Earlier quoted context omitted.
“But A/B testing showed more ‘user engagement’ when you default to public”
Who are you quoting there?
Breach exposed more than one million DNA profiles on a major genealogy database
371–380 of 424 posts
Re: Breach exposed more than one million DNA profiles on a major genealogy database
#372For those who are annoyed about the name of the site not being in the title: GEDMatch was phised a few days ago, then yesterday phishing led to the data exfiltration from the Israeli DNA site MyHeritage. https://www.myheritage.com/
Millions of GEDMatch accounts where opted in to share info with the police, without consent. Also, user emails where leaked, which lead to a phishing attack targeting MyHeritage users. 16 of them fell for it and they passwords were stolen.
Re: Breach exposed more than one million DNA profiles on a major genealogy database
#373Earlier quoted context omitted.
"if insurance is never involved HIPAA doesn't apply." No. This is just plain false. HIPAA applies when personally identifiable health information is shared/exchanged. And it applies whether the data is electronic or physical (paper). (I am NOT saying DNA falls within the HIPAA guidelines.)
No, personally identifiable health information can be shared/exchanged without HIPAA applying. For example if I email my grandma information about my cancer diagnosis, Gmail isn't HIPAA compliant and doesn't need to be just because some people might use it to talk about their health. Grandma is also free to share my health information with impunity, she is free to, say, forward it to my boss because grandma doesn't h…
But a covered entity may not. And there are many covered entities which are not insurance related. That is all I was trying to say.
Re: Breach exposed more than one million DNA profiles on a major genealogy database
#374And half the DNA of all of the siblings and parents of the people that submitted their DNA, a quarter of their grandparents and grandchildren and so on. That's what I really hate about these companies, they get people to submit their DNA and the customers do not realize it isn't a decision that affects just them.
This is exactly how I feel about my friends/family having Facebook apps on their phone. I didn't consent to giving my contact info to Facebook. I wasn't given a choice.
You don't get a choice if your uncle, grandmother, aunt, niece or son share their DNA with law enforcement.
Re: Breach exposed more than one million DNA profiles on a major genealogy database
#375Amazing we don't have a law granting each individual copyright of their own genome.
Re: Breach exposed more than one million DNA profiles on a major genealogy database
#376Earlier quoted context omitted.
People think of HIPAA as a generic cover-all medical privacy law for some reason. It's not, not even close, It's a law that very narrowly applies mainly to insurance companies and healthcare entities that accept medical insurance. As a general rule - if insurance is never involved HIPAA doesn't apply. If you got a DNA test prescribed by your doctor for a diagnosis or even for genetic counseling then HIPAA applies. It…
"if insurance is never involved HIPAA doesn't apply." No. This is just plain false. HIPAA applies when personally identifiable health information is shared/exchanged. And it applies whether the data is electronic or physical (paper). (I am NOT saying DNA falls within the HIPAA guidelines.)
Re: Breach exposed more than one million DNA profiles on a major genealogy database
#377Did not take long: https://mittr-frontend-prod.herokuapp.com/s/614642/dna-datab...
That url is atrocious. It looks like the MIT tech review doesn't pay for its Heroku account.
Re: Breach exposed more than one million DNA profiles on a major genealogy database
#378For those who are annoyed about the name of the site not being in the title: GEDMatch was phised a few days ago, then yesterday phishing led to the data exfiltration from the Israeli DNA site MyHeritage. https://www.myheritage.com/
I thought myheritage was owned by the Mormons.
Re: Breach exposed more than one million DNA profiles on a major genealogy database
#379It sounds to me like hackers just managed to traverse the entire database to hunt for emails. Which is not exactly hard given how the site works.
Most kit numbers seem to be a letter and 6 numbers so not exactly hard to brute force either. You don't even have to get that many right as for any hit you might get a list of 1000+ people and use their kit numbers to get even more.
You might say that's a terrible design security-wise but that's what makes GEDmatch great for researching who you're related to. They'll either have to degrade the experience or be really stringent about rate limits and so forth.
Re: Breach exposed more than one million DNA profiles on a major genealogy database
#380Earlier quoted context omitted.
> One of the core tenets of Mormon faith is that the dead can be baptized into the faith after their passing. Baptism of the dead evolved from the beliefs that baptism is necessary for salvation and that the family unit can continue to exist together beyond mortal life if all members are baptized. > Mormons trace their family trees to find the names of ancestors who died without learning about the restored Mormon Gos…
That leads to my afterlife nightmare scenario. I die bravely in glorious battle and am chosen by the Valkyries for Valhalla. One evening as we feast after that day's fighting, quaffing giant tankards of mead and boasting of our deeds, there comes a knock at the door. Two young men in suits enter, and go to speak to Odin. Odin then call for me to come over. He tells me that the young men are Mormons, and that some dis…