Live data from Hacker News

23andMe is out of bankruptcy and it still hasn’t substantially changed its ways

washingtonpost.com

81–90 of 91 posts

Re: 23andMe is out of bankruptcy and it still hasn’t substantially changed its ways

#81

i'm curious, what's the worst-case scenario if one were to put their whole DNA data exposed publicly? would a future civilization re-make your image? or are there societal benefits?

someone could synthesize your DNA and leave it a crime scene, to use an example popularized by the consent form of the Harvard Personal Genome Project.

Re: 23andMe is out of bankruptcy and it still hasn’t substantially changed its ways

#82

Earlier quoted context omitted.

>Sure they can. GDPR article 2 (2) says: No they can't. That says only about where the law applies, it doesn't say about prosecution of entities not residing in the EU. EU's legal arm can't extent outside the boarders of the EU, without an outright military invasion, it's toothless to foreign entities. >So the GDPR applies. I never said it doesn't apply. I said how is the EU gonna prosecute an entity that doesn't res…

> EU's legal arm can't extent outside the boarders of the EU, without an outright military invasion All the lawsuits from EU against tech companies outside the EU have been carried out without any military invasions required. You are delusional if you think USA is going to go “Google won’t pay the fines, invade us if you want the money”

>You are delusional if you think USA is going to go “Google won’t pay the fines, invade us if you want the money”

Why don't you read my comment thoroughly before accusing people of being delusional? Google is registered in Europe(HQ in Ireland IIRC ) and does business in Europe as an European company, so there's a physical, legal and tax paying entity the EU can fine and even European management they can send to jail just in case they don't comply, same how they did with VW for the diesel scandal.

If you would have read my comment thoroughly (hard ask, I know), you would have seen I'm specifically asking about how would the EU fine foreign companies that have EU citizens' data but have no HQ or any legal entity in Europe that can be reached by EU law enforcement in case of GDPR violations.

Re: 23andMe is out of bankruptcy and it still hasn’t substantially changed its ways

#83

Earlier quoted context omitted.

EU will presumably stop you from doing business in the EU, if you break EU laws and ignore judgments. Companies don't want that. Grindr LLC, a US company with no EU corporate presence as far as I know, was fined 6.5 million for breaching GDPR by an Oslo Court, upheld in appeals. They paid that fine. If they didn't, they'd probably be kicked out of the app stores from Norway (if not from all of EU). Apple and Google d…

You really think they are getting access to their data and looking for some German dude’s data in every server they have? At most 23andMe gets some 250 item questionnaire that some poor soul with a red stapler in a basement has to answer, some middle manager puts a signature on it, sends it saying “yeah we good” and that’s it. Unless there is enough noise for someone to sue, no one is looking at that shit hard enough…

Filling out some form won't help if someone finds out they're not doing what they said they will do. The data protection agencies will sue if they find that out. And they did find out that Grindr was selling data it wasn't allowed to.

Fines are scaled according to revenue. That's the reason for the monumental fines leveled at Google and Facebook. They don't mess around.

I believe Grindr's fine was just based on their revenue from Norwegian users. Probably plenty hurtful enough to make them implement data protection in the jurisdictions which demand it.

Re: 23andMe is out of bankruptcy and it still hasn’t substantially changed its ways

#84
post #12
post #11

I do worry about my data with them, but when I think about the worst-case scenario - you will not get insured (or have high rates) because you have {some genetic condition}.. it seems just as likely that they will simply require my DNA to apply for insurance. (or get my DNA from a blood test within their system, etc.). The obvious solution is with legislation for transparency and better health care system.

> you will not get insured (or have high rates) because you have {some genetic condition}.. s/insured/hired Wait until we have DNA detectors wired up to collect the DNA we exhale and rapid sequencers that handle what might be below the limit of detection today. Maybe that's fifty years down the road, but it's coming. Gattaca was a prescient premonition, it was just a hundred years ahead of its time.

50 years down the road AI will have taken all the jobs, so I'm not sure we should be worried about getting hired. That ship will have sailed.

Re: 23andMe is out of bankruptcy and it still hasn’t substantially changed its ways

#85
post #65

Earlier quoted context omitted.

> Deliberately extracting personal data into un-audited environments without good reason (eg printing a label for shipping), should be punished with GDPR-style global turnover-based penalties and jail for those responsible. There already are, but only for Europeans through the GDPR.

Technically not quite, because even in the EU, you don't have to provide the audit log for someone's data specifically and you as a subject have to make specific requests to delete or retreive your data, it's not make transparent to you as a default position. But yes, you can't just dump it out anywhere you want. How it should be is that personal data's current and historical disposition is always available to the pe…

It doesn't say audited environments as such, but you are required to use secure environments that you control as a basis. What "secure" means can always be discussed, but in general it depends on what data you process and what you do with it; if it is a large volume/big population/article 9-data auditable environments should be expected - though not publicly auditable. Although that would be nice...

