Live data from Hacker News

Breach exposed more than one million DNA profiles on a major genealogy database

buzzfeednews.com

301–310 of 424 posts

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#301
post #286

Earlier quoted context omitted.

Ignorant question here. How is this not regulated through HIPAA? Shouldn't these board members of this company face prison? DNA, a prosecutor could argue is a unique health identifier. "Access to equipment containing health information should be carefully controlled and monitored." https://en.wikipedia.org/wiki/Health_Insurance_Portability_a...

if they construe their DNA data as not health information, but instead information like finger prints?

"I'm standing here in this chalk circle where HIPAA does not apply, can't touch me, nyah nyah!" Sounds like that would work against a 5-year-old sibling, but that's rarely the case...

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#302
post #298

Like this wasn't just waiting to happen. You voluntarily hand over your DNA to a private company. What could possible go wrong?

Well, I'd add : You voluntarily hand over your DNA to a private or public company. Makes no difference. The bigger the trove, the finer the hackers.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#303
post #248

Earlier quoted context omitted.

There is a world of difference between 1. Having your DNA already in the database 2. Your DNA being out somewhere on the street where it could only be linked to you by name through a targeted reconnaissance effort

I think this is somewhat analogous to the privacy issues around Google Street View. Almost nobody thought the image of the front of their house was really private, but the idea of it being catalogued and searchable bothered more than a few. Removing the barrier of someone having to physically do the work to get that information at least made them feel more vulnerable. Has Street View been a problem for the world in t…

It's made me run away from at least one business when I saw that their office address was basically an obviously unoccupied 2up 2down hovel.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#304

Earlier quoted context omitted.

So I should get the consent of my entire extended family before I ever submit my DNA to a service for analysis?

With likely very dire results, yes I think you should. If your mothers insurance rate goes up, since you got one of these dna tests for Christmas, she should be involved in the decision to publish this data in the first place.

In the US, Congress has passed a law that explicitly makes that specific practice illegal: https://en.m.wikipedia.org/wiki/Genetic_Information_Nondiscr...

What workarounds insurance companies come up with to circumvent the spirit of the law and how well it can be enforced will be interesting.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#305
post #274

Earlier quoted context omitted.

In terms of medical data the amount of leakage is somewhat limited by the nature of DNA, e.g because you get a random mix you can't conclude anything about parents, etc medical status. By far the biggest practical knock-on effect is if you match someone who's doesn't know their parentage (adoption/illegitimate children/etc) who can figure out their parentage as a result of that match. Familial DNA crime searches are…

If a child has 2 copies of a variant you know both parents have at least 1 copy. You know what parent a male's X and Y came from. You can use phasing and linkage to reconstruct parental haplotypes.

> You know what parent a male's X and Y came from.

You can identify which parent any chromosome came from. They're all marked, and the same genetics may do sharply different things depending on whether it was inherited from the father or the mother.

Inability to recover this data has nothing to do with "the nature of DNA" -- the data is very much present in the DNA. It's unrecoverable because when we summarize DNA, we leave it out.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#306
post #282

“ As a result of this breach, all user permissions were reset, making all profiles visible to all users ” This seems like the opposite of how a sensible permissioning data model should work.

“But A/B testing showed more ‘user engagement’ when you default to public”

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#307
post #282

“ As a result of this breach, all user permissions were reset, making all profiles visible to all users ” This seems like the opposite of how a sensible permissioning data model should work.

I thought the exact same thing when I got the email. I would have much preferred a permission reset resulting in profiles being locked down tightly.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#308

And half the DNA of all of the siblings and parents of the people that submitted their DNA, a quarter of their grandparents and grandchildren and so on. That's what I really hate about these companies, they get people to submit their DNA and the customers do not realize it isn't a decision that affects just them.

Here's a thought:

"This is a GDPR erasure request. Your site contains my PII by way of that of my father. Please erase this information and indicate that you have complied within 30 days."

Shall I try it?

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#309
post #263

Earlier quoted context omitted.

Your street view doesn’t contain your entire genetic record (including propensities towards disease, mental and physical, which could very easily be used to discriminate against you). So they’re not really comparable whatsoever. And what is with this “this terrible thing X will happen eventually, so why not have it happen now?” argument I keep seeing nowadays? Your argument was quite literally: “Eventually someone wi…

> Your street view doesn’t contain your entire genetic record (including propensities towards disease, mental and physical, which could very easily be used to discriminate against you). Isn't this a form of victim blaming? How is this different than saying Black people should try to hide their skin color since in many cases they will be discriminated against because of it? We should be working to suppress the discrim…

You're right, working to reduce discrimination at source is undoubtedly worthwhile. But data does not exist in a vacuum - it is collected on behalf of, and used by, people.

Until we reach zero intolerance nirvana, you can't ignore that personal data collection at scale simplifies discrimination, and also opens up new methods for discriminating. Will there be benefits to society from personal data collection at scale? Of course. But there are also costs. There are plenty of examples of people whose ideas or products became used in unforeseen ways and regretted their actions.

Discrimination should be suppressed at source and systems that simplify its manifestation in the real world should be handled extra carefully.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#310

Earlier quoted context omitted.

Getting placed at the scene of a crime applies to everyone. Remember that once you do it, it’s out there forever. So you can’t just rely on “I haven’t and won’t break any laws that exist in my country right now”. Having certain characteristics that show up in your test could be illegal in 20 years time. You don’t know.

That's an interesting point, but if your government becomes blatantly oppressive they don't need DNA to do it.

The resistance movement in Norway, during WWii, targeted and blew up the citizen registry, because it was used for evil. Any database we build now could be used like that. Now they are easily copied, so we won't be able to blow them up when it's already too late--we must avoid building them.
Post reply on HN