Live data from Hacker News

23andMe changed its terms of service to prevent hacked customers from suing

engadget.com

61–70 of 402 posts

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#61
post #10

Earlier quoted context omitted.

The email I got from 23andMe linked me to legal@23andme.com.

Yeah, but the actual terms say arbitrationoptout@23andme.com. I wouldn't put it past them to say "ah but you didn't email the right address".

I emailed this one and cc’d the legal@ address just to be sure.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#62
post #31

Earlier quoted context omitted.

Most of the time we're leaking our DNA all over the place by existing

The DNA we are leaking is impossible to copy unlike the DNA we are sending to 23andme.

Nanpore sequencing can be done with a device that can fit into your pocket, these devices can be found for less than $1000.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#63

Earlier quoted context omitted.

Why did you send them your DNA? It was pretty obvious from day 1 that sending some random startup on the internet my DNA was a bad move.

No, I don't think that that's obvious. At least in the US, there are already protections for genetic information (including but not limited to GINA [1]). In the long run, I think keeping your genetic information private will be untenable- the potential benefits will outweigh the drawbacks. Plus, anyone sufficiently motivated could get your DNA somehow, you shed your DNA everywhere you go, no getting around that. So w…

What benefit will there be? And why do you assume that it won't be accompanied by negatives? The problem with all tech is that people direct its use, and the sole agent of evil in this world is people.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#64
post #12

Automatically opting-in customers to a more restrictive TOS is pretty suspect, especially given the timing. IANAL, but I'm pretty sure that a court would not allow that, given that the TOS was changed AFTER the breach and it's pretty clear that the company is trying to avoid legal issues after-the-fact. I would expect the court would evaluate any breach under the TOS that was in effect at the time of the breach, rath…

Cornell's law school has a pretty good guide to these "adhesion contracts" such as web TOS.[0] This alteration strikes me (IANAL) as running the risk of being unconscionable. If the contract change is unconscionable, then the new terms mandating binding arbitration are void.

Again, IANAL. Just my opinion as a citizen, not legal advice. Seek competent legal advice before taking legal action.

[0] https://www.law.cornell.edu/wex/adhesion_contract_(contract_...

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#65
post #21

I would have presumed that security-minded people, which includes those who work in tech, would not so easily give away their genome, and that most of 23andMe's customers are a slice of the general population. But then I read about things like WorldCoin and that people who go to startup parties jump at the chance to give away scans of their retinas and I'm befuddled. Why would anyone willingly do that?

The same people believed crypto-currency, infinite growth, social media and many other things. At least 23andMe provided actual value, to some at least.

What I find strange is that 23andMe did not automatically delete data after 30 days, or at the very least took it offline, only to be available on request. Notify people that their results are available and inform them that the data will be available for 30 days after the first download. This is potentially really sensitive data and based on 23andMe's response, they seem to be aware of that fact. So why would they keep the data around? That seem fairly irresponsible and potentially dangerous to the company.

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#66

Thanks for sharing. Will def opt out and roll into the class action suits already filed. Take security seriously people. Especially when dealing with super sensitive data.

[flagged]

I continue to be surprised at the sheer number of people on HN who are more enraged at the victims for their "stupidity" than at the perpetrators (23andMe for ToS shenanigans and/or the hackers for the hack).

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#67
post #7

To duck out of the new ToS, just write this email to legal@23andme.com-- To Whom It May Concern: My name is [name], and my 23andMe account is under the email [email]. I am writing to declare that I do not agree to the new terms of service at https://www.23andme.com/legal/terms-of-service/ .

> If you do not notify us within 30 days, you will be deemed to have agreed to the new terms. WTF. This is outrageous. And I had find that email in my spam after I read this comment. Hope this POS company goes down in flames after this.

Lol that surely can't be enforceable. Imagine "you agree to give us your kidney if you don't opt out within 30 days" sitting in your spam folder. How is this different?

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#69
post #33
post #21

I would have presumed that security-minded people, which includes those who work in tech, would not so easily give away their genome, and that most of 23andMe's customers are a slice of the general population. But then I read about things like WorldCoin and that people who go to startup parties jump at the chance to give away scans of their retinas and I'm befuddled. Why would anyone willingly do that?

Or the reality is, if someone wants your dna they will follow you around and grab a coffee cup.

Yes, yours specifically, but what if I want like 200.000 people so I can find one that has a DNA profile similar to mine, who could serve as a escape-goat or victim?

Maybe I want to steal a kidney, or a child that could reasonably pass as my own?

Re: 23andMe changed its terms of service to prevent hacked customers from suing

#70

Earlier quoted context omitted.

They probably know that it doesn't hold water legally. The hope is to victim blame as much as possible so that fewer people sue them in the first place. The next step will be to "remind" people about the TOS that they totally agreed to.

Exactly. Same reason construction vehicles have "Stay back 200 feet: not responsible for broken windshields" written on the back.

Yep. A small tangent for anyone who has seen these: they’re very clearly not specifically enforceable. I got a window banged up by things falling off a truck with this signage, and the first thing they said when I called their “How Am I Driving” number the first thing they said was that they were not responsible citing this sign. Fortunately that sign was non binding. :)
Post reply on HN