Hope this isn’t a repeated submission. Funny how they’re trying to deflect blame after they tried to change the EULA post breach.

  • Zoolander
    link
    fedilink
    English
    1751 year ago

    I’m seeing so much FUD and misinformation being spread about this that I wonder what’s the motivation behind the stories reporting this. These are as close to the facts as I can state from what I’ve read about the situation:

    1. 23andMe was not hacked or breached.
    2. Another site (as of yet undisclosed) was breached and a database of usernames, passwords/hashes, last known login location, personal info, and recent IP addresses was accessed and downloaded by an attacker.
    3. The attacker took the database dump to the dark web and attempted to sell the leaked info.
    4. Another attacker purchased the data and began testing the logins on 23andMe using a botnet that used the username/passwords retrieved and used the last known location to use nodes that were close to those locations.
    5. All compromised accounts did not have MFA enabled.
    6. Data that was available to compromised accounts such as data sharing that was opted-into was available to the people that compromised them as well.
    7. No data that wasn’t opted into was shared.
    8. 23andMe now requires MFA on all accounts (started once they were notified of a potential issue).

    I agree with 23andMe. I don’t see how it’s their fault that users reused their passwords from other sites and didn’t turn on Multi-Factor Authentication. In my opinion, they should have forced MFA for people but not doing so doesn’t suddenly make them culpable for users’ poor security practices.

      • @[email protected]
        link
        fedilink
        English
        11 year ago

        Common thing, a lot of people despise MFA. I somewhat recently talked with 1 person who works in IT (programmer) that has not set up MFA for their personal mail account.

      • Zoolander
        link
        fedilink
        English
        51 year ago

        It’s just odd that people get such big hate boners from ignorance. Everything I’m reading about this is telling me that 23andMe should have enabled forced MFA before this happened rather than after, which I agree with, but that doesn’t mean this result is entirely their fault either. People need to take some personal responsibility sometimes with their own personal info.

      • Zoolander
        link
        fedilink
        English
        11 year ago

        Laziness alone is a pretty big reason. MFA was available and users were prompted to set it up. The fact that they didn’t should tell you something.

    • @[email protected]
      link
      fedilink
      English
      01 year ago

      I think most internet users are straight up smooth brained, i have to pull my wife’s hair to get her to not use my first name twice and the year we were married as a password and even then I only succeed 30% of the time, and she had the nerve to bitch and moan when her Walmart account got hacked, she’s just lucky she didn’t have the cc attached to it.

      And she makes 3 times as much as I do, there is no helping people.

      • Snot Flickerman
        link
        fedilink
        English
        0
        edit-2
        1 year ago

        These people remind me of my old roommate who “just wanted to live in a neighborhood where you don’t have to lock your doors.”

        We lived kind of in the fucking woods outside of town, and some of our nearest neighbors had a fucking meth lab on their property.

        I literally told him you can’t fucking will that want into reality, man.

        You can’t just choose to leave your doors unlocked hoping that this will turn out to be that neighborhood.

        I eventually moved the fuck out because I can’t deal with that kind of hippie dippie bullshit. Life isn’t fucking The Secret.

        • R0cket_M00se
          link
          fedilink
          English
          01 year ago

          I have friends that occasionally bitch about the way things are but refuse to engage with whatever systems are set up to help solve whatever given problem they have. “it shouldn’t be like that! It should work like X

          Well, it doesn’t. We can try to change things for the better but refusal to engage with the current system isn’t an excuse for why your life is shit.

          • Snot Flickerman
            link
            fedilink
            English
            0
            edit-2
            1 year ago

            The bootlickers really come out of the woodwork here to suck on corporate boot.

            Edit: wrong thread.

            • NoIWontPickaName
              link
              fedilink
              -11 year ago

              What in the fuck are you talking about? You’re the one standing up for the corporation

              • Snot Flickerman
                link
                fedilink
                English
                0
                edit-2
                1 year ago

                Yeah that is my bad, responded to the wrong thread.

                In this case, the corporation isn’t wrong that users aren’t doing due dilligence.

      • dream_weasel
        link
        fedilink
        English
        2
        edit-2
        1 year ago

        Would bet your password includes “password” or something anyone could guess in 10 minutes after viewing your Facebook profile.

        Edit: Your l33t hacker name is your mother’s maiden name and the last four of your social, bro. Mines hunter1337, what’s yours?

      • capital
        link
        fedilink
        English
        01 year ago

        By your logic I hack into every site I use by … checks notes presenting the correct username and password.