Live data from Hacker News

Ancestry.com can use your DNA to target ads

freedom-to-tinker.com

11–20 of 41 posts

Re: Ancestry.com can use your DNA to target ads

#12
post #9

Earlier quoted context omitted.

> If I could do so anonymously, I'd do it in a heartbeat You can. See "How to use 23andMe without violating your genetic privacy", https://www.abine.com/blog/2013/23andme-without-violating-yo... .

Of course, now you have to trust that Abine won't pas your information on to NSA.

I would be more concerned with information being passed to providers of life, disability, or long-term care insurance. The Genetic Information Nondiscrimination Act (GINA) prohibits the use of genetic information in health insurance and employment, but not those areas.

That seems unlikely, though. The article's approach is probably enough to prevent one's genetic information from being passed on to such insurance providers.

Re: Ancestry.com can use your DNA to target ads

#13
Everything to do with DNA sequences ought to be done by personal agents who are certified, licensed and bonded. And subject to strict oversight and liability. Or it could be done client-side, by those with requisite skills and resources. Only specific information, suitably redacted and abstracted, should be submitted to untrusted third parties.

Sending swabs to untrusted firms is just batshit insane, in my humble opinion. And being "anonymous" is rather pointless. It's ones DNA! That's an ultimate biometric.

Re: Ancestry.com can use your DNA to target ads

#14

This is one of the reasons I've never sent a DNA swab to Ancestry.com, or 23andme. If I could do so anonymously, I'd do it in a heartbeat - but the potential losses+ outweigh the gains%. + admittedly, I'm not even sure what the worst case scenarios are, but that just makes them even scarier. % ooooh, I might learn that I have a predisposition to alcoholism and rectal cancer? That's nothing that my Russian father coul…

> I'd do it in a heartbeat If the benefits aren't really significant why are you interested in doing so anonymously?

Mostly curiosity. For instance, I'd like to know what percentage Neanderthal DNA I have.

Plus, if I am at a significant risk of certain diseases, I'd like to know. I just don't want anyone else to know.

Re: Ancestry.com can use your DNA to target ads

#15
post #8

Earlier quoted context omitted.

Once I checked out, I went to my real, personal inbox to complete the 23andMe registration by clicking the confirmation email, which was forwarded to me from the alias email address. LOL. Thanks for posting this bit of comedy.

How was that problematic? I don't see the issue, especially given that the author was on a VPN and using Firefox in Private Browsing mode while running DoNotTrackMe.

Most email is sent unencrypted, so the NSA likely has a record of that email and can cross-reference it with the 23 account if needed.

Even the header would probably be enough in this case, just to identify the particular masked email with the real email behind it.

Re: Ancestry.com can use your DNA to target ads

#16
post #13

Everything to do with DNA sequences ought to be done by personal agents who are certified, licensed and bonded. And subject to strict oversight and liability. Or it could be done client-side, by those with requisite skills and resources. Only specific information, suitably redacted and abstracted, should be submitted to untrusted third parties. Sending swabs to untrusted firms is just batshit insane, in my humble opi…

> And being "anonymous" is rather pointless. It's ones DNA! That's an ultimate biometric.

But unless it's tied to my identity, I don't care! It may be the ultimate biometric, but that only matters if they can compare it to my DNA by taking it from me directly - and at that point, they have my DNA, so it doesn't matter whether I previously provided it anonymously or not!

Re: Ancestry.com can use your DNA to target ads

#18
post #15

Earlier quoted context omitted.

How was that problematic? I don't see the issue, especially given that the author was on a VPN and using Firefox in Private Browsing mode while running DoNotTrackMe.

Most email is sent unencrypted, so the NSA likely has a record of that email and can cross-reference it with the 23 account if needed. Even the header would probably be enough in this case, just to identify the particular masked email with the real email behind it.

> Even the header would probably be enough in this case, just to identify the particular masked email with the real email behind it.

Are you implying that an HTTP header sent in the request to 23andme upon clicking the confirmation link would contain the forwarded email address of the user?

Unless the user were on a web page that included their email account name in the URL (and thus visible in the REFERER header), I don't see how that would happen. And I don't think I've ever seen an email system that puts the account name in the URL.

Re: Ancestry.com can use your DNA to target ads

#19
post #13

Everything to do with DNA sequences ought to be done by personal agents who are certified, licensed and bonded. And subject to strict oversight and liability. Or it could be done client-side, by those with requisite skills and resources. Only specific information, suitably redacted and abstracted, should be submitted to untrusted third parties. Sending swabs to untrusted firms is just batshit insane, in my humble opi…

> And being "anonymous" is rather pointless. It's ones DNA! That's an ultimate biometric. But unless it's tied to my identity, I don't care! It may be the ultimate biometric, but that only matters if they can compare it to my DNA by taking it from me directly - and at that point, they have my DNA, so it doesn't matter whether I previously provided it anonymously or not!

I suppose. But once there's a bunch of stuff online that's linked to your DNA data, anyone who has your DNA data can correlate it all. And tie it to your true name.

Bottom line, I see no compelling upside to putting ones DNA data on the Internet.

Re: Ancestry.com can use your DNA to target ads

#20
post #15

Earlier quoted context omitted.

Most email is sent unencrypted, so the NSA likely has a record of that email and can cross-reference it with the 23 account if needed. Even the header would probably be enough in this case, just to identify the particular masked email with the real email behind it.

> Even the header would probably be enough in this case, just to identify the particular masked email with the real email behind it. Are you implying that an HTTP header sent in the request to 23andme upon clicking the confirmation link would contain the forwarded email address of the user? Unless the user were on a web page that included their email account name in the URL (and thus visible in the REFERER header), I…

No, the email header sent by abine when they forward the email from 23andme. That contains their real email address in plaintext, and might also contain the masked address; if not, a timing attack given the time of 23's emails and the time of the forwarded email might work.

If the actual email is unencrypted, then the NSA gets everything for free.

Post reply on HN