Live data from Hacker News

23andMe confirms hackers stole ancestry data on 6.9M users

techcrunch.com

111–120 of 321 posts

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#111

Earlier quoted context omitted.

Maybe we all shouldn’t be so QUIC to bad protocols.

Keep downvoting yourself into the deepest hole you can imagine Google.

Personally in downvoting because your posts seem irrelevant or incoherent and I want to discourage that sort of thing on hackernews. Though in your particular case I strongly suspect you're having a psychotic break and need immediate medical help.

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#112
Something super creepy that happened to me recently: a hospital where I've been to a few months ago called me and asked me to participate in some DNA analysis program. They said "oh and the best part? You don't need to do anything! We will use blood samples we collected the last time." I obviously declined, but it was a huge wtf to me - they stored biological samples associated with me without informing me and can do a post hoc DNA analysis. This is just insane and a proof of how non existent any privacy laws in the US are. (In EU they cannot freeze any samples without consent and unfrozen ones are ok for at most a few days)

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#113
Small world. Only yesterday I read that great comment from user adameasterling about credential stuffing in another thread [1]

> Troy Hunt is such a treasure. And for us web application developers, there is no excuse for not having protection against credential stuffing! While the best defense is likely two-factor, checking against Hunt's hashed password database is also very good and requires no extra work for users!

That user even listed 23andMe [2] as an example but it's from 60 days ago. This incident is referenced on the techcrunch article.

[1] https://news.ycombinator.com/item?id=38521106

[2] https://news.ycombinator.com/item?id=37794379

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#115
post #67

Earlier quoted context omitted.

> Isn't it time governments start to regulate passwords ? Nah we're good. They already regulate cookies and it's a dumpster fire.

dumpster fire for who?

Cookie consent is just a nuisance.

Like the cancer warnings in California.

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#116
post #20

Earlier quoted context omitted.

FYI, the police is able to find criminals now by finding DNA sequences similarities with your relatives. Not saying this is good or bad, I am just saying you don't know the extent of the impact to your personal freedom when your relative's DNA is shared.

Well they can narrow it down to the family, unless it was the very DNA giver that left that DNA sample on the scene of the crime. And since 23andme (as I assume others) don't do these anonymously, there is no hope. Unless people use someone as a proxy (i.e. I-1 give my sample to a male colleague to send it as his-2, he-2 gives his sample to someone else to send it as his-3, and so on..). Police would eventually find…

If this was someone trying to fly under the radar by using this scheme to buy burner phones or some such, sure. But this is literal DNA, so even in your attempts to obfuscate, they’d know the name and the sample do not line up, but then be able to link the sample to a family and then figure out who you really are

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#117

I never seriously considered using 23 and me. Not because of hackers, but rather what government would do with that information. I don't want to be responsible for some random relative getting charged with a crime just because I was curious about my family tree.

If that's your only concern, you need to read up on something called "Nazis." Imagine what they would do with a database of genetic information.

Imagine what a racist government would do if they were able to tell who's black!

Sure, now they can start hating on people who have the gene that makes Cilantro taste like soap, but a lot of genetic things are already visible so I don't see this as being fundamentally different.

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#118
post #29

How much does that have to do with their TOS update which went out on thanksgiving DAY (the most perfect time to get lost in everyone’s inboxes). The TOS update somehow tries to forbid class actions, requires you to go through an “informal” 60 day process before any legal action, and forces you into binding arbitration. Functionally you as a customer have next to no legal rights, according to 23andMe lawyers who cook…

Does this hold up in court? At least in Germany any contracts that are heavily in favor of one side will be declared void if it comes to court.

Within limits, in the United States, yes. https://www.law.cornell.edu/wex/adhesion_contract_%28contrac...

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#119

Earlier quoted context omitted.

> I can help track down distant family members who have committed crimes? Sounds like a plus. It's no longer so easy when the definition of "crime" gets expanded. Let's take this scenario: - you're a first generation Chinese immigrant in the US - a nephew of yours is in China and critical of the CCP - you decide to have your genome scanned into 23andme or whatever to determine if you are at risk of genetic illness -…

It's precious that you imagine not getting your DNA sequenced will provide any sort of shield against dystopian governments. This sort of thing looks more like a psychological crutch than an actual effective action.

That’s not what the comment was driving at. At all. It’s about how data you think is innocent can be used in a manner you never thought about nor intended for dark purposes.

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#120
post #53

It does feel at this point that any company collecting data will be hacked, it's only a matter of "when" and no "if"...

Penalties should be strong enough that sites and apps do not collect more than an email address without very good reason. Just wanting to contact me with marketing literature is not a good reason.

I can't help but think that we need is for a class action suit to impose strong enough penalties that insurance companies to insist on proper audits of what data is actually needed and what is just a financial loss waiting to happen.
Post reply on HN