Law enforcement investigators seek out private DNA databases
sandiegouniontribune.com
sandiegouniontribune.com
There are massive statistical problems with this approach, without even having to get to the obvious privacy problems.
http://sanfrancisco.cbslocal.com/2015/11/09/dna-data-from-ca...
http://www.latimes.com/local/politics/la-me-pol-dna-privacy-...
http://www.cdph.ca.gov/programs/nbs/Pages/Default.aspx
has the following code for the link:
<a href="http://cdphiprod/pubsforms/forms/CtrldForms/cdph4410.pdf"tar... Request to Have Newborn Blood Specimen Card Destroyed - CDPH 4410 (PDF) <IMG style="BORDER-TOP: 0px solid; BORDER-RIGHT: 0px solid; BORDER-BOTTOM: 0px solid; BORDER-LEFT: 0px solid" border=0 hspace=2 alt="Opens a new browser window." align=absMiddle src="http://cdphiprod/SiteCollectionImages/1newwind.gif"></a>
Note that "cdphiprod" is not a valid host name. Also, your article linked to:
http://newsmom.com/newborn-blood-spot-dna/
It pointed out that the state sells the information to private companies. As the author points out, it is a test you pay for. Lets see state law requires one to get a test, one has pay for it, one have no control over the handling of it and the state makes money off of it. The state need to do the right thing and protect people's privacy and not sell the people out.
I am not in the mood to check the wording of the law; I wonder if one can refuse to have the hospital to do the test and do it on one's own with a private company where one has control. If one can't do this, then I would look at this as nothing more than state collection of DNA pure and simple and in such a case the state should go F' itself.
They even went so far as to look at records on which people had asked for their samples to be destroyed in a certain case.
And what does accountability have to do with this? Whether the government has accress to DNA markers is orthogonal to them being held accountable for their actions
It is discouraging that this data that was ostensibly collected for non commercial purposes can be sold to Ancestry.
I turned down a $100 best buy gift card in exchange for a 10 minute interview. The guy wouldn't let me go because he couldn't understand why anyone would turn down $100 for a 10 minute chat.
When I was forced to participate in a study in university I always lied in my answers (how is forcing me to participate moral?)
Its my data. I don't trust you, ill do my darnest to keep it from you or feed you wrong info.
As I understand it, they refuse to do anonymous testing - they have good reasons, some of which are completely focused on privacy. I'd love to have an at-home kit, so I could check the contents of my DNA against a database of known facts.
They won't give you information about potential diseases, but they'll give you information about your ancestry and ethnic makeup and they'll do it anonymously. They give you the option to register, but you can also lookup your results by the tag on your sample.
I guess it reveals a few bits of information if you know your killer submitted a sample to the project (but an easy way to avoid this threat is to not be a killer).
Most of the threats I can think of start with the third party already having the DNA, so it's existence in the project database doesn't seem important.
For instance, let's say my brother submits his DNA non-anonymously to some database. By looking at the match between his profile and mine it could be established that I'm a close relative. A few more like that and some constraint trickery and you'd have me as the only solution to your equation.
For an interesting perspective on this: consider what could happen if Facebook bought 23andme... (not much chance, fortunately given who founded 23andme but still).
The third party that is searching using DNA gets "Bill's close relative" or "Bill's close relative that also anonymously submitted their DNA to the database".
The specter of the service working internally to de-anonymize submissions is real enough though.
I guess I don't really care about protecting myself from future dystopias, not really in a sense that I have nothing to hide (I find attention quite uncomfortable), more in a sense that I hope I'd stand up and shout loudly, rendering irrelevant all the past hiding-planning.
Lessons from the past can only be applied to the future if you're actually willing to learn them. Unfortunately, it seems as though those lessons weren't serious enough yet. I shudder to think of the kind of lesson that it would take to get people to understand these things in a way that we will actually live by those lessons in the future.
Standing and shouting loudly is not much of a defense against an organized entity that is 'out to get you', even if that seems like a distant and remote possibility, the damage it could do is sufficient to warrant the - small - premium we'd pay in being careful with our data today.
It's a bit like the rest of the security industry: probability of incidence * potential damage is a good way to figure out whether or not something is worth protecting against.
I wrote a bit more about this here:
http://jacquesmattheij.com/if-you-have-nothing-to-hide
Because I got very tired of the 'if you have nothing to hide' mantra, and even if you freely admit to finding attention quite uncomfortable you might be persuaded by the argument that seemingly innocent entries in databases have cost many lives already.
Maybe it's overly optimistic or foolish or something, but it's still a shit world if only the people that (properly!) planned ahead survive.
Edit: Imagine a modern populist horror that subjected everyone to mandatory genetic testing and slaughtered people with certain genes; You can't escape your genes, the problem would be the populist horror, not whether you were on some preexisting list of people that needed slaughterin'.
https://www.youtube.com/watch?v=9ofu3ZkGw2w
The essence is that the writer meets with an elderly lady from the city on the street and she relates how just above everybody died from a particular family, except for one guy who saw it coming, warned everybody else and then left.
If the Nazi's had been able to take possession of a Europe wide DNA database they might have just been able to eradicate the Jewish people forever and that's a very sobering thought to me. Now, I'm not Jewish but I know a few people here that are 'singletons', they have no living relatives going back two generations and that's a pretty strange thing to have it described to you. I don't have much to worry about from the angle of religious persecution or anything to that effect (I believe, but then again, who knows, maybe one day some religious nutcase will decide to open a war on atheism and maybe then I will have a problem but that's not genetic so the link with DNA isn't really there).
