Hackers got nearly 7M people's data from 23andMe
21–30 of 41 posts
Re: Hackers got nearly 7M people's data from 23andMe
#22Earlier quoted context omitted.
Until the customer loses the key, which is essentially what happened here...
If the customer loses the key to the encrypted data, then it's useless to everyone , including bad actors. This is not what happened here. 23&Me exercised poor security. I deal with financial data for my job, (like, transactional data, for most Americans), and I would consider that less sensitive than DNA data. We lock that transactional data up so tight it'd make your head spin. If it's data about an individual, in…
Re: Hackers got nearly 7M people's data from 23andMe
#23Are there any reports of anyone actually harmed by this, or is it all tiresome righteous indignation?
Are you saying you'd be ok a company leaking not just your sequenced DNA (and the avalanche of things that says about you), but who you're related to, by DNA?
Re: Hackers got nearly 7M people's data from 23andMe
#24Earlier quoted context omitted.
If the customer loses the key to the encrypted data, then it's useless to everyone , including bad actors. This is not what happened here. 23&Me exercised poor security. I deal with financial data for my job, (like, transactional data, for most Americans), and I would consider that less sensitive than DNA data. We lock that transactional data up so tight it'd make your head spin. If it's data about an individual, in…
They didn't require 2FA. That's the only arguably poor security I see. Is there something beyond that they should have done?
Re: Hackers got nearly 7M people's data from 23andMe
#25Re: Hackers got nearly 7M people's data from 23andMe
#26Earlier quoted context omitted.
If the customer loses the key to the encrypted data, then it's useless to everyone , including bad actors. This is not what happened here. 23&Me exercised poor security. I deal with financial data for my job, (like, transactional data, for most Americans), and I would consider that less sensitive than DNA data. We lock that transactional data up so tight it'd make your head spin. If it's data about an individual, in…
They didn't require 2FA. That's the only arguably poor security I see. Is there something beyond that they should have done?
Re: Hackers got nearly 7M people's data from 23andMe
#27Earlier quoted context omitted.
If the customer loses the key to the encrypted data, then it's useless to everyone , including bad actors. This is not what happened here. 23&Me exercised poor security. I deal with financial data for my job, (like, transactional data, for most Americans), and I would consider that less sensitive than DNA data. We lock that transactional data up so tight it'd make your head spin. If it's data about an individual, in…
What lock can protect people's data if the people hand the key over to the bad guy?
Re: Hackers got nearly 7M people's data from 23andMe
#28Wait, people give their real name and DOB when registering with 23andMe? Not blaming the victim, just pointing out that if a company doesn't need to know your real name, why give it to them?
One might ask the same of us who use our initials on hacker news.
Re: Hackers got nearly 7M people's data from 23andMe
#29Earlier quoted context omitted.
If the customer loses the key to the encrypted data, then it's useless to everyone , including bad actors. This is not what happened here. 23&Me exercised poor security. I deal with financial data for my job, (like, transactional data, for most Americans), and I would consider that less sensitive than DNA data. We lock that transactional data up so tight it'd make your head spin. If it's data about an individual, in…
What lock can protect people's data if the people hand the key over to the bad guy?
Re: Hackers got nearly 7M people's data from 23andMe
#30Where is the wall to wall 24x7 coverage of this? I guess if it's not a company that is competing for eyeballs and clicks then it's not a big deal...
It was already extensively covered when it was new. It probably died down because when you strip the sensationalism from the stories it comes down to this. 1. Bad guys took leaked emails and passwords that were leaked from other sites and tried them on 23andMe. 2. 14000 of those people in those leaks from other sites had 23andMe accounts and used the same email and password at 23andMe. 3. That gave the bad guys acces…