Live data from Hacker News

23andMe changed its terms of service to prevent hacked customers from suing

engadget.com

281–290 of 402 posts

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#281
post #116

Earlier quoted context omitted.

They usually put that exact thing into the ToS. The right to change it at any time.

Ahh ok this sounds like a thing that’s OK in the USA but not EU :-/

Ahh ok this sounds like a thing that’s OK in the USA but not EU :-/

NOTE: instead of downvoting as a knee-jerk defense of USA, just reflect on whether you'd benefit from some slightly better consumer protection laws.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#282
post #12

Automatically opting-in customers to a more restrictive TOS is pretty suspect, especially given the timing. IANAL, but I'm pretty sure that a court would not allow that, given that the TOS was changed AFTER the breach and it's pretty clear that the company is trying to avoid legal issues after-the-fact. I would expect the court would evaluate any breach under the TOS that was in effect at the time of the breach, rath…

They probably know that it doesn't hold water legally. The hope is to victim blame as much as possible so that fewer people sue them in the first place. The next step will be to "remind" people about the TOS that they totally agreed to.

I wish a class action could include those of us who have never used their service, but whose relatives have.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#283

Earlier quoted context omitted.

>> That's like saying there's no point in having 2FA or strong passwords, because the FSB, the FBI and Mossad can get in anyway. > Unlike your password, your DNA is unencrypted and gets spread everywhere. This doesn't address the point. In both cases, someone sufficiently motivated could get what they want from you. So by your argument, there's no point in maintaining privacy for either piece of information (DNA / pa…

> So by your argument, there's no point in maintaining privacy for either piece of information (DNA / passwords). The problem with privacy is that it's fragile. When your info is leaked, you should assume it's out there for good. I also think that while right now when you do the cost/benefit analysis of having your DNA sequenced, you think the cost outweights the benefit. Clearly my personal calculus is different tha…

> I think that well-enforced legislation, legislation that limits the way genetic info can be used and gives the individual more control over their own info, is really the only thing that can help.

Absolutely, in theory. But when have politicians respected legislation's original intent over their self-interest over time, especially when monied parties are desirous of changes for those party's own ends?

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#284
post #276
post #163

Earlier quoted context omitted.

I'm familiar with security (I keep a copy of Applied Cryptography on my shelf for "fun reading") and tech, here's a copy of my whole genome: https://my.pgp-hms.org/profile/hu80855C Note it's a full human genome, far more data than a 23&Me report. You can download the data yourself and try to find risk factors (at the time, the genetic counsellors were surprised to find that I had no credible genetic risk factors). Pl…

1) You can be subject to discrimination based on your ethnicity, race, or health related factors. That's especially a problem when the data leaks at scale as in 23andme's case because that motivates the development of easy-to-search databases sold in hacking forums. The data you presented here would be harder to find, but not the case with mass leaks. 2) It's a risk for anything that's DNA-based. For example, your da…

You forgot an important one: Your ancestors, descendants, siblings, and cousins share much of the same DNA but did not consent to its release. All of the above risks apply to them as well. I'd be most concerned about insurance companies using genetic family history to deny coverage.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#286

its insane that a company can just change a tos after you buy their product why can't i be locked into what i chose to purchase?

Changes to the consumer law in Norway tries to account for digital services that a product you bought had at the time of purchase and that no longer work. Also where a lack of an update has caused something to not work an expected.

The actual ramifications of this are yet to be seen, since the changes come into effect from next year. It will be interesting if this means that apps need to be updated to support new iOS and android versions, or if phones will need to get security updates, or if cloud services must be available, or if a feature can be removed from an app or not.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#287
post #276

Earlier quoted context omitted.

1) You can be subject to discrimination based on your ethnicity, race, or health related factors. That's especially a problem when the data leaks at scale as in 23andme's case because that motivates the development of easy-to-search databases sold in hacking forums. The data you presented here would be harder to find, but not the case with mass leaks. 2) It's a risk for anything that's DNA-based. For example, your da…

You forgot an important one: Your ancestors, descendants, siblings, and cousins share much of the same DNA but did not consent to its release. All of the above risks apply to them as well. I'd be most concerned about insurance companies using genetic family history to deny coverage.

I'm not too worried about it because it's never a 100% overlap. Even my brother and I share only ~50% DNA. It gets way sparser for more distant relatives.

About insurance companies, they're legally forbidden to use such data.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#288

"reports revealing that attackers accessed personal information of nearly 7 million people — half of the company’s user base — in an October hack." Breaking into a system should never provide access to 7 million people. The database should be divided up into multiple "cells" each with its own separate access restrictions. It's the same idea that spy networks use to prevent one compromised spy from bringing down the w…

What if you want to run a query to compare your DNA to everyone else’s to see if you have any relatives that are registered already? Wouldn’t that need access to the entire database and essentially be a point of weakness?

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#289

I interviewed for a security position there a few years ago, but they cut the role before the interview process was over. Kind of feels like they didn't prioritize security - you reap what you sow.

Could have been that they found someone internally.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#290
post #7

To duck out of the new ToS, just write this email to legal@23andme.com-- To Whom It May Concern: My name is [name], and my 23andMe account is under the email [email]. I am writing to declare that I do not agree to the new terms of service at https://www.23andme.com/legal/terms-of-service/ .

You have to specifically opt out of the arbitration clause and class action waiver.
Post reply on HN