Even so, less data in searchable files about you is better imnsho, the upsides are quite limited and the downsides significant, especially if you have no idea who is rooting around in them (one case of being stalked is enough for a lifetime).
English translation of that piece from above:
[deleted]
It's super crummy (google translate) but it gives you a bit of a feeling of the atmosphere in the original. This is not fiction.
I'll do a better translation, this really does no justice to the original text.
edit: a much better translation, still a quickie but it captures the mood much better:
Not that I disagree with the general lesson. It just seems in such a situation, a mapping of DNA<->name is actually less worse than a mapping of name<->location.
It's always the combination of databases that makes them that much more powerful.
Tell me how it goes with 1% of the US population living in prison, another 2% in probation (and 0.2% tagged as sex offenders).
In the future, it may be possible to take a sequenced DNA and simulate what the person looks like, but we've barely crossed the threshold of having enough computing power to sequence a genome, so we're many years from that being possible and, even then, without knowing the donors age, you wouldn't be able to say what the donor looks like today.
IIRC it's possible in many cases to go from anonymous genome (and no other info) to a surname with a distressingly high degree of accuracy. It doesn't really involve trying to predict phenotypes or anything, it's basically just because you are distantly related with at least some people who have their names attached to DNA sequences.
It becomes even easier to identify someone if you have some very limited extra information. Like, say, the postcode their sample was mailed from.
My understanding is that basically the idea of an "anonymous" DNA sequence is going to quickly become meaningless, that unless the person being sampled takes extraordinary effort it will be possible to narrow down who they are. It only takes like 30-40 bits of information to uniquely identify a human.
I think sequencing at home would be difficult. What we would need is for them to sequence your DNA, then send that data to you, then destroy their copy of the data. This would need to be enforced contractually. The problem is that if you lose your copy of the data, it is gone. This has issues with usability.
If if they offered to keep your named detached from the sequence it wouldn't do much. Your DNA probably has more bits of entropy than your first and last name together.
(Yes, privacy is why I never signed up with 23andme. I expected news like this.)
Honestly, if you're interested in having your genome sequenced/analyzed, I would suggest contacting a local genetic counselor and asking if they can find a sequencing core (or someone that does beadchips) that would agree to delete your data after analysis. They would also be able to discuss your data and the impact it has on your health with you, and provide referrals if more testing or diagnosis is needed.
Doesn't help them much to know that you got DNA sequencing done if they don't know who you are. Generally the idea is they already have an anonymous DNA sample and they want to find a person with a potentially matching sample. Having two anonymous samples doesn't help them.
Someone intent on finding a suspect can try to find a convenient suspect. Perform secondary sort on those who cannot afford a defense and/or persons of color and you've got someone who is suddenly in a world of undeserved trouble.
There's Promethease (https://www.promethease.com), if you want a more open alternative. They're quite good.
Also I'm impressed at the amount of data, I expected a few VCF files, not a ~60GB BAM.
I did illumination wgs and just visited random doc for the blood draw.
Much scarier that you can't get a lab test without leaving 3 data footprints (insurer, lab, doctor's office).
No doubt they can get my sequence anyway, maybe they already have it; but at least I can say that they got it illegitimately.
https://www.genomeweb.com/applied-markets/ancestrycom-shutte...
A) They might do something statistically invalid like charging whoever matches, even if somebody is bound to match just by chance. That didn't happen here. Usry was only a suspect and interrogated then let go. If he did get wrongly convicted, that means there's always at high risk of that for any investigation even without DNA. If we don't trust our processes for protecting against wrongful convictions, then we should try to fix those because they'll already be being abused. If we don't want police to interrogate any suspects who aren't already known to be guilty, then we might find they become a lot less effective at solving crimes.
"... was interrogated for six hours and finally gave blood for a DNA sample. For the next month, he remained under suspicion until his DNA was determined not to match the samples taken from the crime scene."
That looks like a perfectly normal and acceptable way of investigating a crime. It looks like the system working safely.
B) Police accessing personal data is wrong. How about phone tapping with a warrant? How about searching a house with a warrant? Private surveillance footage? Where do you draw the line and not allow them to investigate crimes?
C) People confuse it with secret anti-terrorist or antidisestablishmentarian (I found a use for that word!) NSA investigations which don't follow the well accepted warrant process.
D) Other.
- 23AndMe/Ancestry shouldn't have a database of DNA -> identity mappings.
- Law enforcement shouldn't have the ability to compel surrender of data for which someone can have a reasonable expectation of privacy (medical records, private communications, journals etc.). Privacy trumps investigation for me.
- Law enforcement shouldn't have any kind of "search" access to any private DNA database. I could accept them getting information for an exact match but including relatives and partial matches is too far.
Of course this is not the same as giving them free access to whatever they want. Then I could understand people's worries. Individual policemen could use it to harass people they don't like, or other abuses.
I can live with the police gaining access to my house but my computer and phone conversations are just as off limits to them as I want my DNA to be. Every device I own that can store data is fully encrypted so the police have no access to that regardless of their wishes. Same goes for most of my phone conversations.
I draw the limits at two things: my body (DNA) and my mind (communications, data).