Live data from Hacker News

23andMe confirms hackers stole ancestry data on 6.9M users

techcrunch.com

201–210 of 321 posts

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#202

Earlier quoted context omitted.

Agreed, but also "privacy" is an abstraction that layers over the actual thing that people are worried about. Any answer to why do you care about hiding this information? can all be boiled down to the fear that "[person or group] might use [private data item] to create [bad outcome] for me." So the thing people actually care about is the risk of bad outcome, not the actual data itself. If your theory is correct, then…

> the focus should be on the prevention of asymmetric power imbalances in societal transactions The rules governing social systems built to obscure the jungle (e.g., political, legal, and penal systems) can always be trumped by that which they were chosen to tame. This is the unfortunate reality of our wetware. > the thing people actually care about is the risk of bad outcome, not the actual data itself "Bad" is subj…

> "Bad" is subjective, no? > Is it good or bad if a father learns that his teenage son is not his own?

I feel like that would depend on the person. If the father wanted to know and the son didn't, that would be good for one and bad for the other, and vice versa.

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#203
post #8

Something does not add up. "23andMe said the data breach was caused by customers reusing passwords" Yet 14,000 accounts were breached in one go? Where did these passwords come from? Maybe there was another related breach (something like lastpass can explain this)? Also, using the "DNA Relatives" features the hackers were able to access personal information relating to 6.9 million individuals. That means each one of t…

Seems plausible to me, assuming that my situation on 23andMe is about average when it comes to the number of DNA relatives and the vulnerability of my relatives to being hacked.

A quick search says 23andMe has 14 million customers, so 14000 accounts breached would be 1 in 1000 accounts breached.

The DNA relatives listing for me lists just over 1500 people. If each of those accounts had a 1/1000 probability of being hacked, the probability none of my relatives were hacked would be (1-1/1000)^1500 = 0.223. The probability that at least one of my relatives was hacked would then be 0.777.

I'd then expect, based on my assumption that I'm typical, about 10.8 million people to have had relatives with hacked accounts, which is close enough to 6.9 million that the latter seems plausible.

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#204

I never seriously considered using 23 and me. Not because of hackers, but rather what government would do with that information. I don't want to be responsible for some random relative getting charged with a crime just because I was curious about my family tree.

I’d really like my 23 and Me info, but I assumed it was only a matter of time before they were hacked or sold to an untrustworthy organization willing to sell out users to make a quick buck. If the test was done, the results were sent, and then my test data/info were destroyed on their end, or if I could do a home test where the data never left my home, then I’d do it. I struggle to understand why companies hold on t…

> I struggle to understand why companies hold on to all this data

To sell it, did you miss the news? https://www.bloomberg.com/news/articles/2023-10-30/23andme-w...

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#205
post #173

Earlier quoted context omitted.

So, the reason for privacy is because the profit motive of capitalism is not sufficiently restrained as to protect citizens from being abused by corporations?

Be careful you don't break something with those gymnastics. The immediate concern I had with this story is nefarious groups or individuals purchasing this data to target people with violence based on their ethnicities. Imagine if the genome of millions of Europeans was available on the black market in 1930s Europe.

Considering one of the hacker's first actions was to offer for sale data identifying people of Jewish or Chinese descent I think that's a very valid concern.

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#206
post #8

Something does not add up. "23andMe said the data breach was caused by customers reusing passwords" Yet 14,000 accounts were breached in one go? Where did these passwords come from? Maybe there was another related breach (something like lastpass can explain this)? Also, using the "DNA Relatives" features the hackers were able to access personal information relating to 6.9 million individuals. That means each one of t…

[flagged]

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#207

Earlier quoted context omitted.

I can think of an easy model. Disallow collection of personal information. Pull the rug out from under "services" which are really just data collection fronts turning a profit from selling your data instead of the primary service/good for money transaction. 23andMe could still have operated legally under this scheme. They could have done the analysis and sent you a printed sheet. But no, they had to store everything…

They are frank about also selling the data for research, it is not underhanded. It's even opt in... For example, they talk about it on this page, which is linked from the about menu (so available with pretty small effort): https://www.23andme.com/research/ I expect lots of people also like that they get updates when information about new markers becomes available.

I trust them to opt me out, not at all. It's safer to just assume your data is being used, regardless, because it's free money to them. If/when they get caught selling data marked as Opted Out, they'll get a pittance fine, paid with other people's money and bonuses for making numbers that quarter.

You're welcome to trust them, but no I.

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#209
post #173

Earlier quoted context omitted.

Be careful you don't break something with those gymnastics. The immediate concern I had with this story is nefarious groups or individuals purchasing this data to target people with violence based on their ethnicities. Imagine if the genome of millions of Europeans was available on the black market in 1930s Europe.

Considering one of the hacker's first actions was to offer for sale data identifying people of Jewish or Chinese descent I think that's a very valid concern.

Did anybody actually buy it though? This could be misdirection, or just misguided marketing based on historical instances of abuse. China isn't known for trying to repatriate descendants, and it's not exactly difficult to find Jews.

Ancestry data would certainly be of interest to a particular demographic known to discriminate by caste. There's no escaping your low-class heritage when anyone can look up your stolen DNA profile on the black market.

Re: 23andMe confirms hackers stole ancestry data on 6.9M users

#210

Does anyone think privacy of any real sort is maintainable going forward? Machine learning algorithms are learning to identify people just by their walk -- no face recognition required. Algorithms are moving toward being able to decipher text just by the audio of the keyboard being typed on. In short, given a gestalt of ALL public data and sufficiently advanced algorithms is there really a way for people to maintain…

> Machine learning algorithms are learning to identify people just by their walk... Turns out the UK government was working on privacy-preserving walks decades ago: https://youtu.be/eCLp7zodUiI

[dead]
Post reply on HN