Live data from Hacker News

23andMe changed its terms of service to prevent hacked customers from suing

engadget.com

271–280 of 402 posts

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#271
post #7

To duck out of the new ToS, just write this email to legal@23andme.com-- To Whom It May Concern: My name is [name], and my 23andMe account is under the email [email]. I am writing to declare that I do not agree to the new terms of service at https://www.23andme.com/legal/terms-of-service/ .

I am logging to my 23andme account to confirm my info and name registered there. I forgot my password and did a password reset. They have password requirement of 12 characters minimum. A bunch of security theater just to get hacked anyways

So as soon as a company gets hacked once, all of their security measures get recategorized as security theater?

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#272

Thanks for sharing. Will def opt out and roll into the class action suits already filed. Take security seriously people. Especially when dealing with super sensitive data.

Why did you send them your DNA? It was pretty obvious from day 1 that sending some random startup on the internet my DNA was a bad move.

Didn't really feel like a random startup - felt like one of the most innovative startups around, backed by impressive investors including Google, co-founder married to Sergey Brin... So perhaps in hindsight sending DNA to anyone is a bad idea, but if there were a startup one might have trusted, this was it.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#273

Earlier quoted context omitted.

Yes, yours specifically, but what if I want like 200.000 people so I can find one that has a DNA profile similar to mine, who could serve as a escape-goat or victim? Maybe I want to steal a kidney, or a child that could reasonably pass as my own?

> escape-goat Unless this is an online joke I don't get, I think you mean "scapegoat".

Seems to be the same thing.

"The concept comes from an ancient Jewish ritual described in the Bible, specifically in Leviticus 16. During the Day of Atonement (Yom Kippur), two goats were chosen: one to be sacrificed and the other to be sent into the wilderness, symbolically carrying away the sins of the community. This second goat was called the "Azazel" or the "scapegoat".

Over time, the term "scapegoat" evolved to have a more general meaning in English. It came to refer to a person or group that is unjustly blamed for the problems or misfortunes of others, reflecting the original ritual in which the goat was symbolically burdened with the sins of others before being sent away. "

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#274

I have tried to quickly diff the previous TOS with the new one and I wasn't able to identify any big changes. I would like to know what the actual changes are. I see a lot of articles criticizing the new TOS, but no one is showing the actual wording differences. Does anyone have an actual diff?

Comparing:

https://www.23andme.com/legal/terms-of-service/full-version/...

https://www.23andme.com/legal/terms-of-service/full-version/

two things jump out at me, as a layman:

insertion into the middle of Limitation of Liability "WITHIN THE LIMITS ALLOWED BY APPLICABLE LAWS, YOU EXPRESSLY ACKNOWLEDGE AND AGREE THAT 23ANDME SHALL NOT BE LIABLE FOR ANY DAMAGES"

Lots of changes to the Dispute Resolution, and new content re: Mass Arbitration. However, the previous ToS still had binding arbitration clauses, and stuff about class actions.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#276
post #163
post #21

I would have presumed that security-minded people, which includes those who work in tech, would not so easily give away their genome, and that most of 23andMe's customers are a slice of the general population. But then I read about things like WorldCoin and that people who go to startup parties jump at the chance to give away scans of their retinas and I'm befuddled. Why would anyone willingly do that?

I'm familiar with security (I keep a copy of Applied Cryptography on my shelf for "fun reading") and tech, here's a copy of my whole genome: https://my.pgp-hms.org/profile/hu80855C Note it's a full human genome, far more data than a 23&Me report. You can download the data yourself and try to find risk factors (at the time, the genetic counsellors were surprised to find that I had no credible genetic risk factors). Pl…

1) You can be subject to discrimination based on your ethnicity, race, or health related factors. That's especially a problem when the data leaks at scale as in 23andme's case because that motivates the development of easy-to-search databases sold in hacking forums. The data you presented here would be harder to find, but not the case with mass leaks.

2) It's a risk for anything that's DNA-based. For example, your data can be used to create false evidence for crimes irrelevant to you. You don't even need to be a target for that. You can just be an entry in a list of available DNA profiles. I'm not sure how much DNA can be manufactured based on full genome data, but with CRISPR and everything I don't think we're too far away either. You can even experience that accidentally because the data is out there and mistakes happen.

3) You can't be famous. If you're famous, you'd be target of endless torrent of news based on your DNA bits. You'd be stigmatized left and right.

4) You can't change your DNA, so when it's leaked, you can't mitigate the future risks that doesn't exist today. For example, DNA-based biometrics, or genome simulation to a point where they can create an accurate lookalike of you. They're not risks today, doesn't mean they're not tomorrow.

There are also additional risks involved based on the country you're living in. So, you might be living in a country that protects your rights and privacy, but it's not the case with the others.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#277
post #262

Earlier quoted context omitted.

Why do you think people are entitled to have genome data on you? The morality is flipped. Privacy is recognized as a core, natural right. Others have to prove their onus for wanting your biological data. Trusting others is a moral and character weakness, because you have no guarantees as to how that data will be used. Or more specifically, what new ways to analyze and take advantage of that data will become. I think…

I think if your prior includes "trusting others is a moral and character weakness" then I don't think it's useful for us to discuss this topic further. As for actuaries, in the US, the GINA law prevents health insurance companies from using this data. I think legal protection is much more important than attempting to hide my DNA.

The law could change, allowing the usage of your data without your consent.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#278

Earlier quoted context omitted.

I wonder what would happen if someone used one of the public email dumps and automated a mass opt-out of every email ever spotted in the wild.

wow, that's probably one of the most brilliant altruistic ideas I've read since buying other people's medical debt. this is probably why the unsubscribe links require some interactive confirmation so that simply loading the page doesn't actually unsubscribe. if this was doable, i'd put them above Troy Hunt in contributions to humankind ;-)

Some email providers navigate to every URL you receive to check them for phishing and malware. That doesn't play well with one-click unsubscribe links.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#279
post #278

Earlier quoted context omitted.

wow, that's probably one of the most brilliant altruistic ideas I've read since buying other people's medical debt. this is probably why the unsubscribe links require some interactive confirmation so that simply loading the page doesn't actually unsubscribe. if this was doable, i'd put them above Troy Hunt in contributions to humankind ;-)

Some email providers navigate to every URL you receive to check them for phishing and malware. That doesn't play well with one-click unsubscribe links.

sounds like the email providers are in the wrong here. quit reading my mail.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#280
post #116

Earlier quoted context omitted.

They usually put that exact thing into the ToS. The right to change it at any time.

Ahh ok this sounds like a thing that’s OK in the USA but not EU :-/

NOTE: instead of downvoting as a knee-jerk defense of USA, just reflect on whether you'd benefit from some slightly better consumer protection laws.
Post reply on HN