A researcher needed three hours to identify me from my DNA
bloomberg.com
bloomberg.com
However, I do agree that in general several "security questions" that are meant to be hard-to-guess data points are actually easy to find the answer to frequently. Maiden names, and school names/cities/mascots, are often found in online profiles in one way or another.
At the same time, I'm not sure the risk is as large as it seems. These security questions help prevent bulk identity theft and add a friction point to the process, they are certainly not equal alternatives to real 2FA, but they are also less "brute forceable".
Though it isn't as bad as; 'You can't cheat an honest man'. You hear someone saying that, you start counting your fingers before you shake hands and check them again as soon as your done.
I generate random strings for these and store them in my password manager. On several occasions I've called companies for whatever reason and they've asked these questions to verify my identity. When I say "oh it's a random string let me open my password manager to confirm it" they often reply with "oh it's ok, you're right it's gibberish" and consider me verified.
Just don't answer the questions basically.
Also, you don't need to type gibberish. If your mothers maiden name is Jones, you can enter her maiden name as Steenberger and store that in your password manager.
If you know the person's name and roughly when they were born (which you can get from the age) and where, you can get the Mothers Maiden name easily.
I found mine here https://www.freebmd.org.uk/cgi/search.pl in a couple of clicks.
But looking up myself (and my brother) I noticed that the record date is a month or two past the actual month. So for me being born in March seeing myself listed as June and in my Brothers case seeing September listed as December. Well, makes me wonder if they had backlogs back then. But most happy it is that way, I know my actual birth certificate has the correct date (still have the original) and those are accessible in some form or another. Just mindful that not all records are that accurate.
[1] Stephen M. Bellovin. 'Frank Miller: Inventor of the One-Time Pad'. Cryptologia 35(3), pp. 203–222, 2011. DOI: 10.1080/01611194.2011.583711
So it literally only works for this purpose the first time you do it, now it's not private anymore (even if it was to begin with). Now it's on file just waiting to be leaked.
For example, how many of us are suckers who have submitted scans of our passport and drivers license to a website like coinbase.com?
It's only a matter of time until https://haveibeenpwned.com/ lets you type in your DL/passport number and it'll tell you how many scans it found in data dumps.
Someone doing social engineering may answer "It was a bunch of random characters/words, I'm sorry I don't have it in front of me" and have that accepted. If they don't accept it, hang up and try again with another rep until someone does.
Picking a random real place off Wikipedia (different for each website, and store that in 1password) avoids this.
My hope would be their training largely prevents "oops I can't remember" getting through, but I suspect you'd eventually get someone quitting tomorrow who doesn't care, or someone having an off day.
(And to your point, I literally had to provide it earlier this week to Chase’s fraud department.)
Searching your name and city+state in Google shows several websites that collect public records and show relatives. Some include age with names. The only people that showed up as relatives that were plausibly your parents (based on age) were two people: one with your same last name (probably your father), and one with a different name (Klass) (most likely your mother).
Having a pretty rare last name makes it really hard to stay anonymous, especially when you engage in public activities like entering road races, buying a home, and voting. Guess it’s a bit late to start using a pseudonym.
Edit: mylife is insane. I’ve googled myself in the past and this much information didn’t used to be so readily available in search results.
I don’t know how a right to disappear would even work when a bunch of the results are curated straight from public records.
Edit 2: I think if I cared more about this I’d have to engage in a prolonged disinformation campaign to muddy the search.
Actually, no. It only takes 2-3 years to disappear from most casual google searches. I know people always say 'the internet is forever' and for some things it might be, but I was suprised how much of my online traces just faded over time after I started being more careful with my identity.
The worst is doubtless to share an uncommon but not unique name with someone who could plausibly be you who is controversial/a criminal/etc. Pre-Web I went to school with someone who shared a name with a very unpopular figure in the same city. My schoolmate got literal death threats left on his answering machine.
The best systems I have seen are the ones that use your credit history to ask you several questions like "Which one these four streets have you lived on?" or "Which one of these four employers have you never worked for?", but even those are gameable with some research. There has to be some better solution out there.
It could be the same one I use for 2FA to the website. Or, an entirely offline flow would work too where they sent a dead-tree mail with the shared secret in QR code format.
So clearly it can be done. Swedish banks have been doing it for at least 20 years.
