Live data from Hacker News

Breach exposed more than one million DNA profiles on a major genealogy database

buzzfeednews.com

391–400 of 424 posts

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#391
post #202

Earlier quoted context omitted.

If the data is managed by a company that isn't in the healthcare industry, HIPPA doesn't apply. An insurance company, even a health insurance company can purchase non healthcare data from an analytics company. It wasn't HIPPA protected when it was on my heritage, and it won't be healthcare data when it's eventually leaked and resold. If you don't think legitimate companies are interested in buying that data, look aro…

I never mentioned HIPAA in the context you are implying. I was simply saying it won't protect the malicious actors from being discovered. > look around at the market for our password breach and identity theft data. There's a brisk, legal trade. If it is so easy to acquire this data legally, do you want to point to a business from which one can legally purchase "identity theft data"?

I read about a "threat intelligence" company on here the other day who got hacked for all their breach data. Not all of it is super public, and none of the public dumps are in a tidy package where you can associate users in one breach with users in another breach. Sorry I couldn't find the name of the company.

But there are more than a handful of "threat intelligence" or OSINT providers. I'll let you Google it for yourself.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#392
post #94
post #58

Earlier quoted context omitted.

Regardless of their policies, they still want to store it themselves and put it on the Internet. I am hoping that someday there will be a sequencing company that will mail me a drive containing the only copy and destroy the sample. I'm not worried about a sophisticated attack on my individual sequence but I suspect most of these services are or will be targeted by advanced and persistent attackers. Call me paranoid b…

This is not meant to be confrontational in any way: what are the risks of having your genome exposed?

Primarily my concern is what it will be possible to infer about a person (or what some people think they can infer) from the genome not just now but in 40 years.

The history of science and politics are filled with ugly chapters of people committing bad acts based on the ancestry of other people.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#393
post #79
post #58

Earlier quoted context omitted.

Regardless of their policies, they still want to store it themselves and put it on the Internet. I am hoping that someday there will be a sequencing company that will mail me a drive containing the only copy and destroy the sample. I'm not worried about a sophisticated attack on my individual sequence but I suspect most of these services are or will be targeted by advanced and persistent attackers. Call me paranoid b…

And you should trust that company or government based on what?

I have no argument against more paranoia, but my curiosity is such that I'm willing to take some risk.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#394
post #18

Earlier quoted context omitted.

What does the GED stand for? Genetic ??? Database? To someone who grew up in the U.S., GEDmatch sounds like a dating site for people who took a test in lue of completing secondary education.

One use of GED is for GEnealogical Data[base], or Genealogy Data. GED files have been used for decades in genealogical circles at least. So I think that's what they're referring to? https://en.m.wikipedia.org/wiki/GEDCOM , for example.

Additionally, I have always heard it pronounced like "jedcom" when referring to the files rather than G-E-D files.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#395
post #151

Earlier quoted context omitted.

That leads to my afterlife nightmare scenario. I die bravely in glorious battle and am chosen by the Valkyries for Valhalla. One evening as we feast after that day's fighting, quaffing giant tankards of mead and boasting of our deeds, there comes a knock at the door. Two young men in suits enter, and go to speak to Odin. Odin then call for me to come over. He tells me that the young men are Mormons, and that some dis…

Mormon baptism for the dead is conditional - it doesn't automatically convert them, but rather the dead person gets a choice to accept that baptism or not. But then again, while in Mormon theology the spirits are immediately sorted into paradise and "spirit prison" upon death, they can apparently communicate across the boundary between the two; and those in paradise can thus evangelize to those in prison, until they…

The mormon belief of being able to preach and convert after death stems from new testament teachings in Peter that Christ preached to those in "prison".

And while many Mormons take the necessity of baptism (even if after death) very literally, it is important to understand that they also believe that anyone who missed the chance to accept a posthumous baptism, will get that chance during the millennium of Christ's reign on earth, pre-judgement day.

All of that is to say, Mormons aren't frantically searching their genealogy to baptise everyone for fear their ancestors will burn in hell. There is a belief that seeking out and understanding your geneology and then setting aside time to go to the temple is beneficial to ones spirituality and well being.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#396
post #166

This is why I want a genetic sequencing lab that will sequence your genome, send it to you encrypted by your own public key and once you confirm receipt and verify it is valid, DELETE IT COMPLETELY. Along with the record you were their customer after the 6 months or whatever required for waiting out chargebacks. Then you can analyze your DNA with a desktop app that doesn't send out any data. The deleting part is hard…

You can do pretty much that by getting your DNA sequenced by Dante labs and then using Promethease on it.

[deleted]

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#397

Earlier quoted context omitted.

That's what they're trying to do. In Mormon theology everyone who dies without a chance to be baptized must be given a proxy baptism by someone living, so they have a chance to accept the gospel in the afterlife. The goal is that this will eventually happen for everyone who ever lived. (Source: former Mormon.)

Why does it require genealogical research, though? Can proxy baptism only be performed by living relatives? And if not, then wouldn't just knowing the name of the person suffice? Or, for that matter, wouldn't any way to unambiguously identify them?

In practice, you just need the name and birth year and maybe another detail or two. And a recent rule does require that members focus on their own ancestors.

But the point of the whole thing is actually to spend time learning and researching your family history. In other words, the literal posthumous baptism is not the point. That's the ritual. It's what to learn and do along the way of accomplishing the ritual that is the point.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#398
post #265

Earlier quoted context omitted.

> there is no risk to you. There is always risk. You probably don't see it yet just like only privacy-forward folks thought Facebook's encouragement to "share everything" publicly (circa 2007) foresaw the problems that would commit 10+ years later. The small benefit of closure to a stranger who has already dealt with the grief of loss is not worth it for me. It depends on your personal value system. > It has been ill…

If you seriously worry that much about far-fetched hypothetical scenarios it simply means you're privileged enough not to have immediate problems that affect you today.

I agree.

But the unprivileged benefit from the privileged identifying longer term issues.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#399

Earlier quoted context omitted.

> and many of the DNA platforms don't allow them I’m assuming that the stolen information doesn’t have this limitation.

> I’m assuming that the stolen information doesn’t have this limitation Stolen information has provenance problems that make it difficult to use as evidence of any crime other than theft itself in any system with even rudimentary due process protections and presumption of innocence. I mean, it's hardly as if you are going to be able to get the people who handled the data between the people who had it lawfully and the…

Its easy to use this information to search for suspects, but not bring it up in court once you find other evidence.

https://en.wikipedia.org/wiki/Parallel_construction

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#400

And half the DNA of all of the siblings and parents of the people that submitted their DNA, a quarter of their grandparents and grandchildren and so on. That's what I really hate about these companies, they get people to submit their DNA and the customers do not realize it isn't a decision that affects just them.

This is really another example of a claim of "genetic exceptionalism", that genetic information has a special status among other sorts of personal information, that mostly is not true. Your personal information, broadly, is informative about your relatives, your friends, etc. This includes your personal health information, your personal financial information, your online habits, etc. Any time you share personal data, you are disclosing information about people associated with you, without their consent, that might be used against them. And often these other classes of personal data are more informative than genetic information.
Post reply on HN