Live data from Hacker News

Breach exposed more than one million DNA profiles on a major genealogy database

buzzfeednews.com

51–60 of 424 posts

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#51
I’ve always wondered if this were a worthy business proposition, cause I would definitely buy a product like this:

Basically all of the features of 23AndMe/Ancestry/etc, but done offline. You’re given an app to download online, provided all of the hardware needed to spit in a tube, and get the same results.

No data stored on a cloud server, and no centralized database of everyone’s DNA. That’s probably where the real business model is though.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#52

As someone who works in cybersecurity, it's always hard for me to interpret PR language like "orchestrated through a sophisticated attack". This could be aimed towards non-savvy readers meaning basically anything or it could be accurate and describe a nation-state (although I don't get the feeling of a sophisticated nation-state actor here). The DoJ used similar wording when prosecuting Aaron Schwartz for using Pytho…

Unless they come out with details of a convoluted deeper infiltration, escalation of privilege, and careful exfiltration of data over a period of time to escape detection I wouldn't buy the PR bs.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#53
post #51

I’ve always wondered if this were a worthy business proposition, cause I would definitely buy a product like this: Basically all of the features of 23AndMe/Ancestry/etc, but done offline. You’re given an app to download online, provided all of the hardware needed to spit in a tube, and get the same results. No data stored on a cloud server, and no centralized database of everyone’s DNA. That’s probably where the real…

I think you're missing the part where you have to send the tube to a lab to do the actual sequencing. At that point they have your data, and even if there were to be a provider that says they don't keep it, that's about as credible as all the VPNs which "don't keep logs" where we later discover, whoops, they lied...

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#54
post #43

As someone who works in cybersecurity, it's always hard for me to interpret PR language like "orchestrated through a sophisticated attack". This could be aimed towards non-savvy readers meaning basically anything or it could be accurate and describe a nation-state (although I don't get the feeling of a sophisticated nation-state actor here). The DoJ used similar wording when prosecuting Aaron Schwartz for using Pytho…

Often, security bulletins will use the word sophisticated when describing multi-step attacks.

Step 1: Type in stolen username

Step 2: Type in stolen password

Step 3: Click log in button

Step 4: ( •_• ) ( •_• )>⌐■-■ ( ⌐■_■)

Step 5: I'm in

One example of a "sophisticated" attack

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#56
post #53
post #51

I’ve always wondered if this were a worthy business proposition, cause I would definitely buy a product like this: Basically all of the features of 23AndMe/Ancestry/etc, but done offline. You’re given an app to download online, provided all of the hardware needed to spit in a tube, and get the same results. No data stored on a cloud server, and no centralized database of everyone’s DNA. That’s probably where the real…

I think you're missing the part where you have to send the tube to a lab to do the actual sequencing. At that point they have your data, and even if there were to be a provider that says they don't keep it, that's about as credible as all the VPNs which "don't keep logs" where we later discover, whoops, they lied...

Right, maybe this is where I’m being ignorant, but would there be a way to do the actual sequencing down to a consumer device?

I presume the machines used are pretty complex.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#57
post #49

Earlier quoted context omitted.

this presentation outlines the kind of terrible attacks that could be based on your DNA in the near future https://youtu.be/HKQDSgBHPfY tldr, CRISPR allows targeting bioweapons at specific individuals.

Thanks for the link to that video. I don't have the time to watch it now, but I will come back to it later. Although on the surface, specifically targeted bio-engineered weapons seems like a silly fear for most us when bullets are so cheap. If someone wants me dead, I don't think any difficulty accessing my genome is going to be what stops them.

Unless they want your demise attributable to "natural causes"

Yeah, no one is going to go to all this trouble for some schmoe from the middle of nowhere. But imagine something like regime change as a motivation.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#58

This is why I’ve been putting off getting my genome sequenced. One breach and it’s out there forever. I’ve heard good things about nebula[0] as a way to get an anonymous genome but have yet to be motivated enough to take the plunge [0] https://nebula.org/whole-genome-sequencing/

Regardless of their policies, they still want to store it themselves and put it on the Internet.

I am hoping that someday there will be a sequencing company that will mail me a drive containing the only copy and destroy the sample.

I'm not worried about a sophisticated attack on my individual sequence but I suspect most of these services are or will be targeted by advanced and persistent attackers.

Call me paranoid but I don't want my genome in an internet connected database (though I am very curious to see it).

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#59

As someone who works in cybersecurity, it's always hard for me to interpret PR language like "orchestrated through a sophisticated attack". This could be aimed towards non-savvy readers meaning basically anything or it could be accurate and describe a nation-state (although I don't get the feeling of a sophisticated nation-state actor here). The DoJ used similar wording when prosecuting Aaron Schwartz for using Pytho…

As someone who works in cybersecurity, it is perfectly clear to me that victims of attacks don't want to sound inept in their announcements so they ALWAYS say attacks are "sophisticated," "orchestrated," or "advanced." Nobody is going to say "we were hacked because we lack even basic security precautions." Instead, everything is an "APT."

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#60

So they sent an email to their users that states: >We can assure you that your DNA information was not compromised, as GEDmatch does not store raw DNA files on the site. When you upload your data, the information is encoded, and the raw file deleted. This is one of the ways we protect our users’ most sensitive information. This is kind of BS right? It's encoded... not encrypted.

Presumably. However, if it was a PR drone who wrote that, it may or may not be accurate as to whether or not it was encoded/encrypted.

I would just assume that it has in fact been compromised though.

Post reply on HN