Live data from Hacker News

23andMe changed its terms of service to prevent hacked customers from suing

engadget.com

171–180 of 402 posts

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#171
post #12

Automatically opting-in customers to a more restrictive TOS is pretty suspect, especially given the timing. IANAL, but I'm pretty sure that a court would not allow that, given that the TOS was changed AFTER the breach and it's pretty clear that the company is trying to avoid legal issues after-the-fact. I would expect the court would evaluate any breach under the TOS that was in effect at the time of the breach, rath…

> IANAL, but I'm pretty sure that a court would not allow that

You and a lot of the people who replied to you seem to be confusing what is unjust with what is illegal. You can't use one to deduce the other.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#172
post #78

Earlier quoted context omitted.

Most of the time we're leaking our DNA all over the place by existing

So you would be ok if governments around the world have sample of yours and store it in a database?

There is no practical way to prevent it, so yes, it's OK because there is no reasonable alternative.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#173
post #30
post #12

Automatically opting-in customers to a more restrictive TOS is pretty suspect, especially given the timing. IANAL, but I'm pretty sure that a court would not allow that, given that the TOS was changed AFTER the breach and it's pretty clear that the company is trying to avoid legal issues after-the-fact. I would expect the court would evaluate any breach under the TOS that was in effect at the time of the breach, rath…

Federal Arbitration Act severely, and nearly completely, ties courts hands around throwing out binding arbitrations. Of course, if people don’t accept the new terms, they are still bound by the one ones. But if you don’t opt out…

The good news is binding arbitration has some significant downsides for corporations - look up "mass arbitration".

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#174

I almost laughed out loud when I got the email a few days after the leak. There's no way a company can just change the TOS AFTER a major leak, right?

yes, companies can change TOS when they want regardless of what happened before, so long as they weren't legally prevented from doing so.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#175
post #127

In case anyone is interested I've been compiling as much factual information on arbitration here. Not yet complete but reasonably useful and well sourced https://grimreaper.github.io/arbitration/docs/problems/

thank you this is really helpful!

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#176
post #163
post #21

I would have presumed that security-minded people, which includes those who work in tech, would not so easily give away their genome, and that most of 23andMe's customers are a slice of the general population. But then I read about things like WorldCoin and that people who go to startup parties jump at the chance to give away scans of their retinas and I'm befuddled. Why would anyone willingly do that?

I'm familiar with security (I keep a copy of Applied Cryptography on my shelf for "fun reading") and tech, here's a copy of my whole genome: https://my.pgp-hms.org/profile/hu80855C Note it's a full human genome, far more data than a 23&Me report. You can download the data yourself and try to find risk factors (at the time, the genetic counsellors were surprised to find that I had no credible genetic risk factors). Pl…

I'm gonna start making clones of you.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#177
post #169
post #163

Earlier quoted context omitted.

I'm familiar with security (I keep a copy of Applied Cryptography on my shelf for "fun reading") and tech, here's a copy of my whole genome: https://my.pgp-hms.org/profile/hu80855C Note it's a full human genome, far more data than a 23&Me report. You can download the data yourself and try to find risk factors (at the time, the genetic counsellors were surprised to find that I had no credible genetic risk factors). Pl…

>well, gattaca, and maybe something else we can't predict, or insurance, or something something Sure, if you don't believe in any of the potential negative scenarios, anything goes. You could also post your full name, SSN, DOB, address, etc. here if you are secure in the knowledge that no harm could ever come of it.

I think we already know for sure that posting a combination of full name, SSN, DOB, and address is a reliable way to provide scammers with the necessary information to commit fraud.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#178
post #163

Earlier quoted context omitted.

I'm familiar with security (I keep a copy of Applied Cryptography on my shelf for "fun reading") and tech, here's a copy of my whole genome: https://my.pgp-hms.org/profile/hu80855C Note it's a full human genome, far more data than a 23&Me report. You can download the data yourself and try to find risk factors (at the time, the genetic counsellors were surprised to find that I had no credible genetic risk factors). Pl…

I'm gonna start making clones of you.

I'm fine with that, but merely having my genome sequence doesn't enable you to do that.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#179
post #169
post #163

Earlier quoted context omitted.

I'm familiar with security (I keep a copy of Applied Cryptography on my shelf for "fun reading") and tech, here's a copy of my whole genome: https://my.pgp-hms.org/profile/hu80855C Note it's a full human genome, far more data than a 23&Me report. You can download the data yourself and try to find risk factors (at the time, the genetic counsellors were surprised to find that I had no credible genetic risk factors). Pl…

>well, gattaca, and maybe something else we can't predict, or insurance, or something something Sure, if you don't believe in any of the potential negative scenarios, anything goes. You could also post your full name, SSN, DOB, address, etc. here if you are secure in the knowledge that no harm could ever come of it.

I think what they're saying is that name (probably not), SSN (almost definitely), DOB (maybe?) and address (probably) have known, confirmed risks. There are current ways that bad actors can abuse that information.

Genome is still pretty theoretical, except getting caught for committing crimes.

Post reply on HN