this post was submitted on 08 Dec 2023
36 points (92.9% liked)

Hacker News

1770 readers
1 users here now

This community serves to share top posts on Hacker News with the wider fediverse.

Rules0. Keep it legal

  1. Keep it civil and SFW
  2. Keep it safe for members of marginalised groups

founded 1 year ago
MODERATORS
 

There is a discussion on Hacker News, but feel free to comment here as well.

you are viewing a single comment's thread
view the rest of the comments
[–] rickdg 14 points 11 months ago (1 children)

You aren’t hacked if your users have the same password on another platform that gets hacked.

[–] [email protected] 7 points 11 months ago

agree. at the same time i wonder whether the usual authentication system is adequate given a) the sensitive nature of the data and b) the data's implications for people who have not signed up, e.g., if my cousin signs up and provides data, the data he provides is not really his but, in a way, also mine. so, i wonder how much data processing is really covered by my cousin's consent, given that it is not really his data alone, and whether, given this circumstances, special provisions should have been provided by the processor.

(personally i tend to believe that companies like 23&me should not exist in the first place, given that their operation requires processing of sensitive data from people who have not consented to the use of their data, i.e. processing of relational data should require consent of all related partners.)