Live data from Hacker News

23andMe changed its terms of service to prevent hacked customers from suing

engadget.com

181–190 of 402 posts

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#181

Earlier quoted context omitted.

Except that the truck driver has zero fault for the gravel on the road and the spacing between the tires and the mud guard of the truck his employer maintains. Or did you mean you’d seek out the ceo of the truck company and give them a black eye?

This is usually related to drivers who do not use the cover of their truck they are legally supposed to. So rocks fly out the top.

And usually because the truck is over full too. For almost any load, if you fill the truck to the brim you have overloaded it. (Unless you're moving styrofoam)

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#182
post #117

Earlier quoted context omitted.

The same people believed crypto-currency, infinite growth, social media and many other things. At least 23andMe provided actual value, to some at least. What I find strange is that 23andMe did not automatically delete data after 30 days, or at the very least took it offline, only to be available on request. Notify people that their results are available and inform them that the data will be available for 30 days afte…

What actual value did 23andMe and similar services offer in the first place? Quenching someone's curiosity about where their ancestors are from? Do we even know how accurate it is at doing that?

Locating secret/hidden family is kinda nice.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#183
post #169

Earlier quoted context omitted.

>well, gattaca, and maybe something else we can't predict, or insurance, or something something Sure, if you don't believe in any of the potential negative scenarios, anything goes. You could also post your full name, SSN, DOB, address, etc. here if you are secure in the knowledge that no harm could ever come of it.

I think what they're saying is that name (probably not), SSN (almost definitely), DOB (maybe?) and address (probably) have known , confirmed risks. There are current ways that bad actors can abuse that information. Genome is still pretty theoretical, except getting caught for committing crimes.

I just checked, and using my True Name (https://en.wikipedia.org/wiki/True_Names) I can easily find my DOB, prior addresses and phone numbers, and using that information, it's likely I could make a reasonable guess for the SSN.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#184

Earlier quoted context omitted.

You know, you can send other peoples DNA to sequencing services too…

Probably you can send to them anything else but how it relates to my comment?

Meaning that your DNA is not safe, even if you yourself never send it. DNA is leaking everywhere, anyone could collect it and send for analysis.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#185
post #10

Earlier quoted context omitted.

The email I got from 23andMe linked me to legal@23andme.com.

Yeah, but the actual terms say arbitrationoptout@23andme.com. I wouldn't put it past them to say "ah but you didn't email the right address".

Wow that is super hidden! They have a fake ToS to try to stop you from seeing the real one.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#186

Earlier quoted context omitted.

They probably know that it doesn't hold water legally. The hope is to victim blame as much as possible so that fewer people sue them in the first place. The next step will be to "remind" people about the TOS that they totally agreed to.

Exactly. Same reason construction vehicles have "Stay back 200 feet: not responsible for broken windshields" written on the back.

At least in California, its illegal for anything to fall from a vehicle except water and bird feathers so not sure how that sign help them.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#187
post #163
post #21

I would have presumed that security-minded people, which includes those who work in tech, would not so easily give away their genome, and that most of 23andMe's customers are a slice of the general population. But then I read about things like WorldCoin and that people who go to startup parties jump at the chance to give away scans of their retinas and I'm befuddled. Why would anyone willingly do that?

I'm familiar with security (I keep a copy of Applied Cryptography on my shelf for "fun reading") and tech, here's a copy of my whole genome: https://my.pgp-hms.org/profile/hu80855C Note it's a full human genome, far more data than a 23&Me report. You can download the data yourself and try to find risk factors (at the time, the genetic counsellors were surprised to find that I had no credible genetic risk factors). Pl…

For one thing, this leaks a portion of the genome of your relatives, which is a clear breach of their privacy. Whether you personally deem it sensitive or not, genetic data is meant to remain confidential.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#188
I honestly don't understand how "If you don't opt out within 30 days you'll be bound to the new TOS" works.

I have heard of two big "trends" of how people think about legal contracts:

[1] What is written there and what both parties agreed to is the truth.

[2] A contract is supposed to be a "meeting of the minds". If it's proven that one party was being deceitful, then the contract (or that part) doesn't hold.

If we go by [1], then the company can change the TOS by sending me a notice with "if you don't opt out, then you're bound by these terms"... but so should I. I should be able to send a letter to 23&me saying "if you don't disagree these are the new terms: if my information is ever hacked, you owe me 10M dollars in damages"

If we go by [2], then sending a notice like that is absolutely invalid. They have no way of proving that I read that notice within 30 days, so there was never a "meeting of the minds".

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#189
post #163

Earlier quoted context omitted.

I'm familiar with security (I keep a copy of Applied Cryptography on my shelf for "fun reading") and tech, here's a copy of my whole genome: https://my.pgp-hms.org/profile/hu80855C Note it's a full human genome, far more data than a 23&Me report. You can download the data yourself and try to find risk factors (at the time, the genetic counsellors were surprised to find that I had no credible genetic risk factors). Pl…

For one thing, this leaks a portion of the genome of your relatives, which is a clear breach of their privacy. Whether you personally deem it sensitive or not, genetic data is meant to remain confidential.

I don't believe making my genome available, which contains similarity to my relatives, is a breach of their privacy.

I think part of my point is that DNA, by its nature, simply cannot remain confidential, and that thinking we can keep it that way is just going to lead to inevitable disappointment.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#190
post #12

Automatically opting-in customers to a more restrictive TOS is pretty suspect, especially given the timing. IANAL, but I'm pretty sure that a court would not allow that, given that the TOS was changed AFTER the breach and it's pretty clear that the company is trying to avoid legal issues after-the-fact. I would expect the court would evaluate any breach under the TOS that was in effect at the time of the breach, rath…

Yep. Having defended contracts that legally the company could novate the circumstances that lead to the notation had to be either outside of our control with a third party changing our underlying costs or the first and second parties failing to agree a new contract and a standard contract that was already defined being put in place. This was later deemed unfair and the standard contract was made much cheaper. Ha!

My point being that in Australia my vibe is that this will be looked upon in a very negative light by courts and any regulators.

Post reply on HN