3 ms·
It is an option. Every user has the option to setup MFA when they set up their account. The fact that people reused their passwords and chose not to setup MFA i
by dpkonofa 3y ago
It is an option. Every user has the option to setup MFA when they set up their account. The fact that people reused their passwords and chose not to setup MFA is not 23andme’s fault.
- toomuchtodo 3y agoAs a 23andme user who has filed a complaint with the FTC, purposely opted out of arbitration and intending to join a class action, and is responsible for customer IAM at a fintech, I politely disagree. Poor IAM and AAA decisions are a choice, and there must be consequences for resulting harm.
- brvsft 3y agoLol, enjoy your $20 because someone reused their password.
- toomuchtodo 3y agoI don't care about the money, let the lawyers and regulators extract. That is the incentive mechanism.
- dpkonofa 3y ago[flagged]
- toomuchtodo 3y agoI absolutely have an axe to grind against consumer harm incurred by lazy and/or negligent technology companies (all companies, really, just scoping for this convo). Guilty as charged. When good behavior is not forthcoming, spin up regulators and the legal framework. EDIT: I do not believe this is an unreasonable position to take. Years ago, I interviewed with the CTO of 23andme and almost took an infra job there (comp too low) ~12 years ago. I am a customer. I have mostly good things to say about them as an org. That is not a free pass when you do harm. Do better, it is not hard.
- dpkonofa 3y agoIt’s not lazy or negligent on the part of the website when they offer additional security and users choose not to use it. 23andMe asks multiple times for users to set up 2FA and apps like 1Password and Bitwarden recognize that it’s available and prompt users to set it up.
- function_seven 3y agoIt is when those users' passwords unlock not just their own data, but that of millions of other users as well. Alice could have set up 2FA and adhered to all the best practices, but she still got her data stolen because Bob used "hunter2" and was hacked. 14,000 accounts compromised, 7 million users' data taken. There's no way 23andMe should be able to offload their responsibilities to Alice's cousin Bob.
- dpkonofa 3y agoThat's not what happened. The 7 million users didn't have their data stolen. The compromised accounts had access to data that those users opted-in to share with those accounts. Imagine that you have a bank account and you share access to it with a family member. If they use "Password1" for their password and someone gets into their account and then, by extension, has access to whatever level of access you've provided them to your account, is that the bank's fault? Is it yours? Is it your family member's?
- function_seven 3y agoYour analogy doesn't fit here. There is no scenario where accessing the accounts of 14,000 banking clients would then blow up to several million clients' accounts. Any bank that even offered this "feature" would, yes, be at fault. There seems to be some transitiveness going on here. Let's go with the banking scenario: I give my son access to my checking account, and I also give my business partner access. My son is a dumbass, and uses the same password for everything. Now my business partner's info is taken. His parents get hacked as well. From 14,000 to 7,000,000 is quite the amplification. That's on 23andMe and nobody else.
- godelski 3y agoUnfortunately the majority of people aren't very tech literate. We have to remember HN is far from average. The company I work for forces MFA and I think if you have sensitive data like this, yes, you should force MFA. Truth be told, it's not going to enter the public lexicon until some big players start forcing adoption. Rule of thumb: if my grandma wouldn't know to do it, I shouldn't expect my users to do it. If you expect your users to use bad practices, then you're not doing your job well. Idk if we should say it's somebody's fault when that somebody is a non-expert and is making a reasonable choice.