Live data from Hacker News

Breach exposed more than one million DNA profiles on a major genealogy database

buzzfeednews.com

11–20 of 424 posts

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#11
post #6

This is why I’ve been putting off getting my genome sequenced. One breach and it’s out there forever. I’ve heard good things about nebula[0] as a way to get an anonymous genome but have yet to be motivated enough to take the plunge [0] https://nebula.org/whole-genome-sequencing/

It's kinda sad that the genome sequencing machines need to be fed loads of genomes in order to offer cheap prices for customers. You can't just buy one for home then use it a couple of times to sequence your family. That'd be most privacy preserving, but the fabled 1k whole genome prices are (currently) only available in high throghput machines. OTOH it's also better because that reduces the nonconsensual sequencing.

The federal government could maintain a central database containing the DNA of every citizen. Submitting a sample might be incentivized by barring people from, say, receiving social security, disability, government backed mortgages and student loans, food stamps, tax refunds, and other federal benefits if someone doesn't comply.

The National Institutes of Health, the Centers for Disease Control, the Central Intelligence Agency, the National Security Agency, the FBI, DEA (Drug Enforcement Agency), ATF (Alcohol, Tobacco, and Firearms), ICE, CBP, and DHS (Department of Homeland Security) could then mine the database for insights into disease, epidemics, crime, intelligence, and so many other purposes. Just imagine the possibilities.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#12

For those who are annoyed about the name of the site not being in the title: GEDMatch was phised a few days ago, then yesterday phishing led to the data exfiltration from the Israeli DNA site MyHeritage. https://www.myheritage.com/

I thought myheritage was owned by the Mormons.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#14
post #6

Earlier quoted context omitted.

It's kinda sad that the genome sequencing machines need to be fed loads of genomes in order to offer cheap prices for customers. You can't just buy one for home then use it a couple of times to sequence your family. That'd be most privacy preserving, but the fabled 1k whole genome prices are (currently) only available in high throghput machines. OTOH it's also better because that reduces the nonconsensual sequencing.

The federal government could maintain a central database containing the DNA of every citizen. Submitting a sample might be incentivized by barring people from, say, receiving social security, disability, government backed mortgages and student loans, food stamps, tax refunds, and other federal benefits if someone doesn't comply. The National Institutes of Health, the Centers for Disease Control, the Central Intellige…

In a perfect world, sure, but in the real world this would obviously be ripe for misuse. Hard to tell if you're being serious or not.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#15
post #6

Earlier quoted context omitted.

It's kinda sad that the genome sequencing machines need to be fed loads of genomes in order to offer cheap prices for customers. You can't just buy one for home then use it a couple of times to sequence your family. That'd be most privacy preserving, but the fabled 1k whole genome prices are (currently) only available in high throghput machines. OTOH it's also better because that reduces the nonconsensual sequencing.

The federal government could maintain a central database containing the DNA of every citizen. Submitting a sample might be incentivized by barring people from, say, receiving social security, disability, government backed mortgages and student loans, food stamps, tax refunds, and other federal benefits if someone doesn't comply. The National Institutes of Health, the Centers for Disease Control, the Central Intellige…

[deleted]

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#16
post #9
post #4

Not saying that building databases of DNA is a good idea, but DNA is basically public information. Everyone whose hands you shake (nowadays quite rare) gets copies of it. The Amazon package you get has genes of every human who touched it. If you send it back, you are sending Amazon your genes. The only issue is the sequencing and the consent to use it for purposes like "improving our services" aka improving the ads t…

It is a bit like face recognition databases. In principle, the data is already public-enough. In practice, building these databases enables qualitatively higher levels of surveillance.

[deleted]

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#17

For those who are annoyed about the name of the site not being in the title: GEDMatch was phised a few days ago, then yesterday phishing led to the data exfiltration from the Israeli DNA site MyHeritage. https://www.myheritage.com/

I thought myheritage was owned by the Mormons.

Just out of curiosity, is there a reason for Mormons to especially care about their genealogy?

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#18

For those who are annoyed about the name of the site not being in the title: GEDMatch was phised a few days ago, then yesterday phishing led to the data exfiltration from the Israeli DNA site MyHeritage. https://www.myheritage.com/

What does the GED stand for? Genetic ??? Database?

To someone who grew up in the U.S., GEDmatch sounds like a dating site for people who took a test in lue of completing secondary education.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#19

This is why I’ve been putting off getting my genome sequenced. One breach and it’s out there forever. I’ve heard good things about nebula[0] as a way to get an anonymous genome but have yet to be motivated enough to take the plunge [0] https://nebula.org/whole-genome-sequencing/

Nebula is definitely an interesting entry into the market. There's also Dante Labs[0], which often offers 30x whole genome in the 200-300USD range. You can download all your raw data (including FASTQs, h37-aligned BAMs, and VCFs) from AWS. There are some quality concerns (and they use BGI instead of Illumina sequencers), but at that price it's tempting to do Dante and Nebula as a check on each other.

Dante also has what seems like a pretty good privacy policy, including an option to destroy your saliva sample and delete all your data[1]. Obviously you still have to trust them, but it's a step in the right direction.

There's a good Facebook group for customers of both Dante and Nebula[2].

[0]: https://www.dantelabs.com/

[1]: https://us.dantelabs.com/pages/privacy-policy

[2]: https://www.facebook.com/groups/373644229897409/

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#20

There should be fines big enough to bankrupt the companies who fail to secure data this kind of data. Is there some other way to convince them to take the issue more seriously?

That just pushes them offshore.

I would rather that there be greater security training in software development programs/bootcamps.

I’m a software engineer. I know a lot of software engineers. None of us have ever been trained in security.

Any “best practices” are usually picked up in Stack Overflow conversations.

Post reply on HN