Live data from Hacker News

23andMe changed its terms of service to prevent hacked customers from suing

engadget.com

151–160 of 402 posts

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#151

Earlier quoted context omitted.

In the US, the bad actor here is much more likely to be insurance companies who can tune their secret algorithms to make sure no one with a gene tied to an illness which blooms later in life can get affordable heath care.

In the US, health insurers can only price based on age, location, and tobacco use. Setting health insurance premiums or denying coverage based on any health-related factors has been illegal for over a decade, and changing that would be totally unviable politically. However, it's a significant risk for other types of insurance including life, disability, and long term care.

Just because it's illegal, doesn't mean health insurance companies don't find loopholes, and consider fines when they get caught as the cost of doing business. See this series of articles[1] for some of their criminal shenanigans.

It's more than likely that they would use genetic data to deny insurance, and then settle the cases in court if they happen to get sued, which statistically is probably a rare occurrence.

[1]: https://www.propublica.org/series/uncovered

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#152
post #21

I would have presumed that security-minded people, which includes those who work in tech, would not so easily give away their genome, and that most of 23andMe's customers are a slice of the general population. But then I read about things like WorldCoin and that people who go to startup parties jump at the chance to give away scans of their retinas and I'm befuddled. Why would anyone willingly do that?

It will be a cold day in hell before I ever submit to dna analysis of this nature. That doesn't stop my family from doing so, but I sure as hell will never.

So they've basically done it for you. Primary sensitive information is about is predisposition to hereditary disease. That's the same for you and your siblings.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#153

Earlier quoted context omitted.

Except that the truck driver has zero fault for the gravel on the road and the spacing between the tires and the mud guard of the truck his employer maintains. Or did you mean you’d seek out the ceo of the truck company and give them a black eye?

This is usually related to drivers who do not use the cover of their truck they are legally supposed to. So rocks fly out the top.

Also mud flaps

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#154
post #21

I would have presumed that security-minded people, which includes those who work in tech, would not so easily give away their genome, and that most of 23andMe's customers are a slice of the general population. But then I read about things like WorldCoin and that people who go to startup parties jump at the chance to give away scans of their retinas and I'm befuddled. Why would anyone willingly do that?

I was 24 in 2015 and not in tech or as security minded as I am now when I received the test as a Christmas present. Obviously now I wouldn’t have dared do it, but it’s too late. Lacked the foresight at the time.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#155
post #72

Earlier quoted context omitted.

No; this is factually wrong.

And not even a bit of clarifying? If you can convert the DNA sample into two DNA copies without destroying the sample, probably you are a God.

You said "The DNA we are leaking is impossible to copy unlike the DNA we are sending to 23andme."

I said it was wrong because if people collect environmental human DNA samples and "copy" them (amplify with PCR).

Not sure what you mean about destroying the sample- you typically take part of the sample and amplify it without destroying the whole thing.

I'm just unsure of what you are trying to say here; I'm responding with purely factual answers based on modern DNA technology.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#156
post #21

I would have presumed that security-minded people, which includes those who work in tech, would not so easily give away their genome, and that most of 23andMe's customers are a slice of the general population. But then I read about things like WorldCoin and that people who go to startup parties jump at the chance to give away scans of their retinas and I'm befuddled. Why would anyone willingly do that?

What's the implication here, that tech people should know better? I just don't care a ton about my privacy. At least that makes me not a hypocrite for working at a company that profits from user data (like many tech ones do).

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#157
post #7

To duck out of the new ToS, just write this email to legal@23andme.com-- To Whom It May Concern: My name is [name], and my 23andMe account is under the email [email]. I am writing to declare that I do not agree to the new terms of service at https://www.23andme.com/legal/terms-of-service/ .

> If you do not notify us within 30 days, you will be deemed to have agreed to the new terms. WTF. This is outrageous. And I had find that email in my spam after I read this comment. Hope this POS company goes down in flames after this.

Write back "you agree to pay me $10M in compensation unless you reply in 30 days" ...

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#158
post #140
post #21

I would have presumed that security-minded people, which includes those who work in tech, would not so easily give away their genome, and that most of 23andMe's customers are a slice of the general population. But then I read about things like WorldCoin and that people who go to startup parties jump at the chance to give away scans of their retinas and I'm befuddled. Why would anyone willingly do that?

The long term premise of WorldCoin is to not store retina scans in any way, and scanning stations in the US already do not do so.

'long term premise'

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#159
As someone living in the EU, these kind of things puzzle me a lot.

How can a legal system exist, where it's possible to deny a (consumer) contract party access to the legal system and law of the land?

(In the EU we do have arbitrations clauses, but they are only legal between businesses and tightly regulated. Arbitration "courts" must be neutral. And you can not put them into ToS.)

Also, I was under the impression that all sane legal systems on this planet are based on the broad principle of "pacta sunt servanda" = "agreements must be kept". One party of a contract never can change the contract without consent from the other party.

We do have the concept of "silent approval" for consumers over here, too, but that only applies to minor changes to terms that are not a "surprising" change to the consumer. It recently was ruled that for example Netflix increasing prices without active consent is not legal in the EU. There is not much that is not regarded as "surprising" by courts here. "You are not allowed to sue us after having lost your personal data, then lying about it" clearly would be regarded as surprising.

Im summary: Every aspect of that whole 23andMe story would be impossible in the EU. The amount of data they collected, the way they stored it, the way they tried to hide the breach, and them trying to prevent their customers to get access to the law.

I wonder how on earth the US legal system could deteriorate so much that such a story becomes possible.

[Disclaimer: I am not bragging about living in the EU. I did not have any influence on my place of birth. I do not wish to imply that the EU is "superior" to the US. I am just trying to give an outside perspective.]

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#160
post #75

Earlier quoted context omitted.

I'd say it's more than suspect, what's the point of agreeing to a terms of service if they can change after you agree to them?

They usually put that exact thing into the ToS. The right to change it at any time.

Just because they write that doesn't make it legally enforceable. You can't agree to terms you don't know. Which is why many services will haunt you to explicitly agree to the new ToS when you next log in.

And even if you click agree there are legal questions about how much that can change about your past relationship, and what kind of changes you can legally make.

Post reply on HN