Live data from Hacker News

UK Biobank leak: Health details of 500k people offered for sale on Alibaba

bmj.com

71–80 of 94 posts

Re: UK Biobank leak: Health details of 500k people offered for sale on Alibaba

#71
post #42
post #32

Earlier quoted context omitted.

I guess you can't imagine a free, open democratic state with rule of law either. Because when broad, independent, quality journalism with a wide audience is gone, all you'll have to worry about is that poor cat in a tree in Ottawa.

This free, open democratic state with rule of law funds broad, independent, quality journalism from the public purse: https://www.bbc.com/news/articles/cpvxgl3n138o

BBC is not independent high quality journalism, as we can see from how they cover Israel and Gaza and the corresponding UK protests.

Re: UK Biobank leak: Health details of 500k people offered for sale on Alibaba

#72
post #21

Earlier quoted context omitted.

Yeah, as long as all 500,000 people in the data set agreed for it to be public then thats fine. But how do we verify that?

They're on the list, their information is out there. Isn't that what 'opt in' means?

That's a quite.... astonishing* take.

If I leak your medical information you confidentially shared it with your doctor that means you are okay with it because you opted in for that?

Or does the scope / details do not matter for others, but only matter for your data.

*I have much better word but I guess I should say it.

Re: UK Biobank leak: Health details of 500k people offered for sale on Alibaba

#73
One thing that struck me was, when you look through the board and the committees, it's full of scientists, finance people, doctors, academics. There's maybe a couple of technologists - ML, IT delivery.

If they've got anyone with a background in cyber security I can't see it.

https://www.ukbiobank.ac.uk/about-us/people-and-governance/

And then the CEO comes out with:

> We have never seen any evidence of any UK Biobank participant being re-identified by others.

This data contains sex, at least month and year of birth. I can't see any sensible security-oriented technical person coming out with a line like that.

Re: UK Biobank leak: Health details of 500k people offered for sale on Alibaba

#74

Earlier quoted context omitted.

> they’re not intentionally leaking health details To many, they are. They're leaking information that has been trusted to the NHS to their own databases. The fact that it's being done under government contract and (arguably) within the law shouldn't immediately make it any less bad.

> The fact that it's being done under government contract and (arguably) within the law shouldn't immediately make it any less bad. Of course it should, to say otherwise is absurd what, the NHS shouldn't have _any_ subcontracting? All data must only be held by sacred NHS monks in a vault somewhere? As long as palentir are holding the data on UK servers, to modern data security standards, and they have a contract to d…

no, they should not, since we already know that the contract won't stop them from using that data for other purposes and other governments. A government should act in the interest of its own citizens, first and foremost, and not pretending to believe a pinky swear by a notoriously bad actor.

Re: UK Biobank leak: Health details of 500k people offered for sale on Alibaba

#75
post #74

Earlier quoted context omitted.

> The fact that it's being done under government contract and (arguably) within the law shouldn't immediately make it any less bad. Of course it should, to say otherwise is absurd what, the NHS shouldn't have _any_ subcontracting? All data must only be held by sacred NHS monks in a vault somewhere? As long as palentir are holding the data on UK servers, to modern data security standards, and they have a contract to d…

no, they should not, since we already know that the contract won't stop them from using that data for other purposes and other governments. A government should act in the interest of its own citizens, first and foremost, and not pretending to believe a pinky swear by a notoriously bad actor.

Why do you trust the UK government won’t do the same?

Re: UK Biobank leak: Health details of 500k people offered for sale on Alibaba

#76

There isn't much difference between giving this data to 20,000 researchers all over the world and simply publishing the data on the web. I personally would like data like this to simply be published, together with a law that says using the data to make personalized decisions affecting those individuals is punishable with life in prison. Basically, this data is 'opensource', but not for use to decide insurance premium…

> There isn't much difference between giving this data to 20,000 researchers all over the world and simply publishing the data on the web. As a researcher who regularly deals with such data there is a MASSIVE difference. Yes, I have access to the data but I am restricted on how it can be stored (no cloud), what I can and can't do with it, and for some of it I'm even mandated to destroy it once the research project is…

I am not arguing either way, but I think you missed the point.

When you give O(20000) people you have a 1-0.9999^20000 (high) probability that that will leak anyway (either 1/20000 people not following the rules, or just the accident/attack surface area).

Re: UK Biobank leak: Health details of 500k people offered for sale on Alibaba

#77
post #68

Earlier quoted context omitted.

Palantir may not be random but it's certainly a malicious actor

"certainly" is doing a lot of work here. I'm not "certain". In fact the people I have spoken to who have worked on Palantir platform were deeply suspicious of their users treating data with respect, and so built security and immutable auditability as foundational tech.

Killing hundreds of children in Iran is certain.

Re: UK Biobank leak: Health details of 500k people offered for sale on Alibaba

#78
post #69

Earlier quoted context omitted.

No, Palantir is not a "database vendor", it's an intelligence company closely working with IOF in their ongoing genocidal efforts and with DHS with mass deportations. I'd rather see Oracle than a ghoul openly supporting targeting civilians.

Doesn't Oracle (or at least Larry Ellison) openly support extermination of civilians too?

Not ordinarily, at least not anymore. They cancelled Project Beanstalk in the late 2010s, now relying on the legal system to extract perceived debts.

Re: UK Biobank leak: Health details of 500k people offered for sale on Alibaba

#79

Earlier quoted context omitted.

> they’re not intentionally leaking health details To many, they are. They're leaking information that has been trusted to the NHS to their own databases. The fact that it's being done under government contract and (arguably) within the law shouldn't immediately make it any less bad.

> The fact that it's being done under government contract and (arguably) within the law shouldn't immediately make it any less bad. Of course it should, to say otherwise is absurd what, the NHS shouldn't have _any_ subcontracting? All data must only be held by sacred NHS monks in a vault somewhere? As long as palentir are holding the data on UK servers, to modern data security standards, and they have a contract to d…

Why subcontract with public money to a private for-profit enterprise whose main goal is not the public good?

Re: UK Biobank leak: Health details of 500k people offered for sale on Alibaba

#80
The general public tried over and over and over to reject the collection of such data in the first place. At every opportunity they rejected it. But the people who wanted the data just took it anyway, and when the predictable and predicted bad thing happens, nobody will be punished for it.
Post reply on HN