They’re blaming customers for not having good cybersecurity practices instead of themselves for not having good cybersecurity practices.

  • pearsaltchocolatebar
    arrow-up
    17
    arrow-down
    4
    ·
    10 months ago
    link
    fedilink

    23andMe can have all of the security practices they want, but they can’t stop users from reusing passwords from other sites.

    • doppelgangmember
      arrow-up
      17
      arrow-down
      0
      ·
      10 months ago
      link
      fedilink

      Uhh yeah you can

      Mandatory 2FA with phone and password retry count. If it’s targeted using breach data of email/passwords then the 2FA should still stop the majority

      • brbposting
        arrow-up
        2
        arrow-down
        0
        ·
        10 months ago
        link
        fedilink

        Shouldn’t service providers be hashing the plaintext passwords that show up in dark web leaks to see if matching users reused those passwords?

        • folkrav
          arrow-up
          4
          arrow-down
          0
          ·
          10 months ago
          link
          fedilink

          Wouldn’t really be of any use if they’re doing things right and salt their hashes

        • sugar_in_your_tea
          arrow-up
          3
          arrow-down
          0
          ·
          10 months ago
          link
          fedilink

          They typically do, but that doesn’t stop hackers from posting the plaintext.

          The real solution is to never store plaintext and to use MFA.