3 ms·
> users negligently recycled and failed to update their passwords following these past security incidents, which are unrelated to 23andMe. Therefore, the incide
by block_dagger 3y ago
> users negligently recycled and failed to update their passwords following these past security incidents, which are unrelated to 23andMe. Therefore, the incident was not a result of 23andMe’s alleged failure to maintain reasonable security measures.
23andMe's argument seems ridiculous on its face.
- yreg 3y agoIt doesn't seem ridiculous to me.
- gkbrk 3y agoWhy? You could have a 100% secure website, but if the user gives their credentials to someone else (another website in this case), and that website with bad security gets hacked and leaks the credentials, how is that their fault?
- Spivak 3y agoBecause we've known about credential reuse for 20+ years, developed multiple means to keep a site secure when it happens and then chose to not employ those security measures on data people broadly consider incredibly sensitive. It is your job as a service provider to not allow access to anyone but the authorized user, how you do it is an implementation detail. You can't throw up your hands and say "well we decided that doing that is too hard so we're defining the authorized user as anyone who knows the password."