this post was submitted on 06 Oct 2023
393 points (97.1% liked)
World News
32316 readers
1301 users here now
News from around the world!
Rules:
-
Please only post links to actual news sources, no tabloid sites, etc
-
No NSFW content
-
No hate speech, bigotry, propaganda, etc
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
I can't believe people voluntarily sent them their DNA.
The worst part is it you have enough family members who used these services your details are likely on there too.
Though if neither a father nor his sons have submitted their DNA, the service will lack all that Y-DNA though, right? I'm glad I made the right decision to not send in my DNA to those sites, despite my sisters hounding me to do it after our dad refused, lol.
It's a shame though, because family genetic networking is interesting, but it just goes to show you can't trust these companies. (Even though the company didn't really do anything truly wrong in this case, as it's simply users reusing passwords, they still should have been better/more proactive especially with such sensitive information)
There's nothing special or new or unique or unforseen about the security requirements of 23andMe.
They absolutely failed to implement an appropriate level of security measures for their service.
Mandatory 2FA could've prevented this.
Part of the issue is the average person using a service like this, and people comfortable with MFA don’t really overlap.
I mean, too bad. You're accessing the results of your genetic data that contain sensitive personal information on relatives as well as yourself. Banks require 2FA, and people figure out how to use that.
Hence the key word: mandatory.
Oh I didn’t miss that. Would it be a good business decision for nascar to force people wanting to buy live tickets to eat a vegan meal?
"We sent you an SMS with a 4 digit number, please type it in this box" is a pretty low bar.