Live data from Hacker News

23andMe told victims of data breach that suing is futile

arstechnica.com

31–34 of 34 posts

Re: 23andMe told victims of data breach that suing is futile

#31

Earlier quoted context omitted.

Exactly. The number of people making light of this in this thread is unsettling, to put it mildly. If that's the 'tech savvy' crowd then you have to really worry about everybody else. The parallels with the Dutch citizen registry story from WWII are just too much to ignore.

Jacques, I respect you, but I'm already apparently living in a world where my genetic markers make me feel like a rabbit-on-the-run, or at least they force me to pre-emptively apologize for other people with similar genes when I want to travel in most countries. I'm not going to be overly concerned about the constituents of this thread; their views are incoherent, but if they had much power to influence anything, the…

> My father, stupidly, put his genes on this website without asking his children

Oh shit. That really sucks. My mother was about to do it but I talked her out of it.

Re: 23andMe told victims of data breach that suing is futile

#32
post #24

Earlier quoted context omitted.

Weren't users willingly sharing that data with eachother? Encrypting it wouldn't make sense in that use case.

I don't actually know. But if a user wanted to share personal data with another user, I'd make a one-time key. I'm relatively certain that they took no precautions against someone with access to their database. In some scenarios for tiny companies that might be okay, if you don't store sensitive data; but not when it might get whole groups of people slaughtered based on their genetic profile.

Might be a hard sell, though. People on Facebook share personal data with their friends in their profiles all the time.

Re: 23andMe told victims of data breach that suing is futile

#33
post #32

Earlier quoted context omitted.

I don't actually know. But if a user wanted to share personal data with another user, I'd make a one-time key. I'm relatively certain that they took no precautions against someone with access to their database. In some scenarios for tiny companies that might be okay, if you don't store sensitive data; but not when it might get whole groups of people slaughtered based on their genetic profile.

Might be a hard sell, though. People on Facebook share personal data with their friends in their profiles all the time.

Ugh. I'm so divorced from social media, I didn't even consider the marketing use case for "share your genetic data with your friends"... I wonder if this hack was just someone scraping an API for that (?!!)

It's gross. On a side note, when I asked my father (an educated man in his 80s with a law degree) why he put our genetic information online without asking us, his response was that he didn't put it online, he mailed it, and it was just his own. I only say this to illustrate that the entire setup here resembled a con game to collect genetic data from unwitting people - which if they represented only 25% of the population would be enough to let you deduce the rest. The abhorrent fact that the was handled so flippantly is just icing on the cake.

Re: 23andMe told victims of data breach that suing is futile

#34
post #32

Earlier quoted context omitted.

Might be a hard sell, though. People on Facebook share personal data with their friends in their profiles all the time.

Ugh. I'm so divorced from social media, I didn't even consider the marketing use case for "share your genetic data with your friends"... I wonder if this hack was just someone scraping an API for that (?!!) It's gross. On a side note, when I asked my father (an educated man in his 80s with a law degree) why he put our genetic information online without asking us, his response was that he didn't put it online, he mail…

In this case, to be fair, it's not "share your genetic data with your friends", exactly.
Post reply on HN