It's not on 23andMe, or anyone (other than the user) for that matter, to ensure the passwords used by the user are not copied passwords from other credentials.
Seems to me like passwords need to be regulated on a governmental level, but that's a can of worms of an idea that I am not ready to defend.
Credential stuffing is most preventable by the user (who can simply not reuse passwords), but platforms have a responsibility as well. They can at least mitigate it through rate limiting, and mostly stop it with 2FA requirements.
If an attacker is able to exfiltrate millions of records from a platform with credential stuffing, that means they tried to login to multiple millions of accounts. It shouldn't be difficult for a service to detect and stop such a sustained level of load on its login infrastructure. You can't get millions of proxies.
I work on combating credential stuffing on a regular basis... it's quite challenging.
They could have prevented that by not keeping the data longer than needed to send it to the user.
I don't really think this needs to be regulated; government-standard guidelines are probably sufficient, with companies knowing that deviating will expose them more to litigation in the event of a problem.
Not trying to argue with you, I did read your last sentence, just tossing in another POV.
Sort of a "negative security externality"...
It's simply easier for me, as a human, to remember that my password for all websites is Hunter2, rather than spend the extra time, create a password manager account, store passwords, utilize best password management practices, etc. Not saying this is what I do, but for many people, this is how they remember their password(s).
Maybe I should have changed the "tricked into" to "trick themselves", but I'm just a human and this was easier for me.
In my opinion, it is, actually, on 23andMe. At my tiny startup, I implemented a simple check against Troy Hunt’s compromised password database.[1] If I can do it, 23andMe can.
If anyone reading this is in the business of making web apps and there’s literally anything of value behind your login, prioritize this mitigation. OWASP recommends it too. [2]
1. https://haveibeenpwned.com/Passwords
2. https://cheatsheetseries.owasp.org/cheatsheets/Credential_St...
Source: https://www.linkedin.com/feed/update/urn:li:share:7116053429...
And all their relatives (who share a lot of their DNA after all)
Seriously — what are people going to do with it? It's illegal for insurance companies to discriminate. I'd post it myself on GitHub if anyone showed the slightest interest in using it.
You're confident enough that nothing can be done, to the point that you'd take the risk for no upside. That... doesn't sound rational to me?
We know now, they are going to leak it.
Everyone is going to know that I'm an Ashkenazi Jew who is more likely going to have blue or brown eyes and hair loss.
Whooops.
We know where Meryem was born (govt records which you probably helped make public), we can read James' twitter feed and we know the relatives of political figures (except for all the illegitimate children).
So yea... I'm still not seeing the issue here.
We are assuming James posted such details to a public twitter feed. That does not account for the others who did not. The issue in Meryem's case is that obtaining birth records is not guaranteed (especially from a foreign country), and that birth location isn't the same as genetic ancestry. Regarding Alex:
> except for all the illegitimate children
That is part of my point. If my absent parent were actually some famous politician, I would personally not want to have that information leaked. Some might not care - that's great. My point is a simple one - just because having private medical info exfiltrated is not really a big deal for many people, doesn't mean that it's ok to give a pass to the parties responsible for the exfiltration.
Your original comment was all about hypotheticals, so yes, it opens up the discussion to assumptions.
Agreed that, in general, it sucks that stuff leaks out. That said, every time someone brings up 23andme, it feels like one of those "the govt is going to shut down in a week if we don't do something!" type of headlines that seem to be on repeat... where in the end it turns out that at the last minute, something is done to prevent it, and everything turns into a giant nothing burger.
> More that govt's, in general, have a habit of leaking personal information for their own benefit.
I 100% agree with this.
Cheers!
For how long ? Being jewish on record in Germany in 1930 was fine, in 1940 not so much
Data is forever, laws, regulations, governments, &c. aren't
If you want to take that bet, let me know and I will send you my contact info.
Get back to your crystal ball and tell me when the war in Ukraine will end and how much will a btc be worth in 5 and 10 years
If people in this forum believe Musk when he says fully autonomous vehicles will be there in two years (since 2012) and that the AI singularity is coming this decade, the possibility of genetic testing being extended to pre conditions isn't so crazy
Genetic data will definitely be used to limit freedom of movement somewhere on Earth in the next 25 years. We’ve already been mass-swabbing for COVID for the past three years, so it won’t be that big a change.
well well well
A concrete example: What could the consequences in today's USA political climate be of having a massive database be with columns: Firstname, Lastname, y_chromosome_present.
Only for health insurance. Other types of insurance companies are free to use that data to discriminate against you, include life, disability, and long-term care insurance.