Live data from Hacker News

Breach exposed more than one million DNA profiles on a major genealogy database

buzzfeednews.com

21–30 of 424 posts

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#21
post #9
post #4

Not saying that building databases of DNA is a good idea, but DNA is basically public information. Everyone whose hands you shake (nowadays quite rare) gets copies of it. The Amazon package you get has genes of every human who touched it. If you send it back, you are sending Amazon your genes. The only issue is the sequencing and the consent to use it for purposes like "improving our services" aka improving the ads t…

It is a bit like face recognition databases. In principle, the data is already public-enough. In practice, building these databases enables qualitatively higher levels of surveillance.

Definitely agree. The point I'm trying to make is that DNA is a bit more "private" than your face, as there is a nontrivial cost to sequence it, but in general it's the same level. One day we'll be able to read thoughts and I'm pretty sure that some folks will build thought databases and people might even share their thoughts with the public... and ad companies will love it because they love checking the reactions of people to ads.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#22
As someone who works in cybersecurity, it's always hard for me to interpret PR language like "orchestrated through a sophisticated attack". This could be aimed towards non-savvy readers meaning basically anything or it could be accurate and describe a nation-state (although I don't get the feeling of a sophisticated nation-state actor here).

The DoJ used similar wording when prosecuting Aaron Schwartz for using Python scripts to glue together "curl" calls.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#23

For those who are annoyed about the name of the site not being in the title: GEDMatch was phised a few days ago, then yesterday phishing led to the data exfiltration from the Israeli DNA site MyHeritage. https://www.myheritage.com/

I thought myheritage was owned by the Mormons.

FamilySearch is the Mormon site.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#24

Earlier quoted context omitted.

I thought myheritage was owned by the Mormons.

Just out of curiosity, is there a reason for Mormons to especially care about their genealogy?

> One of the core tenets of Mormon faith is that the dead can be baptized into the faith after their passing. Baptism of the dead evolved from the beliefs that baptism is necessary for salvation and that the family unit can continue to exist together beyond mortal life if all members are baptized.

> Mormons trace their family trees to find the names of ancestors who died without learning about the restored Mormon Gospel so that these relatives from past generations can be baptized by proxy in the temple. For Latter-day Saints, genealogy is a way to save more souls and strengthen the eternal family unit.

http://www.pbs.org/mormons/etc/genealogy.html

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#25
So they sent an email to their users that states:

>We can assure you that your DNA information was not compromised, as GEDmatch does not store raw DNA files on the site. When you upload your data, the information is encoded, and the raw file deleted. This is one of the ways we protect our users’ most sensitive information.

This is kind of BS right? It's encoded... not encrypted.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#26

There should be fines big enough to bankrupt the companies who fail to secure data this kind of data. Is there some other way to convince them to take the issue more seriously?

That just pushes them offshore. I would rather that there be greater security training in software development programs/bootcamps. I’m a software engineer. I know a lot of software engineers. None of us have ever been trained in security. Any “best practices” are usually picked up in Stack Overflow conversations.

Software engineers don't run these companies, executives do. Even if you have security training, that won't do you much good if leadership doesn't value security. If your company stores highly-sensitive data, you need teams dedicated to security, you need regular audits, and you need your entire company trained to handle phishing attacks.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#27
Can someone explain the potential short to medium term fears of one's DNA leaking? My initial assumption is that it would be less of a problem compared to nearly any other personal data leaking. Like it certainly sounds creepy, but credit card or other financial data being stolen presents a huge headache and creates a lot of work.

I understand that in specific instances, for example when paternity is in question or if a person is hiding from someone this information getting out could be catastrophic, but that applies to such a tiny portion of the population. So for most people, what is the downside to some random individual knowing the country of origin one's ancestors are from or that they might have a genetic predisposition to heart disease? It isn't like any reputable company is going to be able to use this information against us.

Plus in the long term there are likely going to be ways to get this information directly and almost instantaneously from any personal interaction you make since we can't really stop ourselves from shedding our DNA wherever we go.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#28
post #18

For those who are annoyed about the name of the site not being in the title: GEDMatch was phised a few days ago, then yesterday phishing led to the data exfiltration from the Israeli DNA site MyHeritage. https://www.myheritage.com/

What does the GED stand for? Genetic ??? Database? To someone who grew up in the U.S., GEDmatch sounds like a dating site for people who took a test in lue of completing secondary education.

One use of GED is for GEnealogical Data[base], or Genealogy Data.

GED files have been used for decades in genealogical circles at least. So I think that's what they're referring to?

https://en.m.wikipedia.org/wiki/GEDCOM, for example.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#29
post #9
post #4

Not saying that building databases of DNA is a good idea, but DNA is basically public information. Everyone whose hands you shake (nowadays quite rare) gets copies of it. The Amazon package you get has genes of every human who touched it. If you send it back, you are sending Amazon your genes. The only issue is the sequencing and the consent to use it for purposes like "improving our services" aka improving the ads t…

It is a bit like face recognition databases. In principle, the data is already public-enough. In practice, building these databases enables qualitatively higher levels of surveillance.

How, exactly? It's not like I can use wide-area instrumentation to locate you via your genome. You can imagine how to do it with cameras and faces, but I just don't see the method for DNA.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#30
post #27

Can someone explain the potential short to medium term fears of one's DNA leaking? My initial assumption is that it would be less of a problem compared to nearly any other personal data leaking. Like it certainly sounds creepy, but credit card or other financial data being stolen presents a huge headache and creates a lot of work. I understand that in specific instances, for example when paternity is in question or i…

My hunch is that if this information is used against you, you'd never know.

First scenario that comes to mind: The insurance company that gives you an extremely high quote because you come back as "high risk" from a 3rd party company that they use to vet applications, and that 3rd party company uses your genetic predisposition for a condition.

Post reply on HN