Live data from Hacker News

23andMe confirms hackers stole ancestry data on 6.9M users

techcrunch.com

151–160 of 321 posts

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#152
post #57

Isn't it time governments start to regulate passwords ? (They already regulate a lot of privacy issues like medical and financial history. Some governments even regulate the use of finger print authentication of employees) For example, any website that allows users to choose normal, easy to remember passwords should meet a long list of requirements: For example security audits, bug bounties, capital reserves to deal…

That would not have protected 23andme from this issue. Password complexity does not stop password reuse.

I'm only suggesting password complexity as a compromise so that websites wouldn't need to implement OAuth. (Do you have a better comprise ?)

Password complexity encourages the use of password managers. They in turn remove the need to reuse passwords.

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#153

I never seriously considered using 23 and me. Not because of hackers, but rather what government would do with that information. I don't want to be responsible for some random relative getting charged with a crime just because I was curious about my family tree.

Have they used these sorts of databases to charge things other than murder and rape? The cases I have seen solved by way of this technology, I would very much feel glad that something I did led to stopping someone doing seriously bad things.

[deleted]

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#154
post #11

If anyone who used the service, do you know if you can use it anonymously? I wanted to try it but I was afraid of exactly this. How feasible it is to use a payment and an address that doesn't directly connect you to your samples?

You DNA is shared with others, so any amateur geneaologist is likely to be able to find out who, approximately, you are.

The exact info though should be easy to protect. Just dont give it away.

But remember that other close family members to you are very likely to know who you are, and they may share that info by accident. Normally you can't share data of anyone living on these services, since that is illegal pretty much anywhere, but its enough if one user happen to mark you dead in their tree and has filled in your real data.

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#156

Earlier quoted context omitted.

Maybe we all shouldn’t be so Quic to create bad ideas.

Right, like the person posting an idea on an Internet forum was the first and only person to have that idea. Security through obscurity does not work. It’s much better to open up the curtains and let the sunlight in. It’s the best disinfectant. At least then everyone is working with all of the information.

Blinds open btw. I’m picking up what you are gracefully throwing down but not without checks and balances.

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#157

Does anyone think privacy of any real sort is maintainable going forward? Machine learning algorithms are learning to identify people just by their walk -- no face recognition required. Algorithms are moving toward being able to decipher text just by the audio of the keyboard being typed on. In short, given a gestalt of ALL public data and sufficiently advanced algorithms is there really a way for people to maintain…

> Machine learning algorithms are learning to identify people just by their walk...

Turns out the UK government was working on privacy-preserving walks decades ago: https://youtu.be/eCLp7zodUiI

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#159

Earlier quoted context omitted.

That’s not what the comment was driving at. At all. It’s about how data you think is innocent can be used in a manner you never thought about nor intended for dark purposes.

Fair. On the other hand, I'm a bit surprised that anti-immigrant forces in the US haven't made DNA sampling compulsory for new immigrants. The argument would be these would be harder to track down by these techniques, because the ancestry information is not as available, giving them an "unfair" advantage over white Americans.

I don’t think that fits with how people on this side of the pond think about immigration.

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#160

I never seriously considered using 23 and me. Not because of hackers, but rather what government would do with that information. I don't want to be responsible for some random relative getting charged with a crime just because I was curious about my family tree.

I’d really like my 23 and Me info, but I assumed it was only a matter of time before they were hacked or sold to an untrustworthy organization willing to sell out users to make a quick buck.

If the test was done, the results were sent, and then my test data/info were destroyed on their end, or if I could do a home test where the data never left my home, then I’d do it.

I struggle to understand why companies hold on to all this data. It is a huge liability. In this case, maybe it is so they can identify familial relationships, but is that feature worth the risk?

Post reply on HN