Live data from Hacker News

23andMe changed its terms of service to prevent hacked customers from suing

engadget.com

241–250 of 402 posts

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#241
post #186

Earlier quoted context omitted.

Exactly. Same reason construction vehicles have "Stay back 200 feet: not responsible for broken windshields" written on the back.

At least in California, its illegal for anything to fall from a vehicle except water and bird feathers so not sure how that sign help them.

What about fallen leaves?

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#242
post #12

Automatically opting-in customers to a more restrictive TOS is pretty suspect, especially given the timing. IANAL, but I'm pretty sure that a court would not allow that, given that the TOS was changed AFTER the breach and it's pretty clear that the company is trying to avoid legal issues after-the-fact. I would expect the court would evaluate any breach under the TOS that was in effect at the time of the breach, rath…

"a court would not allow that"

I don't know where you have been the last few years, but I am pretty sure things like that happen all the time, based on the emails I received regarding ToS updates. And I have never heard any company got into trouble in court. Maybe public opinion, but that's it.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#243
post #42

Earlier quoted context omitted.

Exactly my thoughts. I'd be more upset if a combination of my name and email/phone number got leaked than if my DNA was made available public.

Why would you be upset if your name+phone combo was leaked? Mine is all over internet so wonder why you feel it would be bad.

I simply don't want to deal with spam or scams. If I'm exposing my contact details it would be a separate set that is dedicated to dealing with communication coming from the public.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#244

Huge HIPPA violation as well.

> Huge HIPPA violation as well.

It's HIPAA.

IANAL: And unless 23andMe meets the HIPAA definition of a "covered entity", which I'm not sure they do, they're not going to be covered by HIPAA.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#245
post #78

Earlier quoted context omitted.

Most of the time we're leaking our DNA all over the place by existing

So you would be ok if governments around the world have sample of yours and store it in a database?

No, the company in question made promises about the security of it and has broken those promises. Now their customer's DNA is potentially available to anyone (not just governments). They should pay dearly for breaking these promises. This is not the point of my original comment.

The person I'm responding to is victim-blaming, and also making the completely silly claim that it's irresponsible to willingly "leak" DNA through some vague lens that it's going to be used to harm your descendants for generations.

DNA sequencing is constantly becoming more affordable and accessible. Unless regulated, this will be data that gets collected and abused en-masse. It's a little expensive now, but I could easily sequence just about anyone's DNA today as long as I have some sort of physical access to a space they use. If that's the commenters concern, they'd be much better off focusing on that rather than blaming people for expecting a company to keep medical data secure.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#246
post #21

I would have presumed that security-minded people, which includes those who work in tech, would not so easily give away their genome, and that most of 23andMe's customers are a slice of the general population. But then I read about things like WorldCoin and that people who go to startup parties jump at the chance to give away scans of their retinas and I'm befuddled. Why would anyone willingly do that?

>But then I read about things like WorldCoin and that people who go to startup parties jump at the chance to give away scans of their retinas and I'm befuddled.

I'm befuddled that anyone thinks Sam Altman is the least bit trustworthy after WorldCoin.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#247

Earlier quoted context omitted.

I wonder if they can use things like opt out data to find a way screen for genetic markers of "troublemakers" or similar. DNA driven targeted advertising that finds only the most docile consumers.

They can't tell you your eye color from their DNA data with any degree of confidence, and you seriously expect them to be able to find a marker of something as vague as "troublemakers" ?!

https://pubmed.ncbi.nlm.nih.gov/19619260/ """Nevertheless, it has been estimated that 74% of the variance in human eye colour can be explained by one interval on chromosome 15 that contains the OCA2 gene"""

That's about blue/brown, and realistically, there are a bunch of other genes which also have effects, as "eye color" is really a collection of phenotypes, not just a single one.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#248

Earlier quoted context omitted.

This looks like a perfect class action case. There's really no physical harm or financial harm to the users, but a class action might be the only way for it to hurt. But IANAL, and probably have it all wrong in my head???

Why is it that in the US individuals have to band together and privately launch a class action to stop these types of parasitic behaviours. The government is supposed to represent the interests of citizens.

1) Common law versus civil law. We rely a lot more on private lawsuits than on regulator action. This is probably a mistake, given that it sure looks like it adds costs to common law countries with little to no benefit (and, arguably, harm) but it’s what we have.

2) The consumer protection laws we do have, and the bodies to enforce them, are relatively weak and enforcement is spotty at best. The most recent serious attempt to kinda fix this is the formation of the CFPB, and one of our two relevant political parties deliberately prevents it from working when they hold the White House (sample size of one, admittedly) and has been trying to totally kill it, in the legislature or (better, because it’s popular and this is deniable) in the courts.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#249
post #183

Earlier quoted context omitted.

I think what they're saying is that name (probably not), SSN (almost definitely), DOB (maybe?) and address (probably) have known , confirmed risks. There are current ways that bad actors can abuse that information. Genome is still pretty theoretical, except getting caught for committing crimes.

I just checked, and using my True Name ( https://en.wikipedia.org/wiki/True_Names ) I can easily find my DOB, prior addresses and phone numbers, and using that information, it's likely I could make a reasonable guess for the SSN.

it's likely I could make a reasonable guess for the SSN.

It is? I mean then why are we bothering to protect anything, this shit is all super available for any given person.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#250
post #189

Earlier quoted context omitted.

I don't believe making my genome available, which contains similarity to my relatives, is a breach of their privacy. I think part of my point is that DNA, by its nature, simply cannot remain confidential, and that thinking we can keep it that way is just going to lead to inevitable disappointment.

First, some people extend your argument from DNA to everything and say "I believe that privacy in the modern world is unrealistic"; that doesn't make the argument applicable to the rest of us. Second, whether DNA can or cannot remain confidential is yet to be seen, but feasibility is certainly orthogonal to whether it ought to be, which is the point at hand. Third, whether you believe it's a breach of privacy to leak…

To your first point: Yes, I generally extend my argument to more or less everything in the modern world. Put your garbage out on the street: reporters can rifle through it looking for evidence.

To your second point: we already know DNA can't remain confidential (there is no practical mechanism by which even a wealthy person could avoid a sufficiently motivated adversary who wanted to expose their DNA). That's just a fact, we should adjust our understanding based on that fact.

Most important: sharing my genomic information with the world is not a breach of any privacy framework I'm aware of and subject to (US laws). Do you have a specific framework or country in mind?

Post reply on HN