Live data from Hacker News

23andMe changed its terms of service to prevent hacked customers from suing

engadget.com

201–210 of 402 posts

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#201
post #12

Automatically opting-in customers to a more restrictive TOS is pretty suspect, especially given the timing. IANAL, but I'm pretty sure that a court would not allow that, given that the TOS was changed AFTER the breach and it's pretty clear that the company is trying to avoid legal issues after-the-fact. I would expect the court would evaluate any breach under the TOS that was in effect at the time of the breach, rath…

They probably know that it doesn't hold water legally. The hope is to victim blame as much as possible so that fewer people sue them in the first place. The next step will be to "remind" people about the TOS that they totally agreed to.

This looks like a perfect class action case. There's really no physical harm or financial harm to the users, but a class action might be the only way for it to hurt. But IANAL, and probably have it all wrong in my head???

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#202

Earlier quoted context omitted.

> If you do not notify us within 30 days, you will be deemed to have agreed to the new terms. WTF. This is outrageous. And I had find that email in my spam after I read this comment. Hope this POS company goes down in flames after this.

Write back "you agree to pay me $10M in compensation unless you reply in 30 days" ...

[deleted]

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#204
post #163

Earlier quoted context omitted.

I'm familiar with security (I keep a copy of Applied Cryptography on my shelf for "fun reading") and tech, here's a copy of my whole genome: https://my.pgp-hms.org/profile/hu80855C Note it's a full human genome, far more data than a 23&Me report. You can download the data yourself and try to find risk factors (at the time, the genetic counsellors were surprised to find that I had no credible genetic risk factors). Pl…

That's not the same risk because 23andme also has name, address, email. One risk if you have PII+genome is that a technically sophisticated entity can determine if you've physically been in a location. Also with an extensive PII+genome database they could find your family, for example for blackmail purposes. Another risk is that a health insurance provider could deny you based on potential health issues they find in…

Yes, but technically sophisticated entities can also use methods that require less effort.

https://xkcd.com/538/

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#205
post #6

I'm not a lawyer but I doubt that this will matter in the court because the time of actions matter; or in another words at the time when user registered they agreed to TOS A and later when 23andMe changed their TOS A to TOS B they achieved nothing because you can't unregister users and register them again and force them to agree to the new TOS B. I mean they can ask you to agree to new TOS but you don't have to becau…

> I mean they can ask you to agree to new TOS but you don't have to because TOS is not a law Aren't they forcing you to agree to the new TOS to continue using the product?

Perhaps, but if someone ignores the email and never logs into or interacts with 23andMe in the meantime, the post hoc change in ToS should have no impact on their ability to join a class action lawsuit.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#207
post #169
post #163

Earlier quoted context omitted.

I'm familiar with security (I keep a copy of Applied Cryptography on my shelf for "fun reading") and tech, here's a copy of my whole genome: https://my.pgp-hms.org/profile/hu80855C Note it's a full human genome, far more data than a 23&Me report. You can download the data yourself and try to find risk factors (at the time, the genetic counsellors were surprised to find that I had no credible genetic risk factors). Pl…

>well, gattaca, and maybe something else we can't predict, or insurance, or something something Sure, if you don't believe in any of the potential negative scenarios, anything goes. You could also post your full name, SSN, DOB, address, etc. here if you are secure in the knowledge that no harm could ever come of it.

The question is, what are the potential negative scenarios.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#209
post #163
post #21

I would have presumed that security-minded people, which includes those who work in tech, would not so easily give away their genome, and that most of 23andMe's customers are a slice of the general population. But then I read about things like WorldCoin and that people who go to startup parties jump at the chance to give away scans of their retinas and I'm befuddled. Why would anyone willingly do that?

I'm familiar with security (I keep a copy of Applied Cryptography on my shelf for "fun reading") and tech, here's a copy of my whole genome: https://my.pgp-hms.org/profile/hu80855C Note it's a full human genome, far more data than a 23&Me report. You can download the data yourself and try to find risk factors (at the time, the genetic counsellors were surprised to find that I had no credible genetic risk factors). Pl…

Fully agree with you here. I can understand why people argue "We must do everything possible that no human being ever finds out anything medical-related about another human being, ever"

But that is a value judgement, and I believe it is one that comes at a great cost to society- I wouldn't be surprised if >50% of the cost of medical care is directly or indirectly due to this attitude, and that medical progress has been slowed immensely for the same reason.

If we could make medical data more open, it would greatly benefit the vast majority of people. OF COURSE it is true that some smaller number of other people/patients are helped by the existing medical secrecy system. I fully admit this is a trade-off, where we have to decide what values are more important.

(source: Am medical doctor)

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#210
post #186

Earlier quoted context omitted.

Exactly. Same reason construction vehicles have "Stay back 200 feet: not responsible for broken windshields" written on the back.

At least in California, its illegal for anything to fall from a vehicle except water and bird feathers so not sure how that sign help them.

If I'm not mistaken, that's the point the person above you was making. Those stickers on dump trucks that say "Stay back 200 feet. Not responsible for broken windshields" are worthless from a legal perspective.

They do absolutely nothing to remove liability from the truck driver/company. If a rock falls from their truck and cracks your windshield, they absolutely are responsible for any damages.

Rather, their sole value is to convince drivers that the trucking companies aren't at fault, so that drivers whose vehicles are damaged from falling rocks erroneously elect not to press charges or pursue damages.

Post reply on HN