I think this is a more broad issue, how do you give the same service for all users, regardless of their level of experience.
I’ve never used 23andMe and yet I’m involved in this breach. How is that a fair shake?
How were you notified? I’ve never used the service but wondered what shadow profiles they may hold.
Doesn’t feel like an unsolvable problem, certainly not one without edge cases but surely we can hit 80/20 without too big a hassle.
Doing low-hanging fruit isn't enough here. Honestly I just don't feel like the time is right to build such big DNA databases yet. Maybe one day with quantum encryption (can't observe the state without modifying it) or whatever else we may figure out, but today it just seems like you're taking a risk for yourself and half a dozen layers of relatives
23andme bears responsibility more than users like banks bear more responsibility for customers choosing stupid pins. DNA info is valuable they need to design good safeguards.
2. Send a postcard to the billing address where you signed up (verified against credit reports) with a one time verification code, upon which some second factor is set up. Maybe put 20 "rescue codes" on the postcard too, if you like.
3. Force user to enable some sort of second factor authentication on their next login.
It will be sold and resold so eventually your TikTok feed will be influenced by your genes.
2. Identify DNA sequences and genes associated with various diseases, then contact you AND your relatives to advise seeing a doctor and consider using drugs made by the new owners of your genetic data
3. Sell your data to insurance companies who would pay plenty for early evidence of breast cancer likelihood or Huntington's Disease so they can avoid insuring you
https://www.cbsnews.com/news/blackstone-private-equity-ances...
"Theoretically" is the operative word here.
2) Is it supported by all websites and apps I use?
3) Is it supported by all devices I use?
Until the answer to all of those is "yes", passwords will remain superior.