23andMe told victims of data breach that suing is futile
arstechnica.com
23andMe told victims of data breach that suing is futile
1–10 of 34 posts
Re: 23andMe told victims of data breach that suing is futile
#2Re: 23andMe told victims of data breach that suing is futile
#3Re: 23andMe told victims of data breach that suing is futile
#4I think we all know the answer already.
Re: 23andMe told victims of data breach that suing is futile
#5https://www.nbcnews.com/news/us-news/23andme-user-data-targe...
One could easily see, e.g. a citizen of a middle eastern country who had some surprising Ashkenazi background being targeted for death as a result of this.
Re: 23andMe told victims of data breach that suing is futile
#6even if there's no financial compensation for the victims, it makes sense to make an example out of a company that doesn't actually take data privacy and security seriously.
Re: 23andMe told victims of data breach that suing is futile
#7even if there's no financial compensation for the victims, it makes sense to make an example out of a company that doesn't actually take data privacy and security seriously.
they even offer 2 factor https://customercare.23andme.com/hc/en-us/articles/360034119...
sure they could do better, but are they legally required to be better? They could force 2fa, or 3fa, or 4fa, and disable accounts that go inactive for more than a week and require a validating DNA sample in the mail to reactivate.
if they're "made an example of" what exactly does that mean? at what point is an entity legally responsible for the irresponsibility of it's users?
Re: 23andMe told victims of data breach that suing is futile
#8We'll see how the EU data protection offices feel about that. Just imagine having something like this happen and then giving your customers the finger. The lack of ethics is impressive. I sincerely hope they get fined into oblivion as a nice example to the next medical company that doesn't understand their responsibilities towards their users.
Re: 23andMe told victims of data breach that suing is futile
#9We'll see how the EU data protection offices feel about that. Just imagine having something like this happen and then giving your customers the finger. The lack of ethics is impressive. I sincerely hope they get fined into oblivion as a nice example to the next medical company that doesn't understand their responsibilities towards their users.
And what exactly where their responsibilities that they failed to understand?
You don't engineer a service like 23andme without doing some risk assessment and one of the risks they should have identified and mitigated is password re-use by Joe Average because Joe Average (and his mom) were exactly the demographic that they targeted. Anybody that was somewhat sensitive to the privacy risks wouldn't have used the service in the first place.
Re: 23andMe told victims of data breach that suing is futile
#10Security practices and their ludicrously bad response aside, I cannot fathom why someone would send their literal DNA to a company and then take no steps to secure that information. Is technical literacy really this poor amongst the general population? Even my retiree dad who can't reliably turn on his TV on knows about MFA.