news.volyx.in

Hacker leaks millions more 23andMe user records on cybercrime forum (techcrunch.com)

490 points by coloneltcb · 1040 days ago · 394 comments on HN

Article summary

A hacker has leaked millions of 23andMe user records on a cybercrime forum, following a previous leak of user data two weeks ago. The leaked data includes information on users from Great Britain and the wealthiest individuals in the US and Western Europe. 23andMe has stated that it is reviewing the data to determine its legitimacy. The company had previously announced that hackers had obtained some user data using credential stuffing, a technique where hackers try combinations of usernames and passwords that are already public from other data breaches.

Main themes

  • data breach
  • password security
  • multi-factor authentication
  • credential stuffing
  • customer responsibility
  • company accountability

What commenters say

  • The blame for the data leak should be placed on 23andMe for not enforcing stronger security measures, rather than on customers for reusing passwords.
  • Implementing multi-factor authentication and password managers could have prevented the leak.
  • Forcing users to have unique passwords for every account is impractical and may lead to other security issues.
  • The term 'credential stuffing' is misleading and does not accurately describe the type of attack that occurred.
  • The scale of the attack suggests that 23andMe's security measures were inadequate, and the company should have detected and prevented the breach.
  • Users are not entirely to blame for reusing passwords, as it is a common practice and can be difficult to manage multiple unique passwords.
  • 23andMe's decision to allow users to opt-in to sharing their genetic data with other users may have contributed to the scope of the breach.