In an email sent to customers earlier this week viewed by Engadget, the company announced that it had made updates to the “Dispute Resolution and Arbitration section” of its terms of service that would prevent customers from filing class action lawsuits.
PSA: you can request deletion of your 23andMe account. It won’t do anything for this past hack, but it’ll at least prevent your data from being included in future hacks (assuming they actually completely delete your data like they’re supposed to).
They didn’t.
They just made it so you couldn’t see it anymore.
Why would you this wasn’t even a hack for my understanding?
It was a password stuffing attack. Meaning that a bunch of users with reused crappy passwords had their accounts accessed with their legitimate passwords by attackers.
I’m not sure why this reflects horribly on the company in a way that would encourage one to delete their account?
This would be like leaving the key to your apartment in a public place and then complaining about your landlords terrible security when someone accesses your house when you’re not there.