this post was submitted on 08 Dec 2023
36 points (92.9% liked)
Hacker News
1770 readers
1 users here now
This community serves to share top posts on Hacker News with the wider fediverse.
Rules
0. Keep it legal
- Keep it civil and SFW
- Keep it safe for members of marginalised groups
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
You aren’t hacked if your users have the same password on another platform that gets hacked.
agree. at the same time i wonder whether the usual authentication system is adequate given a) the sensitive nature of the data and b) the data's implications for people who have not signed up, e.g., if my cousin signs up and provides data, the data he provides is not really his but, in a way, also mine. so, i wonder how much data processing is really covered by my cousin's consent, given that it is not really his data alone, and whether, given this circumstances, special provisions should have been provided by the processor.
(personally i tend to believe that companies like 23&me should not exist in the first place, given that their operation requires processing of sensitive data from people who have not consented to the use of their data, i.e. processing of relational data should require consent of all related partners.)