Live data from Hacker News

23andMe confirms hackers stole ancestry data on 6.9M users

techcrunch.com

161–170 of 321 posts

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#161
post #140

Earlier quoted context omitted.

If that's your only concern, you need to read up on something called "Nazis." Imagine what they would do with a database of genetic information.

Look at what they did without it. Godwin's Law aside, the point is, if a sufficiently powerful group is set on doing something, they'll do it. Such a group won't let "facts" or "accuracy" get in the way. Look at McCarthyism.

People bent on doing evil things are going to do evil things, but perhaps it's a good idea to not build systems that will let their evil be faster and more efficient.

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#162
post #128

Earlier quoted context omitted.

I think the more common one I've heard is "Why do you care about privacy if you have nothing to hide?" In the case of 23andme, it's a perfect answer: We don't know what's hiding in our DNA and I don't know how people will use that against me in the future.

So, the reason for privacy is because the profit motive of capitalism is not sufficiently restrained as to protect citizens from being abused by corporations?

My go-to is "what if literal nazis come to power and use this information to kick-start their eugenics program", but I guess rampant capitalism is also on the threat list.

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#163

Earlier quoted context omitted.

I'm not a lawyer so I can't answer the question, but it will defintely complicate going to court, and I'm confident that the company has more lawyers and more money for lawyers than the average user. A class action suit may follow, but only if enough people and lawyers are willing, and it'll likely end up with a pittance in damages paid in a settlement, eventually.

What really interests me is "Are ToS changes absolutely binding?" I am also not a lawyer. But I think there are two types of changes to ToS. One is purely administrative. For example, they might change the methods available to reach for support. For example, they might say that you are no longer able to send a Fax to get support help. Or that their domain name changed. Second is something that changes the service tha…

Not just "are the changes binding" but also "are the changes relevant". The changes might be binding for future services, but previous services were provided under the old terms; so you can make an argument that any arbitration clause in the new terms doesn't apply to services rendered before the new terms took effect.

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#164
post #155

So the original "14000" leak is 0.1% of the customers, but now 6.9M is claimed. 14000/6900000 ~ 0.2%, so now half the customers are indirectly leaked?

Yes, likely at different levels. For example, if I log into my myheritage account, I have 27000 DNA matches which I can download a .csv of, which includes the matching parts. I can also access the trees of those users that share theirs. This really does not include personal data, _except_ the information about where our DNA is identical or half-identical. Which has potentially far-reaching implications, but the personal data should not really be available here, unless people has opted in to sharing it.

Since its a site about sharing data, its not weird that its easy to extract data from it. It is sort of the purpose.

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#165
post #148

Earlier quoted context omitted.

Well they did call you and tried to trick you into letting them use it. But assuming they obey the law they did not used your samples. So there are privacy laws in place? Also they could have been cleaning old results/samples and this was one step.

How do I know they didn't use them? They already did something with my biological samples (storing for a different purpose than when they drew my blood) without my consent nor informing me. And also - could eg. police use it?

I am not sure, only guessing. But why would they ask for permission in the firs place?

> They already did something with my biological samples

I can only guess you were tested for something in the hospital. Samples are sent to the lab (separate department) to be tested. If additional tests need to be perform they can use the blood they already received. The samples are kept for ready availability if additional tests are requested by doctor. Doctors dont care how its done, they dont have time to inform lab patient x is out home.

After some time they need to be destroyed - due to expiry date on it. Before destroying the lab contacted you and asked for dna permission.

> And also - could eg. police use it?

I don't know that. But you might want to check how medical data is protected in your jurisdiction.

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#166

This disaster is the perfect counter-argument to those always saying "why do you care so much about privacy. It doesn't affect you when I share things. You can just choose not to do it", except no, I can't choose when we're relatives and you chose to share our genome. It is so obvious that your relatives sharing their genomic data with 23andMe reveals a lot of information about you. We can only hope people will reali…

Agree. Alternatively: how much do you earn? Do you mind if I read your physical mail? Can I have a key to your home?

I think it is difficult for some people to think about abstract ideas. When you bring it to the physical world everyone understands it is vexing.

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#167

Earlier quoted context omitted.

I can think of an easy model. Disallow collection of personal information. Pull the rug out from under "services" which are really just data collection fronts turning a profit from selling your data instead of the primary service/good for money transaction. 23andMe could still have operated legally under this scheme. They could have done the analysis and sent you a printed sheet. But no, they had to store everything…

They are frank about also selling the data for research, it is not underhanded. It's even opt in... For example, they talk about it on this page, which is linked from the about menu (so available with pretty small effort): https://www.23andme.com/research/ I expect lots of people also like that they get updates when information about new markers becomes available.

[deleted]

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#168
post #88

Earlier quoted context omitted.

I can help track down distant family members who have committed crimes? Sounds like a plus. I think the angst about this comes from men who don't want their status as fathers of illegitimate children (or, rapists when they were younger) unmasked.

Why do you make this issue gendered, and if you do why would it impact only men father of illegitimate children, and not cheating mothers ?

Cause in the case of cheating mother, it is clear she is the mother. And to confirm fatherhood of husband or partner, no external registry is needed or helpful.
Post reply on HN