Fully agree on what you are saying, and my popcorn is ready for August when the penalties part of the AI Act comes into force. There is a grace period for two years for certain systems already on the market, but any new model introduced after August this year has to be compliant. AI Act+GDPR will be a great show to watch...

Re: 23andMe is out of bankruptcy and it still hasn’t substantially changed its ways

#86

Earlier quoted context omitted.

EU will presumably stop you from doing business in the EU, if you break EU laws and ignore judgments. Companies don't want that. Grindr LLC, a US company with no EU corporate presence as far as I know, was fined 6.5 million for breaching GDPR by an Oslo Court, upheld in appeals. They paid that fine. If they didn't, they'd probably be kicked out of the app stores from Norway (if not from all of EU). Apple and Google d…

You really think they are getting access to their data and looking for some German dude’s data in every server they have? At most 23andMe gets some 250 item questionnaire that some poor soul with a red stapler in a basement has to answer, some middle manager puts a signature on it, sends it saying “yeah we good” and that’s it. Unless there is enough noise for someone to sue, no one is looking at that shit hard enough…

Fines are based on a number of things; the type of data (PII or Article-9-PII), number of people affected, amount of data, previous violations, and as far as I know also the country issuing the fine. 6.5M might be a small fine by some standards, but if fined and nothing improves the fine is likely to be a lot higher the next time around.

Re: 23andMe is out of bankruptcy and it still hasn’t substantially changed its ways

#87
post #56
post #40

Earlier quoted context omitted.

The samples of DNA of the best employees will be collected, evaluated and compared to applicants. So if your DNA is similar they will let you in. Wait for a clever startup to offer a complete solution for this comparison soon.

I'm not discussing that it would be doable if it worked, and that some startups will be up for it. I'm saying that DNA is not a predictor of being a "good employee", and if you believe otherwise I'd be interrested to know why.

But good employees have DNA to analyze and compare to applicants. I am not saying, there is science behind. I also not saying, that good employees are the real good ones and not good looking ones.

Re: 23andMe is out of bankruptcy and it still hasn’t substantially changed its ways

#88
post #57
post #56

Earlier quoted context omitted.

I'm not discussing that it would be doable if it worked, and that some startups will be up for it. I'm saying that DNA is not a predictor of being a "good employee", and if you believe otherwise I'd be interrested to know why.

> I'm saying that DNA is not a predictor of being a "good employee" Sure it is. Easy case in point: count the chromosomes. The wrong number alters gene dosage, leading to diseases such as down syndrome. Neuroticism amongst many other personality traits is heavily genetically linked, obesity and cardiovascular health are genetically linked, ... Lots of things an employer or insurer would be interested in if our laws d…

Come on, I don't need a dna analysis to tell if one has Down syndrome or is obese. Again, a google search teach me much more about a candidate than his or her dna.

And about dna to be used baselessly to take decision, sure, like graphology, or astrology could be used... but then concealing dna is like concealing your handwriting or exact date of birth. Why not, but we are no longer speaking about privacy protection but about fighting superstition.

Re: 23andMe is out of bankruptcy and it still hasn’t substantially changed its ways

#89
post #25

I started doing a relevant project https://github.com/barisozmen/securegenomics . Because I believe 23andMe event will result in people to be more wary of sharing their genetic data, and we need ways to make people able to contribute in genetic research without exposing their data.

In what you show, people encrypt their genome before uploading data on some server, and then scientists can work on the data. How are scientists able to work on encrypted genomes?

Yes, it's by homomorphic encryption as @vintermann mentioned.

That being said, scientists can implement their own protocols, and use whatever technique they want. For example: https://github.com/securegenomics/protocol-alzheimers-sensit....

It's that our platform makes federated computing + homomorphic encryption analysis easy, but protocols are customizable.

Re: 23andMe is out of bankruptcy and it still hasn’t substantially changed its ways

#90
post #36
post #11

I do worry about my data with them, but when I think about the worst-case scenario - you will not get insured (or have high rates) because you have {some genetic condition}.. it seems just as likely that they will simply require my DNA to apply for insurance. (or get my DNA from a blood test within their system, etc.). The obvious solution is with legislation for transparency and better health care system.

One aspect to this tangle is knowledge asymmetry: One of the traditional justifications for insurers poking around is to guard against an applicant that conceals important factors as a kind of fraud. But what about the reverse? There's something intuitively unjust about the customer not knowing why they're being charged a higher rate, especially if it means the company believes there's a potential danger (enough that…

Currently, due to the Affordable Care Act aka Obamacare, health insurance companies are prohibited from setting rates based on individual risk (except they can charge higher premiums to tobacco users). Before the law, ensures would typically put applicants through a health screening that would determine their rate. People with pre-existing medical conditions could be denied coverage or charged higher rates. Women routinely paid higher premiums than men.
Post reply on HN