Live data from Hacker News

Breach exposed more than one million DNA profiles on a major genealogy database

buzzfeednews.com

311–320 of 424 posts

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#311
This quote by John Young of Cryptome sums up the dark truth of the state of cybersecurity:

" Wonder how long it will take to reveal cybersecurity is a Ponzi racket.

Profits from commercial harvesting data of online users now exceeds the total funding of all the global spy agencies, with a healthy chunk of the steal bought by official spies and law enforcement which ignore the violation. Edu, orgs and NGOs part of the rotten racket."

Essentially, every major data breach is planned by the "good guys" having a stake in criminal ops.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#312
post #272
post #204

One thing I’m thinking about: this is probably an inevitable future. That we like it or not technology is going to be more and more intrusive. If not our generation, the next one, or the one after. We’ve seen that short-sighted laws have caused more harm than good on the long-term. Like the war on drugs. Knowing this, is there a future where we can lose privacy but still live a good life? And what can we do to get th…

https://en.wikipedia.org/wiki/Homomorphic_encryption

The cost of that is prohibitive except for very particular cases. On the other hand, even tiny devices have powerful computers nowadays. We don't need 3rd party cloud.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#313
post #274

And half the DNA of all of the siblings and parents of the people that submitted their DNA, a quarter of their grandparents and grandchildren and so on. That's what I really hate about these companies, they get people to submit their DNA and the customers do not realize it isn't a decision that affects just them.

In terms of medical data the amount of leakage is somewhat limited by the nature of DNA, e.g because you get a random mix you can't conclude anything about parents, etc medical status. By far the biggest practical knock-on effect is if you match someone who's doesn't know their parentage (adoption/illegitimate children/etc) who can figure out their parentage as a result of that match. Familial DNA crime searches are…

> and many of the DNA platforms don't allow them

I’m assuming that the stolen information doesn’t have this limitation.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#314

So they sent an email to their users that states: >We can assure you that your DNA information was not compromised, as GEDmatch does not store raw DNA files on the site. When you upload your data, the information is encoded, and the raw file deleted. This is one of the ways we protect our users’ most sensitive information. This is kind of BS right? It's encoded... not encrypted.

This seems very odd. These sites add features over time when new patterns are discovered, so I'd doubt that they delete any parts not used today because they might be useful in the future...

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#315

Earlier quoted context omitted.

Getting placed at the scene of a crime applies to everyone. Remember that once you do it, it’s out there forever. So you can’t just rely on “I haven’t and won’t break any laws that exist in my country right now”. Having certain characteristics that show up in your test could be illegal in 20 years time. You don’t know.

That's an interesting point, but if your government becomes blatantly oppressive they don't need DNA to do it.

More to the point, the government can just collect your DNA itself if it wants to.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#316
post #166

This is why I want a genetic sequencing lab that will sequence your genome, send it to you encrypted by your own public key and once you confirm receipt and verify it is valid, DELETE IT COMPLETELY. Along with the record you were their customer after the 6 months or whatever required for waiting out chargebacks. Then you can analyze your DNA with a desktop app that doesn't send out any data. The deleting part is hard…

You can do pretty much that by getting your DNA sequenced by Dante labs and then using Promethease on it.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#318

Earlier quoted context omitted.

Just wait until these fancy "smart" coffee cups with built-in nano-labs become ubiquitous.

Before that happens, I'm guessing that full DNA sequencing at birth will be a legal requirement. Like footprints are now.

Holly... You're right. This will happen. To an over-arching state this is the ultimate modus.

  INSERT INTO Citizen(dob,ssn)
  VALUES 2030-10-28, sha(atgcaatgcatcgc..)

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#319
post #76

Earlier quoted context omitted.

I was just wondering if this one leak would spur a hike in organ thefts. Or a spike in abusive husbands and fathers, pedophiles and rapists tracking down the victims that escaped them. Even if this doesn't happen, the future is a devious thing; I think we will eventually get to a stage of gene oppression; We have went through periods of oppressing and persecuting religion and ethnicity. DNA seems even more vulnerable…

Organ theft and the holocaust? If that's what you're worried about your problems are already much much much more severe than what we're discussing here.

we should always try to minimize future catastrophes by enshrining rights and regulation around issues that could contribute to them.

We should not be tricked into ignoring these issues because catastrophes are rare, as this would logically make them less rare.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#320

And half the DNA of all of the siblings and parents of the people that submitted their DNA, a quarter of their grandparents and grandchildren and so on. That's what I really hate about these companies, they get people to submit their DNA and the customers do not realize it isn't a decision that affects just them.

Here's a thought: "This is a GDPR erasure request. Your site contains my PII by way of that of my father. Please erase this information and indicate that you have complied within 30 days." Shall I try it?

Yes, please!
Post reply on HN