Live data from Hacker News

23andMe is out of bankruptcy and it still hasn’t substantially changed its ways

washingtonpost.com

71–80 of 91 posts

Re: 23andMe is out of bankruptcy and it still hasn’t substantially changed its ways

#71
post #24

Earlier quoted context omitted.

The analogy I have used in the past is this fear is like thinking that health insurance companies were more likely to buy the old Marlboro Miles database rather than just making detailing your smoking history a required part of the application process. If these companies have the legal clearance to use DNA data, why would they be satisfied only having secondhand access to that data for a relatively small subset of th…

Yes. Behavioral data is in most cases far more useful to them than DNA. No need to go all the way of using the non-coding SNPs in a genealogical test to infer your coding DNA, to infer your propensity for smoking, when they can just find out if you smoke instead.

The data that 23andme goes far beyond DNA. It goes into explicit family history. Which as it turns out is pretty close to behavioral information

Re: 23andMe is out of bankruptcy and it still hasn’t substantially changed its ways

#72
post #30
post #12

Earlier quoted context omitted.

> you will not get insured (or have high rates) because you have {some genetic condition}.. s/insured/hired Wait until we have DNA detectors wired up to collect the DNA we exhale and rapid sequencers that handle what might be below the limit of detection today. Maybe that's fifty years down the road, but it's coming. Gattaca was a prescient premonition, it was just a hundred years ahead of its time.

Either you or me are deeply wrong about how genotypes relate to phenotype. While some DNA characteristics can be statistically linked with some costly health conditions, the connection to "being a good hire" seems totally imaginary to me, has always been and will always be. For what it's worth, public posts and comments on internet are probably a much better indicator of whether someone is going to be an obedient emp…

Whether or not the connection exists is not the question. The question is whether or not someone will make decisions based off that limited information

Re: 23andMe is out of bankruptcy and it still hasn’t substantially changed its ways

#73

Earlier quoted context omitted.

Health problems and healthcare is not that simple. Almost everyone will experience healthcare issues in their life, so the insurance becomes more of a subsidy mechanism to time shift costs from one population to another (which at some point becomes indistinguishable from taxpayer funded healthcare, just with a different administrator). Also, legislation requires health insurance to pay for all healthcare, so there is…

This isn't really true in the US, I have specific policies that insure me against other types of illness. They pay directly to me in the form of a predetermined cash settlement in the event of a diagnosis.

The Affordable Care Act does not allow for benefit maximums. Necessary healthcare beyond the out of pocket maximum is (theoretically) required to be paid for by the insurer.

You might have supplemental insurance that pays you in case of a specific illness, but that is not what is commonly referred to as health insurance.

Can you provide a link to a business selling the type of policy you are referring to? I am curious what these look like.

Re: 23andMe is out of bankruptcy and it still hasn’t substantially changed its ways

#74
post #65

Earlier quoted context omitted.

Things like financial and medical data should be required to have an audit log that you can see, in real-time and subscribe to updates for, including extraction into "anonymised" formats, along with a description of that process, format and a justification for why it is robust against deanonymisation. If data is handled well, there is nothing to fear here. Fiddly, perhaps. Expensive, probably. But personal data proce…

> Deliberately extracting personal data into un-audited environments without good reason (eg printing a label for shipping), should be punished with GDPR-style global turnover-based penalties and jail for those responsible. There already are, but only for Europeans through the GDPR.

Technically not quite, because even in the EU, you don't have to provide the audit log for someone's data specifically and you as a subject have to make specific requests to delete or retreive your data, it's not make transparent to you as a default position. But yes, you can't just dump it out anywhere you want.

How it should be is that personal data's current and historical disposition is always available to the person in question.

If that's a problem for the company processing the data (other than being fiddly to implement at first), that sounds like the company is up to some shady shit that they want to keep quiet about.

Nothing to hide, nothing to fear should apply here, and companies should be fucking terrified with an existential dread of screwing up their data handling and looking for ways to always avoid handing PII at all costs. The analogy of PII being like radioactive material is a good one. You need excellent processes, excellent reasons to be doing it in the first place, you must show you can do it safely, securely and if you fuck up, you'd better hope your process documentation is top tier or you'll be in the dock. Or, better, you can decide that actually you can make do by handling the nuclear material only in some safer form like encapsulated vitrified blocks at least for most of your processes.

The data processing industry has repeatedly demonstrated they they cannot be trusted and so they should reap the whirlwind.

Re: 23andMe is out of bankruptcy and it still hasn’t substantially changed its ways

#75
post #12
post #11

I do worry about my data with them, but when I think about the worst-case scenario - you will not get insured (or have high rates) because you have {some genetic condition}.. it seems just as likely that they will simply require my DNA to apply for insurance. (or get my DNA from a blood test within their system, etc.). The obvious solution is with legislation for transparency and better health care system.

