Live data from Hacker News

Breach exposed more than one million DNA profiles on a major genealogy database

buzzfeednews.com

351–360 of 424 posts

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#351

Earlier quoted context omitted.

Of course I realised the comparison would be somewhat controversial, it was actually the point of bringing it up. However, if you have the time I would appreciate it if you tried to articulate why you think the comparison is unfair, instead of just a general dismissal.

Your (twin’s) photo is unlikely to be used for: * Identifying future medical risk factors * Solving 30-year-old cold cases where DNA is the only evidence * Identifying parentage in adoption cases

But my (twin's) photos could likely be used used for:

* Linking them to the location of a crime using Clearview AI and similar scraping facial recognition services

* Creating fake but believable defamatory photos and videos, such as deepfakes

* Being scraped and used in fake profiles by spambots and other nefarious actors

* Being exploited as a tool in identify theft and identify fraud, via various kinds of social engineering.

Do you not consider some of these scenarios worthy of a similar amount of consideration?

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#352

Earlier quoted context omitted.

What would insurance companies do with the data though? If they knew you were predisposed to obesity and cancer due to this data, would they be kind enough to ignore that info?

Federal law prohibits health insurers from using DNA data for underwriting and pricing.

And if it didn't the insurance companies could just demand a dna test before underwriting any policies.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#354
The human genome is about 3.4B base pairs (G-C, A-T). The specific DNA used for genealogical matching is 700K base pairs. So the testing companies are only using 0.02% of your DNA, hardly enough to compromise you.

Furthermore, the matching process is based on SNPs (Single Nucleotide Polymorphism) and STRs (Short Tandem Repeat) in the "junk" DNA section, which constitute 92% of your DNA, and is distinct from the coding DNA that contains health traits, among others.

So, not much to worry about.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#355
post #300

Earlier quoted context omitted.

That's such an incredibly rude and conceited practice.

Oh, nonsense. Proxy baptism doesn't make you a member. That's not what they believe. Century after century Catholics taught that if your loved one had the misfortune to die before baptism, no hope. Eternal misery, because Christ said baptism was mandatory. Mormons say, well Christ was right of course but certainly not cruel, so the good news (gospel) is that if you don't get baptized before death for whatever reason,…

My life is none of their business.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#356
post #324

Earlier quoted context omitted.

> and many of the DNA platforms don't allow them I’m assuming that the stolen information doesn’t have this limitation.

Most law enforcement typically use a handful of commercial agencies (like Parabon NanoLabs, etc) for these kind of searches, it seems highly unlikely that any of them would risk using illegally obtained data because it would put their entire business at risk. (obviously if your threat model includes intelligence agencies, etc. then your calculus might be different)

And of course law enforcement has never before used illegally obtained evidence to construct a new trail that was plausible:

https://en.wikipedia.org/wiki/Parallel_construction

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#357
post #274

Earlier quoted context omitted.

In terms of medical data the amount of leakage is somewhat limited by the nature of DNA, e.g because you get a random mix you can't conclude anything about parents, etc medical status. By far the biggest practical knock-on effect is if you match someone who's doesn't know their parentage (adoption/illegitimate children/etc) who can figure out their parentage as a result of that match. Familial DNA crime searches are…

> and many of the DNA platforms don't allow them I’m assuming that the stolen information doesn’t have this limitation.

> I’m assuming that the stolen information doesn’t have this limitation

Stolen information has provenance problems that make it difficult to use as evidence of any crime other than theft itself in any system with even rudimentary due process protections and presumption of innocence.

I mean, it's hardly as if you are going to be able to get the people who handled the data between the people who had it lawfully and the time it got to the police on the stand to attest to it's integrity.

(That doesn't prevent its use in investigations, but it means that it would only lead to convictions in a contested case where the police used it to locate proof that was legally sufficient without the use of the DNA as evidence.)

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#358

And half the DNA of all of the siblings and parents of the people that submitted their DNA, a quarter of their grandparents and grandchildren and so on. That's what I really hate about these companies, they get people to submit their DNA and the customers do not realize it isn't a decision that affects just them.

Yeah, that was my biggest fear with these services. How do I stop my family members from falling for it? In the end, I can't and just have to live with their mistake (if they used these services).

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#359
post #352

Earlier quoted context omitted.

Federal law prohibits health insurers from using DNA data for underwriting and pricing.

And if it didn't the insurance companies could just demand a dna test before underwriting any policies.

It would be a sound business decision (who takes on unnecessary risk or costs willingly?), and yet another reason to support universal healthcare.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#360

Earlier quoted context omitted.

> and many of the DNA platforms don't allow them I’m assuming that the stolen information doesn’t have this limitation.

> I’m assuming that the stolen information doesn’t have this limitation Stolen information has provenance problems that make it difficult to use as evidence of any crime other than theft itself in any system with even rudimentary due process protections and presumption of innocence. I mean, it's hardly as if you are going to be able to get the people who handled the data between the people who had it lawfully and the…

Law enforcement is trained in information laundering and courts consider it a legitimate tactic.
Post reply on HN