulnerability, it’s how the website works.

      • Hegar@kbin.social
        link
        fedilink
        arrow-up
        0
        arrow-down
        2
        ·
        6 months ago

        Laughing a feature that lets an inevitable attack access 500 other people’s info for every comprimised account is a glaring security failure.

        Accounting for foreseeable risks to users’ data is the company’s responsibility and they launched a feature that made a massive breach inevitable. It’s not the users’ fault for opting in to a feature that obviously should never have been launched.