4 ms·
>I mean for the 14,000 accounts accessed with compromised login credentials, yes that's logical that it's their fault. The provider has a responsibility here a
by macspoofing 3y ago
>I mean for the 14,000 accounts accessed with compromised login credentials, yes that's logical that it's their fault.
The provider has a responsibility here as well - after all, a breach like this followed by the negative public fallout (and potential lawsuits) represents a risk to the business itself. There are things they could have done to mitigate this risk ... Like enforcing 2FA.
And they did mess up, and they know they messed up. Do you know how I know? Because they just started enforcing 2FA (and not in 2019) [1]
[1]https://blog.23andme.com/articles/enhanced-customer-security-at-23andme-with-2-step-verification https://blog.23andme.com/articles/enhanced-customer-security...