Live data from Hacker News

Breach exposed more than one million DNA profiles on a major genealogy database

buzzfeednews.com

171–180 of 424 posts

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#171
post #154

That’s why I bought the tests on Amazon on Father’s Day sale. Then used completely fake info and fake email to register on the testing company site. Totally anonymous as there’s no way to link the purchase to results.

You used a fake address to send the results?

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#172
post #166

This is why I want a genetic sequencing lab that will sequence your genome, send it to you encrypted by your own public key and once you confirm receipt and verify it is valid, DELETE IT COMPLETELY. Along with the record you were their customer after the 6 months or whatever required for waiting out chargebacks. Then you can analyze your DNA with a desktop app that doesn't send out any data. The deleting part is hard…

Seems unlikely to be a sustainable business.

For GEDMatch, Ancestry.com, 23andMe, etc, most of the value comes from being able to aggregate many people's data. If they had to delete it after collecting, they'd have to charge a lot more, and there's just no market for that.

Perhaps they could anonymize the data (at least, purge foreign key references to account/billing info) after 6 months, but not delete it.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#173
post #56

Earlier quoted context omitted.

Right, maybe this is where I’m being ignorant, but would there be a way to do the actual sequencing down to a consumer device? I presume the machines used are pretty complex.

DNA sequencers are not that expensive [1]. And I’m told the actual lab work is not that hard or dangerous (high school level?). I fact, the database correlating millions of people’s DNA with their medical history and migration history is probably the hardest part. But the potential market is there. I’d gladly play $1000 to have my sequence, even unanalyzed, with the knowledge no one else does. 1 cursory look at eBay.…

I'm assuming that you meant to link a MinION (as it's the only device I know of at that price point). They would be fit for human DNA, though a single flow cell (consumable part that will degrade after X amount of DNA read) might not be quite enough to read a whole human genome with the desired accuracy.

So if you purchase all the consumables (flow cells + chemicals) in low quantities, a single human genome will probably run you around $2000 in materials. With the bulk orders from their website you could get it down to half of that (so probably even more if you were doing really big bulk orders).

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#174
post #172
post #166

This is why I want a genetic sequencing lab that will sequence your genome, send it to you encrypted by your own public key and once you confirm receipt and verify it is valid, DELETE IT COMPLETELY. Along with the record you were their customer after the 6 months or whatever required for waiting out chargebacks. Then you can analyze your DNA with a desktop app that doesn't send out any data. The deleting part is hard…

Seems unlikely to be a sustainable business. For GEDMatch, Ancestry.com, 23andMe, etc, most of the value comes from being able to aggregate many people's data. If they had to delete it after collecting, they'd have to charge a lot more, and there's just no market for that. Perhaps they could anonymize the data (at least, purge foreign key references to account/billing info) after 6 months, but not delete it.

Much like you can't anonymize browsing history data, email metadata or financial transactions -- I suspect DNA information also cannot be satisfactorily anonymized.

"Anonymized data" is a marketing term.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#175

As someone who works in cybersecurity, it's always hard for me to interpret PR language like "orchestrated through a sophisticated attack". This could be aimed towards non-savvy readers meaning basically anything or it could be accurate and describe a nation-state (although I don't get the feeling of a sophisticated nation-state actor here). The DoJ used similar wording when prosecuting Aaron Schwartz for using Pytho…

On the subject of nation-states, they want the data to help out spies

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#176
post #151
post #24

Earlier quoted context omitted.

> One of the core tenets of Mormon faith is that the dead can be baptized into the faith after their passing. Baptism of the dead evolved from the beliefs that baptism is necessary for salvation and that the family unit can continue to exist together beyond mortal life if all members are baptized. > Mormons trace their family trees to find the names of ancestors who died without learning about the restored Mormon Gos…

That leads to my afterlife nightmare scenario. I die bravely in glorious battle and am chosen by the Valkyries for Valhalla. One evening as we feast after that day's fighting, quaffing giant tankards of mead and boasting of our deeds, there comes a knock at the door. Two young men in suits enter, and go to speak to Odin. Odin then call for me to come over. He tells me that the young men are Mormons, and that some dis…

I believe the "if you live a good life you go to heaven" is a common tenet of many Christian denominations since the Vatican Council.

At least, I recall my religion teacher (a catholic priest, we have such a class in public schools in Italy tho they vary in content and quality) telling us that some decades ago.

You do not go to heaven if you're an atheist tho, as _denying_ there is something divine puts you in the bad list, sorry.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#177
post #172
post #166

This is why I want a genetic sequencing lab that will sequence your genome, send it to you encrypted by your own public key and once you confirm receipt and verify it is valid, DELETE IT COMPLETELY. Along with the record you were their customer after the 6 months or whatever required for waiting out chargebacks. Then you can analyze your DNA with a desktop app that doesn't send out any data. The deleting part is hard…

Seems unlikely to be a sustainable business. For GEDMatch, Ancestry.com, 23andMe, etc, most of the value comes from being able to aggregate many people's data. If they had to delete it after collecting, they'd have to charge a lot more, and there's just no market for that. Perhaps they could anonymize the data (at least, purge foreign key references to account/billing info) after 6 months, but not delete it.

It’s not unstable in anyway. What he’s describing is a lab. Lots of labs will do exactly what he wants.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#178
post #166

This is why I want a genetic sequencing lab that will sequence your genome, send it to you encrypted by your own public key and once you confirm receipt and verify it is valid, DELETE IT COMPLETELY. Along with the record you were their customer after the 6 months or whatever required for waiting out chargebacks. Then you can analyze your DNA with a desktop app that doesn't send out any data. The deleting part is hard…

There's a massive tension between privacy and utility. Most of the value of having the data is in publishing it so you can match with relations.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#180
I understand the desire to trace one's family history, find/treat diseases, discover murderers, etc. However, any time I read about these types of personal information breach events (DNA and genealogy could arguably be the most personal info of all) I so badly wish we didn't have this tech to begin with and how much present day sucks compared to the past as a direct result of these personal data mining tech companies (thinking social media, surveillance as well). I also wish the general population thought more clearly about the long term consequences of their information being in the hands of others before they so naively and/or willingly divulge it. Worse yet, we often don't have the choice. Nightmare scenarios where some could wield such information to do harm are not too difficult to think up, and if we are really being honest with ourselves, are occurring present day. Personal information data playgrounds like Facebook become precision tools for deception and oppression at best, genocide at the worst (thinking Myanmar). Not to single out Facebook, imagine what a psychopathic genocidal leader could do with 23andme data. With the rampant data collection, the human population has never faced this scale and breadth of societal threat before and we are indirectly feeling the consequences of it in our lives daily. I wish we could go back.
Post reply on HN