Live data from Hacker News

23andMe changed its terms of service to prevent hacked customers from suing

engadget.com

31–40 of 402 posts

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#31

Earlier quoted context omitted.

[flagged]

Most of the time we're leaking our DNA all over the place by existing

The DNA we are leaking is impossible to copy unlike the DNA we are sending to 23andme.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#32

Earlier quoted context omitted.

Why did you send them your DNA? It was pretty obvious from day 1 that sending some random startup on the internet my DNA was a bad move.

No, I don't think that that's obvious. At least in the US, there are already protections for genetic information (including but not limited to GINA [1]). In the long run, I think keeping your genetic information private will be untenable- the potential benefits will outweigh the drawbacks. Plus, anyone sufficiently motivated could get your DNA somehow, you shed your DNA everywhere you go, no getting around that. So w…

> In the long run, I think keeping your genetic information private will be untenable- the potential benefits will outweigh the drawbacks.

Can you give an example?

> Plus, anyone sufficiently motivated could get your DNA somehow, you shed your DNA everywhere you go, no getting around that.

That assumes there's someone out to get you specifically. That's like saying there's no point in having 2FA or strong passwords, because the FSB, the FBI and Mossad can get in anyway. Having my DNA because you vacuumed it up off the subway floor is significantly less useful to anyone without it being explicitly tied to me.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#33
post #21

I would have presumed that security-minded people, which includes those who work in tech, would not so easily give away their genome, and that most of 23andMe's customers are a slice of the general population. But then I read about things like WorldCoin and that people who go to startup parties jump at the chance to give away scans of their retinas and I'm befuddled. Why would anyone willingly do that?

Or the reality is, if someone wants your dna they will follow you around and grab a coffee cup.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#35
post #12

Automatically opting-in customers to a more restrictive TOS is pretty suspect, especially given the timing. IANAL, but I'm pretty sure that a court would not allow that, given that the TOS was changed AFTER the breach and it's pretty clear that the company is trying to avoid legal issues after-the-fact. I would expect the court would evaluate any breach under the TOS that was in effect at the time of the breach, rath…

And just because a TOS says something doesn't mean it will necessarily hold up in court. They aren't law.

Right. Also, the practice of having a sticker on a shrink-wrapped box of software that read "By opening this package you agree to the Terms of Service contained within", where the TOS was inside the box that you needed to open the package to read, was deemed unenforceable back in the 90's. It's the reason that TOS' are now displayed as a pop-up during installation. Not that many more people actually read them before installing the software, but at least they are given the option to.

I suspect that a competent lawyer could fairly easily argue that this "automatic opt-in" is the same thing in a slightly different format.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#36
post #7

To duck out of the new ToS, just write this email to legal@23andme.com-- To Whom It May Concern: My name is [name], and my 23andMe account is under the email [email]. I am writing to declare that I do not agree to the new terms of service at https://www.23andme.com/legal/terms-of-service/ .

> If you do not notify us within 30 days, you will be deemed to have agreed to the new terms.

WTF. This is outrageous. And I had find that email in my spam after I read this comment. Hope this POS company goes down in flames after this.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#37
post #21

I would have presumed that security-minded people, which includes those who work in tech, would not so easily give away their genome, and that most of 23andMe's customers are a slice of the general population. But then I read about things like WorldCoin and that people who go to startup parties jump at the chance to give away scans of their retinas and I'm befuddled. Why would anyone willingly do that?

> But then I read about things like WorldCoin and that people who go to startup parties jump at the chance to give away scans of their retinas

Well, in the case of WorldCoin, I think there's still some pretty significant questions of why they made Africa a prominent launch market (well, there are some reasons), but in some places they repeatedly increased incentives until they were offering people there up to a month's income to give their scans. That might not be a lot of money to a big startup, but is telling that they had to offer that much to get some people to "opt" in.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#38
post #29
post #10

Earlier quoted context omitted.

The email I got from 23andMe linked me to legal@23andme.com.

Deeper in it has the other one. I also set my future status to auto opt-out. “I opt out of the updated terms and will stick to the current in place ones indefinitely, including any future changes. I declare myself immune from having to do anything like this again in the future and set my status to auto-opt-out.”

Is this legally binding? I'm extremely skeptical any time phrases like "immune" and "automatically" start making their way into legalese as it's usually something like those Facebook "don't use my photos" things your aunt reposts every few months.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#39

Thanks for sharing. Will def opt out and roll into the class action suits already filed. Take security seriously people. Especially when dealing with super sensitive data.

Why did you send them your DNA? It was pretty obvious from day 1 that sending some random startup on the internet my DNA was a bad move.

Any other way to know the information they are offering? It is hard to own your own sequencing machine.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#40
post #31

Earlier quoted context omitted.

Most of the time we're leaking our DNA all over the place by existing

The DNA we are leaking is impossible to copy unlike the DNA we are sending to 23andme.

You know, you can send other peoples DNA to sequencing services too…
Post reply on HN