Live data from Hacker News

DNA testing company vanishes along with its customers' genetic data

malwarebytes.com

31–40 of 52 posts

Re: DNA testing company vanishes along with its customers' genetic data

#31
post #27

Earlier quoted context omitted.

You can download your data from 23andMe and request deletion, FYI.

and hope they're really deleted and not just marked as deleted.

Sad state of affairs - this is so messed up. No trust anywhere! I’m senior Software Architect in Germany and some years ago we built an app that handles highly confidential tax-related data. And we did everything to stick to the highest standards: Strong encryption, distribution of keys and data into different datacenter operated by different companies, protocols of deletion of data, implementing every aspect of DSGVO, including Art.35 - „creation of a DSFA (Assessment Of Consequences of Data Privacy Measures)“ more than 100 pages thick. Guess what: When I tell customers that we cannot read and really delete their data - they straight up accuse me of lying!

Re: DNA testing company vanishes along with its customers' genetic data

#32

This sort of thing was only a matter of time. The clock is also ticking on 23andMe going bankrupt and selling their assets (your PII) to stay afloat. https://hoodline.com/2024/11/23andme-in-turmoil-stock-plunge...

You can download your data from 23andMe and request deletion, FYI.

The key word in that sentence:

"request"

Re: DNA testing company vanishes along with its customers' genetic data

#33
post #27

Earlier quoted context omitted.

and hope they're really deleted and not just marked as deleted.

Sad state of affairs - this is so messed up. No trust anywhere! I’m senior Software Architect in Germany and some years ago we built an app that handles highly confidential tax-related data. And we did everything to stick to the highest standards: Strong encryption, distribution of keys and data into different datacenter operated by different companies, protocols of deletion of data, implementing every aspect of DSGV…

Consider these statements:

- state level actors can basically break into any computer system given enough time

- corporate databases have a gigantic amount of information on everyon

- states want all of that data

I hope the conclusion is as straightforward as it seems to me.

OK, not exactly what you are responding about Let's talk about corporate IT systems, let's get into "deleted". Is it:

- deleted from backups? Almost universally this answer will be no.

- deleted from each and every database and system in your presumably huge corporation, which may involve literally thousands of IT systems? I'd guess no.

- is it deleted by moving the data to a separate "deleted data" table or database, thus sequestering the data from the "active data" rather than deleting it, just in case you want to "undo"?

- is it deleted from all system logs?

- is it deleted from all records systems that may have minimum retention periods legally or by policy?

- what about data warehouses or data lakes that repackage/mirror data?

Re: DNA testing company vanishes along with its customers' genetic data

#34
post #27

Earlier quoted context omitted.

and hope they're really deleted and not just marked as deleted.

Sad state of affairs - this is so messed up. No trust anywhere! I’m senior Software Architect in Germany and some years ago we built an app that handles highly confidential tax-related data. And we did everything to stick to the highest standards: Strong encryption, distribution of keys and data into different datacenter operated by different companies, protocols of deletion of data, implementing every aspect of DSGV…

> When I tell customers that we cannot read and really delete their data - they straight up accuse me of lying!

I'd accuse you too. If you can't read their data, then the data doesn't exist? Also, if you can't read read their data, how are the customers seeing it on their dashboard?

Re: DNA testing company vanishes along with its customers' genetic data

#35
post #12
post #9

Earlier quoted context omitted.

... and from what I can tell, most people just wanted to know their nationality.

I found out my nationality by looking at the front of my passport.

I think he meant ethnicity.

Re: DNA testing company vanishes along with its customers' genetic data

#36
post #28
post #26

Earlier quoted context omitted.

> They aren't truly geographical- they're based on population structure in the genome. Determining whether people are genetically similar is indeed well-studied. The problem is saying with certainty that you know where their ancestors lived. There are a few ways the results end up being inaccurate, and they apply to all the companies. The first and most important is that the data is from where people live now or in t…

My doctorate is in biophysics with deep experience in genomics. I've attended talks from the world's leading experts (as well as scientists/researchers/engineers) who work in this field, and read papers. From my inspection of the data, identity by descent does exactly what the researchers say, with a level of accuracy that is consistent with our current understanding of population structure and its changes in the pas…

We seem to be talking past each other.

You're saying it's possible to accurately determine how closely related individuals (and even groups) are.

I agree.

But you can't determine where those individuals' ancestors lived at any given time unless you also have historical data. Land does not imprint upon DNA.

So these companies can tell me that I have many distant cousins in, say, Brazil and Portugal, and we can make an inference that I'm of Portuguese descent. But clear-cut situations like that are extremely rare unless good genealogy records are kept as well and can be combined with genetic testing.

Re: DNA testing company vanishes along with its customers' genetic data

#37
Looks still alive, probably just closed their UK branch.

https://atlas.ru/about

They are subject to FZ 152, Russian equivalent of GDPR, as well as DNA-specific regulations which AFAIR are more strict. Not sure though if they care about foreign users.

Re: DNA testing company vanishes along with its customers' genetic data

#38
post #34

Earlier quoted context omitted.

Sad state of affairs - this is so messed up. No trust anywhere! I’m senior Software Architect in Germany and some years ago we built an app that handles highly confidential tax-related data. And we did everything to stick to the highest standards: Strong encryption, distribution of keys and data into different datacenter operated by different companies, protocols of deletion of data, implementing every aspect of DSGV…

> When I tell customers that we cannot read and really delete their data - they straight up accuse me of lying! I'd accuse you too. If you can't read their data, then the data doesn't exist? Also, if you can't read read their data, how are the customers seeing it on their dashboard?

Client-side encryption?

Re: DNA testing company vanishes along with its customers' genetic data

#39
post #22
post #16

Earlier quoted context omitted.

No, identity by descent works extremely well.

No it doesn't. We don't have DNA from 100 or even 50 years ago. These genetic tests are essentially geographical. For example, there are tens of millions of people in Africa and Latin America who unknowingly have mixed ancestry and will be labeled in the data set as being "from X country." That will mean the dataset thinks European genes might indicate Latin American descent or vice versa.

But we do have "DNA from 100 or even 50 years ago". In fact, we have DNA from much, much longer ago. Ancient DNA as a field is heavily invested in exploring past human populations, so there quite a lot of data available at this point

Re: DNA testing company vanishes along with its customers' genetic data

#40
post #27

Earlier quoted context omitted.

and hope they're really deleted and not just marked as deleted.

Sad state of affairs - this is so messed up. No trust anywhere! I’m senior Software Architect in Germany and some years ago we built an app that handles highly confidential tax-related data. And we did everything to stick to the highest standards: Strong encryption, distribution of keys and data into different datacenter operated by different companies, protocols of deletion of data, implementing every aspect of DSGV…

That’s an interesting point to add to the feature list of a future product: “Proof” of deletion that is plausible to laypeople. Of course one has to delete according to the law, too, but that plausible proof may get rid of a lot of support calls escalating to your level.
Post reply on HN