当前状态
网络身份
1人物与联系方式
10相关研究
6- 23andMe 将亲属匹配暴露成为同意责任测试
23andMe 是一个风险和问责案例,因为责任问题在于一个用户的账户设置可能暴露亲属信息,因此同意和安全控制必须考虑网络化基因身份而非孤立的账户所有权。公开记录对于需要证据证明客户选择、违规响应和数据管理与基因社会信息敏感性相匹配的客户、亲属、监管机构、基因隐私倡导者、研究人员、身份窃贼、收购方和平台运营商至关重要。
主文章发布时间 2026-07-12 - 23andMe 使亲属成为共模隐私依赖
23andMe 凭证填充事件不仅仅是一个账户接管案例。它表明,一个关系功能可以使一个被攻破的账户成为许多人共模暴露路径,这些人没有重复使用该账户的密码,没有批准恶意会话,也无法看到提取过程。因此,有责的控制问题比登录卫生更广泛:谁管理着共享图谱、默认保证级别、提取成本,以及后来基因和家族背景的所有权?
主文章发布时间 2026-07-12 - 23ANDME 凭据填充漏洞:当亲属成为暴露面
2023 年 23ANDME 事件的核心并非部分用户重用了密码,而是一个成功登录即可暴露众多未重用该密码、未控制被侵账户且无法发现涉及其会话的遗传亲属信息。这种共享资料架构改变了问责衡量标准:身份验证默认值、关系可见度、抓取防护、通知边界和跨境数据治理,均需根据账户的触及范围而非仅凭被接管账户的数量来评判。
主文章发布时间 2026-07-10 - 23andMe made relative-matching exposure a consent-accountability test
23andMe is a risk and accountability case because the accountability issue is that one users account settings can expose information about relatives, so consent and security controls have to account for networked genetic identity rather than isolated account ownership. The public record matters for customers, relatives, regulators, genetic privacy advocates, researchers, identity thieves, acquirers, and platform operators needed evidence that customer choice, breach response, and data stewardship matched the sensitivity of genetic-social information.
主文章发布时间 2026-07-12 - 23andMe made relatives a common-mode privacy dependency
The 23andMe credential-stuffing incident was not only an account-takeover case. It was a demonstration that a relationship feature can make one compromised account a common-mode exposure path for many people who did not reuse that account's password, did not approve the hostile session, and could not see the extraction as it happened. The accountable control question is therefore wider than login hygiene: who governed the shared graph, the default assurance level, the extraction cost, and the later ownership of genetic and family context?
主文章发布时间 2026-07-12 - 23andMe and the credential-stuffing breach that turned relatives into exposure surface
The central fact of the 2023 23andMe incident is not that some customers reused passwords. It is that one successful login could reveal information about many genetic relatives who did not reuse that password, did not control the accessed account and could not see the session that exposed them. That shared-profile structure changes the accountability test: authentication defaults, relationship visibility, scraping controls, notification boundaries and cross-border data governance all have to be judged against the reach of an account, not merely the number of accounts taken over.
主文章发布时间 2026-07-10
最近变化
2- Rir transfer event高置信度历史
- Rir transfer event高置信度历史
