Live data from Hacker News

23andMe confirms hackers stole ancestry data on 6.9M users

techcrunch.com

181–190 of 321 posts

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#181

Earlier quoted context omitted.

So, the reason for privacy is because the profit motive of capitalism is not sufficiently restrained as to protect citizens from being abused by corporations?

How do you make the leap to it being an issue of capitalism? There are plenty of bad actors who could use this information (or other hacked info) who are not a corporation seeking profit.

Like North Korea which by far has the most state sponsored cyber thugs per capita.

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#182

Earlier quoted context omitted.

Fair. On the other hand, I'm a bit surprised that anti-immigrant forces in the US haven't made DNA sampling compulsory for new immigrants. The argument would be these would be harder to track down by these techniques, because the ancestry information is not as available, giving them an "unfair" advantage over white Americans.

I don’t think that fits with how people on this side of the pond think about immigration.

It fits with how some people think about immigration on either side of the pond. That some is close to 50% on the western side of the pond.

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#183

It does feel at this point that any company collecting data will be hacked, it's only a matter of "when" and no "if"...

Not because it’s hard work to protect themselves. But because it’s typically not a business priority (at top middle and via coercion and incentives, the bottom/workers too) to invest in security. Most of these big hacks are via well known threats that can be caught in typical good-faith auditing

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#184

Earlier quoted context omitted.

That’s not what the comment was driving at. At all. It’s about how data you think is innocent can be used in a manner you never thought about nor intended for dark purposes.

I actually had intended to point out the dangers of "scope creep". Everyone is happy with a lot of pretty invasive stuff - dragnet surveillance, targeted surveillance (i.e. bugs placed in a suspect's home/car/computer/phone), DNA and fingerprint mass tests, no-knock raids - in severe crime cases such as terrorism, murder, rape, child sexual exploitation or abduction. So far, so good, and almost all Western countries…

> Everyone is happy with a lot of pretty invasive stuff

I beg to differ. The fact we're even having this discussion means not everyone is happy with the situation. Maybe Stockholm Syndrome has kicked in for you, but I'm still resisting

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#185

Earlier quoted context omitted.

Right, like the person posting an idea on an Internet forum was the first and only person to have that idea. Security through obscurity does not work. It’s much better to open up the curtains and let the sunlight in. It’s the best disinfectant. At least then everyone is working with all of the information.

Blinds open btw. I’m picking up what you are gracefully throwing down but not without checks and balances.

My checks are bouncing off the heavily skewed balance. These internet posts are pretty much the only "checks and balances", and they do diddly squat.

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#186
post #57

Isn't it time governments start to regulate passwords ? (They already regulate a lot of privacy issues like medical and financial history. Some governments even regulate the use of finger print authentication of employees) For example, any website that allows users to choose normal, easy to remember passwords should meet a long list of requirements: For example security audits, bug bounties, capital reserves to deal…

Please have a look at the "recommendations" of your national security agency (except NIST).

It is all outdated, written by people who thought they understood security in the 90's.

The French ANSSI recommendations are ridiculous. The German as well. Having an incompetent gov org forcing you to apply their "best practices" is terrible.

We have already for banks and look at what they have done: all possible "don't do it!" implementations neatly on one page (source: Boursobank, Fortuneo and other French banks who replay that the security is "reviewed by experts")

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#187
post #174

Earlier quoted context omitted.

Or a rival country could create a virus that targets 80% of their enemies population and only 20% of their own

This is tin-foil hat nonsense.

It is becoming far easier than you are aware then. Sam Harris and Rob Reid discussed in length a few years ago.

https://www.samharris.org/podcasts/making-sense-episodes/spe...

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#188

This disaster is the perfect counter-argument to those always saying "why do you care so much about privacy. It doesn't affect you when I share things. You can just choose not to do it", except no, I can't choose when we're relatives and you chose to share our genome. It is so obvious that your relatives sharing their genomic data with 23andMe reveals a lot of information about you. We can only hope people will reali…

I guess I'm feeling a bit philosophical today, but in some sense, aren't we all part of a shared data structure given that we are all somewhat related? While there a few bits that make us individuals, there is much that is shared to the point that privacy doesn't seem truly possible.

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#190

Does anyone think privacy of any real sort is maintainable going forward? Machine learning algorithms are learning to identify people just by their walk -- no face recognition required. Algorithms are moving toward being able to decipher text just by the audio of the keyboard being typed on. In short, given a gestalt of ALL public data and sufficiently advanced algorithms is there really a way for people to maintain…

Agreed, but also "privacy" is an abstraction that layers over the actual thing that people are worried about. Any answer to why do you care about hiding this information? can all be boiled down to the fear that "[person or group] might use [private data item] to create [bad outcome] for me." So the thing people actually care about is the risk of bad outcome, not the actual data itself. If your theory is correct, then…

> the focus should be on the prevention of asymmetric power imbalances in societal transactions

The rules governing social systems built to obscure the jungle (e.g., political, legal, and penal systems) can always be trumped by that which they were chosen to tame. This is the unfortunate reality of our wetware.

> the thing people actually care about is the risk of bad outcome, not the actual data itself

"Bad" is subjective, no?

Is it good or bad if a father learns that his teenage son is not his own?

Post reply on HN