Live data from Hacker News

DNA testing company vanishes along with its customers' genetic data

malwarebytes.com

51–52 of 52 posts

Re: DNA testing company vanishes along with its customers' genetic data

#51
post #42

Earlier quoted context omitted.

Not always. For example, my birth certificate has my father’s name on it. I am in my 30’s, and it was only a few months ago that I learned that I was conceived via IVF, and that my biological father was a sperm donor. In my case, my mother told me. But I could have also learned that from a DNA test. (Which I have since taken. As a result, I now know the identity of my biological father.) It is not uncommon for DNA te…

Which bit of ancestry means more to who you are?

The family that raised me surely had more of an impact on my identity, but both parts of my ancestry are independently significant to me.

My point, though, was that using birth and death records to trace your ancestry is not always reliable.

Re: DNA testing company vanishes along with its customers' genetic data

#52
post #34

Earlier quoted context omitted.

Sad state of affairs - this is so messed up. No trust anywhere! I’m senior Software Architect in Germany and some years ago we built an app that handles highly confidential tax-related data. And we did everything to stick to the highest standards: Strong encryption, distribution of keys and data into different datacenter operated by different companies, protocols of deletion of data, implementing every aspect of DSGV…

> When I tell customers that we cannot read and really delete their data - they straight up accuse me of lying! I'd accuse you too. If you can't read their data, then the data doesn't exist? Also, if you can't read read their data, how are the customers seeing it on their dashboard?

I try to explain it shortly: The encrypted data is in a different datacenter than the keys needed to decrypt the data. The services we implemented to bring both together run in an secured environment that has no services implemented to access the servers and where physical access is restricted. Errors and monitoring data gets out, PII does not. Everything is documented and was inspected and certified by a 3rd party. If a customer requests to delete his data we instantly delete the key, a litte later we delete the (already useless) data and all backups will lose this information about a month later too.

And of course we did that not because we are nice people (though we belive we are). We did it, because we had the hypothesis that a reputation to handle the user-data with proofable utmost respect to security and privacy would be more valuable than having access to this data.

People not believing us or accusing us of lying obviously defy that hypothesis.

Post reply on HN