> you will not get insured (or have high rates) because you have {some genetic condition}.. s/insured/hired Wait until we have DNA detectors wired up to collect the DNA we exhale and rapid sequencers that handle what might be below the limit of detection today. Maybe that's fifty years down the road, but it's coming. Gattaca was a prescient premonition, it was just a hundred years ahead of its time.

Why would that matter at hiring time? If the person develops a health issue during employment they’ll just fire them. Unlike insurance where there they’d have to spend money.

Re: 23andMe is out of bankruptcy and it still hasn’t substantially changed its ways

#76

Earlier quoted context omitted.

>Sure they can. GDPR article 2 (2) says: No they can't. That says only about where the law applies, it doesn't say about prosecution of entities not residing in the EU. EU's legal arm can't extent outside the boarders of the EU, without an outright military invasion, it's toothless to foreign entities. >So the GDPR applies. I never said it doesn't apply. I said how is the EU gonna prosecute an entity that doesn't res…

EU will presumably stop you from doing business in the EU, if you break EU laws and ignore judgments. Companies don't want that. Grindr LLC, a US company with no EU corporate presence as far as I know, was fined 6.5 million for breaching GDPR by an Oslo Court, upheld in appeals. They paid that fine. If they didn't, they'd probably be kicked out of the app stores from Norway (if not from all of EU). Apple and Google d…

You really think they are getting access to their data and looking for some German dude’s data in every server they have? At most 23andMe gets some 250 item questionnaire that some poor soul with a red stapler in a basement has to answer, some middle manager puts a signature on it, sends it saying “yeah we good” and that’s it. Unless there is enough noise for someone to sue, no one is looking at that shit hard enough.

Even if they are, 6.5 million in fines is chump change.

Re: 23andMe is out of bankruptcy and it still hasn’t substantially changed its ways

#77
post #3

Can one even truly delete their DNA from 23andMe? Wouldn't deleting someone's DNA require deleting not only the existing record, but also the record from all historical back-ups too? What is to say 23andMe just doesn't flip a bit in their database and claim one's DNA is (soft) deleted?

The only truly reliable way to do this is to have a per-customer encryption key used to encrypt ALL data for that customer. Then you can simply delete the key to delete the customer data.

Re: 23andMe is out of bankruptcy and it still hasn’t substantially changed its ways

#78
post #3

Can one even truly delete their DNA from 23andMe? Wouldn't deleting someone's DNA require deleting not only the existing record, but also the record from all historical back-ups too? What is to say 23andMe just doesn't flip a bit in their database and claim one's DNA is (soft) deleted?

The only truly reliable way to do this is to have a per-customer encryption key used to encrypt ALL data for that customer. Then you can simply delete the key to delete the customer data.

[deleted]

Re: 23andMe is out of bankruptcy and it still hasn’t substantially changed its ways

#79

Earlier quoted context omitted.

EU will presumably stop you from doing business in the EU, if you break EU laws and ignore judgments. Companies don't want that. Grindr LLC, a US company with no EU corporate presence as far as I know, was fined 6.5 million for breaching GDPR by an Oslo Court, upheld in appeals. They paid that fine. If they didn't, they'd probably be kicked out of the app stores from Norway (if not from all of EU). Apple and Google d…

You really think they are getting access to their data and looking for some German dude’s data in every server they have? At most 23andMe gets some 250 item questionnaire that some poor soul with a red stapler in a basement has to answer, some middle manager puts a signature on it, sends it saying “yeah we good” and that’s it. Unless there is enough noise for someone to sue, no one is looking at that shit hard enough…

Meta has been fined €1.2b for breaching GDPR, though it seems to still be appealing.

The fine is revenue adjusted.

Re: 23andMe is out of bankruptcy and it still hasn’t substantially changed its ways

#80
post #61

Earlier quoted context omitted.

Sure they can. GDPR article 2 (2) says: «This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union;» So the GDPR applies. The EU can…

>Sure they can. GDPR article 2 (2) says: No they can't. That says only about where the law applies, it doesn't say about prosecution of entities not residing in the EU. EU's legal arm can't extent outside the boarders of the EU, without an outright military invasion, it's toothless to foreign entities. >So the GDPR applies. I never said it doesn't apply. I said how is the EU gonna prosecute an entity that doesn't res…

> EU's legal arm can't extent outside the boarders of the EU, without an outright military invasion

All the lawsuits from EU against tech companies outside the EU have been carried out without any military invasions required. You are delusional if you think USA is going to go “Google won’t pay the fines, invade us if you want the money”

Post reply on HN