Live data from Hacker News

23andMe confirms hackers stole ancestry data on 6.9M users

techcrunch.com

61–70 of 321 posts

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#61

It's imperative to recognize that the healing of cross-generational trauma is a journey within an individual's lifetime, rather than resorting to a confrontational approach that employs genetic data to incriminate individuals based on what science implies about their genetic makeup. The flaws inherent in this data—biased, widespread, and contaminated—highlight its unreliability. Relying on such data, which historical…

I struggle to understand what is written here.

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#62
I never seriously considered using 23 and me. Not because of hackers, but rather what government would do with that information. I don't want to be responsible for some random relative getting charged with a crime just because I was curious about my family tree.

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#63
post #18

Earlier quoted context omitted.

I'm in favor of privacy, and I'm willing to go more out of my way to not share than the vast majority of people, but I'm also in favor of individual choice, and I can't think of a privacy model that would disallow other people from sharing their information just because you have some matching information.

I can think of an easy model. Disallow collection of personal information. Pull the rug out from under "services" which are really just data collection fronts turning a profit from selling your data instead of the primary service/good for money transaction. 23andMe could still have operated legally under this scheme. They could have done the analysis and sent you a printed sheet. But no, they had to store everything…

> Disallow collection of personal information

It's all about the money, always. So not gonna happen.

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#64
post #8

Something does not add up. "23andMe said the data breach was caused by customers reusing passwords" Yet 14,000 accounts were breached in one go? Where did these passwords come from? Maybe there was another related breach (something like lastpass can explain this)? Also, using the "DNA Relatives" features the hackers were able to access personal information relating to 6.9 million individuals. That means each one of t…

>Yet 14,000 accounts were breached in one go?

That part isn't super surprising beyond the technical issue of the data usurpers probably not being metered or flagged for continuously logging into different accounts. They could have used a massively distributed network to pull all the data, but there probably simply wasn't the detection or protection.

Having said that, in logging into my account to verify how many relatives are shown to add this response, 23andme refused to let me login and demanded that I reset my password because of password reuse. I have always had a very strong password on this account, and it isn't reused anywhere. I even have 2FA on. So it seems that the company isn't entirely comfortable with the notion that it was reused passwords behind it...

However after resetting my password that I never reused anywhere, the DNA relatives panel shows 60 pages of relatives, with each having 25 relatives. So 1500 relatives could be pulled. Grabbing that for 14000 random accounts would be a pretty formidable network someone could build.

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#65
post #20

Earlier quoted context omitted.

FYI, the police is able to find criminals now by finding DNA sequences similarities with your relatives. Not saying this is good or bad, I am just saying you don't know the extent of the impact to your personal freedom when your relative's DNA is shared.

Well they can narrow it down to the family, unless it was the very DNA giver that left that DNA sample on the scene of the crime. And since 23andme (as I assume others) don't do these anonymously, there is no hope. Unless people use someone as a proxy (i.e. I-1 give my sample to a male colleague to send it as his-2, he-2 gives his sample to someone else to send it as his-3, and so on..). Police would eventually find…

There are plenty of cases where DNA is found at the crime scene, run through a database, match is found with a relative. Then the cops start looking at the family and boom there's your shady uncle with priors they got their guy.

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#67
post #57

Isn't it time governments start to regulate passwords ? (They already regulate a lot of privacy issues like medical and financial history. Some governments even regulate the use of finger print authentication of employees) For example, any website that allows users to choose normal, easy to remember passwords should meet a long list of requirements: For example security audits, bug bounties, capital reserves to deal…

> Isn't it time governments start to regulate passwords ?

Nah we're good. They already regulate cookies and it's a dumpster fire.

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#68
post #61

It's imperative to recognize that the healing of cross-generational trauma is a journey within an individual's lifetime, rather than resorting to a confrontational approach that employs genetic data to incriminate individuals based on what science implies about their genetic makeup. The flaws inherent in this data—biased, widespread, and contaminated—highlight its unreliability. Relying on such data, which historical…

I struggle to understand what is written here.

Me too but I think OPs point is “this was a pointless product in the first place, and can only lead to harm”

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#70

This disaster is the perfect counter-argument to those always saying "why do you care so much about privacy. It doesn't affect you when I share things. You can just choose not to do it", except no, I can't choose when we're relatives and you chose to share our genome. It is so obvious that your relatives sharing their genomic data with 23andMe reveals a lot of information about you. We can only hope people will reali…

To clarify, genomic data was not reported stolen. It sounds like the breach was about genealogical data.

The stolen data included the person’s name, birth year, relationship labels, the percentage of DNA shared with relatives, ancestry reports and self-reported location.

Post reply on HN