A critical factor enabling the attack's success was 23andMe's lack of rate limiting in their login API, which allowed ...