4 ms·
> On one hand, I have to somewhat agree with 23andMe here. If someone uses the password "password1" for some service, they should not be able to turn around and
by Beldin 3y ago
> On one hand, I have to somewhat agree with 23andMe here. If someone uses the password "password1" for some service, they should not be able to turn around and blame that service when their account is compromised.
I call BS. If the service thinks the user's password is acceptable to perform authentication, how should a user know they are actually wrong about that?
Either it is flawed, and therefore the service's job to catch, or it is acceptable. But the service doesn't get to say afterwards "haha, that was really dumb of you, you should have used a stronger password".
- ziddoap 3y ago>Either it is flawed, and therefore the service's job to catch, or it is acceptable. But the service doesn't get to say afterwards "haha, that was really dumb of you, you should have used a stronger password". You are missing the category of attack that happened here. The password was acceptable. But the users used the acceptable password on multiple websites. A different website was breached, and the password was leaked. It is not 23andMe's responsibility to check if other services are breached, cross-reference the users in that other service, get the leaked password list, and then see if those leaked passwords are currently in-use on their website on accounts that are used on both sites. However, as noted in my top-level comment, they should be checking against known-compromised passwords at password creation/change time, and disallow those.
- richbell 3y ago> It is not 23andMe's responsibility to check if other services are breached, cross-reference the users in that other service, get the leaked password list, and then see if those leaked passwords are currently in-use on their website on accounts that are used on both sites. To play devil's advocate here, why not? Plenty of companies (e.g., Tumblr) specifically do this and require email verification + password change if yours was breached. It would make the world a better and more secure place if companies took proactive security measures. There is even a financial incentive for them to do so because it mitigates risk.
- ziddoap 3y ago>It would make the world a better and more secure place if companies took proactive security measures. I _absolutely_ agree. I just do not think it is possible to require every company to monitor every data breach, check those breaches for emails that are in-use on their service, check the passwords (not always possible), and then require a change if the password matches. >Plenty of companies (e.g., Tumblr) specifically do this and require email verification + password change if yours was breached. You're saying that if HackerNews was hacked and my password was leaked, that Tumblr will ingest the breach data, cross-reference if I have a Tumblr account, and then have me change my Tumblr password? Are you sure? Do they have a documented process on how they do this? Edit: I've spent some time now looking at the Tumblr website and do not see any indication that they do this, but would be happy to be corrected. Or a link to any company that does this, it doesn't need to be Tumblr.