23andMe could have done a better job communicating the risks of sharing your data with random strangers on the internet, but it's also not unreasonable for them to put some level of blame on users. If you wanted to treat that information as secure, you shouldn't have opted in to sharing it with an arbitrary number of strangers.
The only way you’d be affected by this is if you used the same password on multiple sites (where one of those sites actually had a breach) or if you shared your DNA profile (since it is opt-in) with someone that reused passwords. In the latter case, only the info you shared with that person would be accessible to someone using a compromised account.
In other words, if you shared your info with someone you didn’t know and didn’t trust, your info can be used by bad actors.
If 23andMe had made any claim that they took steps to force users to secure their accounts properly or that they implemented measures to prevent data exfiltration then perhaps you could argue that you should have been able to rely on those claims, but as far as I can tell 23andMe made no such claims.
We can argue about whether the office building should have had better security and noticed weird people around, but ultimately it's the accountant's negligence that allowed my info to be compromised, and if I suspected they weren't the best with their security, I should have factored that into who I decided to share my info with.
Legally, logically, and ethically this is an absurd argument on its face.
Also, the turfer comment makes you seem like a conspiracy theorist. There’s nothing untoward or off about the replies you’ve received so far that is off enough to suggest astroturfing.
Even the backwards cybersecurity laws in the US don't work that way.
If you use “Hunter2” as a password for all of your accounts and AOL gets hacked, the hackers know your password is “Hunter2”. If they get into your Facebook or Gmail account because you also used “Hunter2” there, that is neither Facebook’s or Gmail’s fault. It is your own fault.
In your example the site is fully capable of preventing weak passwords or enforcing things like MFA that make this type of attack a lot less effective. It may surprise you to know that most websites already do this!
I think this is why we were all so surprised when Venmo took off in popularity, with everybody's transactions made public by default...
So while I agree with you that those users are not responsible for the accounts that were actually compromised, they were fully responsible for sharing their data on that service without fully thinking the implications through. 23andMe is not blameless--it's their poor security controls that allowed it to happen in the first place--but I strongly feel people do not take security and privacy as seriously as they should and as a result do share at least some of the blame.
Password rotations are dumb and do not improve security.
NIST, Microsoft, etc. didn't decide to change their minds (to now explicitly discourage arbitrary expiration) out of the blue.
See:
https://web.archive.org/web/20180603140100/https://www.cs.un...
>Using this framework, we confirm previous conjectures that the effectiveness of expiration in meeting its intended goal is weak.
Also see:
https://people.scs.carleton.ca/~paulv/papers/expiration-auth...
>in sum, these security-specific observations and the results in Section 3 suggest the security benefit of password aging policies are at best partial and minor. Combining this with the well-known and widely experienced (negative) usability impact of password aging policies, and results [18] mentioned earlier on high predictability of new passwords from knowledge of old, the burden appears to shift to those who continue to support password aging policies, to explain why, and in which specific circumstances, a substantiating benefit is evident.
And:
https://discovery.ucl.ac.uk/id/eprint/20247/2/CACM%20FINAL.p...
>Although change regimes are employed to reduce the impact of an undetected security breach, our findings suggest that they reduce the overall password security in an organization.
There have been several more, and I'm sure that NIST and others did their own additional analysis prior to changing their recommendations which may not have been made public.
I'd venture that this 23andMe situation is one of the scenarios where password expiration could have significantly improved the outcome, but I concede that it was a poor example for me to use.