3 ms·
No, we're not playing a semantics game. The access wasn't "unauthorized" if the person that "hacked" it was using the person's right email and password. MFA was
by dpkonofa 3y ago
No, we're not playing a semantics game. The access wasn't "unauthorized" if the person that "hacked" it was using the person's right email and password. MFA was also available and the hacked accounts did not have it enabled. It's not 23andMe's fault that users reused passwords and chose not to enable MFA. This isn't about weak passwords or passwords that were known to be leaked on sites like HaveIBeenPwned. Was there more they could have done? Of course. Is it their fault? Absolutely not. Are they liable in any sort of legal sense? Absolutely not.