At least with simple "mother's maiden name" type questions, you could, if you were concerned by its insecurity, choose to use a secret value. With the automation of the process, that is not an option, while the security value of this pseudo-secret information will be eroded by its inevitable over-use.
I have both recorded in password vault and both are random.
The benefit is it they've reset my password for some reason or it was hijacked. I've been able to recover accounts. Not because I forgot a password but because it was essentially a harder to change 2nd "secret"
That is, indeed, the problem that these questions are supposed to avoid, but they only offer sort-of security to the extent that the information is sort-of confidential. Anything that the automated validation service can find from public sources can also be found by the black hats, and the more common these automated services become, the more worthwhile it will be for the black hats to similarly automate their search for them.
The end result is that real security that is based on something you know has to depend on secrets.
Given how bad the credit companies are at distinguishing me and my father (we share a name), I don't have much faith in this process either. What if you don't have a credit history?
Realistically most businesses don't have a need to pin an identity to a real-world person.
The assumption that you have, that the system "just works" is awful. Because when it turns out the system actually doesn't work, it's a fucking clusterfuck just to get someone to listen to you because they don't believe you are who you say you are, and government issued ID is apparently insufficient.
And the government seems to think I am the same person as my deceased father and grandfather because we share a name, and holy fuck is it frustrating come tax season (I have never in my life had my taxes accepted the first try and have had to physically visit the IRS before) or any time anybody tries to do any sort of background check on me.
Their founder is going to jail but the tech was OK - take a photo of your ID with your phone and look into the camera. Do the faces match?
Cool!
Other systems require you to record a video of you saying a particular sentence which is then checked (presumably) by a human. And others require a video call to a real person.
None of them were true, because when I was first opening my credit karma account was when I first got a credit card; up to that point I had no credit history at all. When it asked me these questions, and I believe it implied one of the questions was true, I assumed my identity was stolen and got a report from transunion and equifax.
Turns out my identity was never stolen and credit karma was just being obtuse.
BankId is a 2FA mechanism that proves that you are who you say you are. Before you can download the mobile app (Mobilt BankId) and assign a password, the bank must issue you a card with a certificate on it (BankID på kort[0,1]).
You use this card to then validate the Mobilt BankId, since it creates a chain-of-custody for identity, as it were.
In other words, someone with your personnummer on-hand can't just download Mobilt BankId and then assign their own password because they're lacking the physical evidence [read: the BankId på kort], which prevents them from falsely representing that they are you.
How Mobilt BankId works with BankId is that it houses a certificate (much the same as BankId på Kort) and leverages the same auth prompting mechanisms for challenge/response to authenticate the user. Essentially, it "replaces" the kort but only in the sense that the kort is required to be physically present in the system. With the Mobilt BankId app, the certificate is always present.
Sorry for the long-winded explanation but it isn't as simple as downloading the app and assigning a password and don't want people to get the wrong idea. :(
Encountering men with hyphenated last names is uncommon enough (for me) that I don't know the rules for that, so if that's the case, I don't know either.
It really is a pretty outdated and sexist system, really.
You also don't lose it or forget it, like you would password or 2FA device.
How accustomed we've become to giving our privacy away.
It's just not that big a deal. You shed your DNA everywhere. Knowing it isn't more useful than information about your life that is already collected and used to manipulate you all the time. It's one of the weaker forms of personal information available.
I can’t take your hair off your head, but I can take it off the ground.
Somewhere, somewhen, there is likely to be another person who has a face, or fingerprints, or snippet of DNA that cannot be distinguished from yours within the accuracy of the tools we have today.
But pretty much any other use of a photo in a public place is fair game if it doesn't misrepresent you in some way.
"My DNA is my personally-identifying data," is a better one.
The question of what rights we have to our personally identifiable information is not yet answered fully, and the debate is an important one (e.g. consider GDPR and the "right to be forgotten").
Data's worth is recognized today by those who are harvesting it from us. The mountains of data which only a few multinational corporations can gather and store in globally-distributed data centers are imperative to machine learning and the artificial intelligences they are making, which will soon direct a great many of our daily conveniences at potentially great profit to them.
So it is important for us to today define what rights we demand to such a valuable resource, which is created solely by, and living within, the only item any of us has true natural possession of: our very bodies.
Do not forget that op argues it isn't that big of a deal.
>Data's worth is recognized today by those who are harvesting it from us.
There is a lot more case-based, abstract, and long-term worth to privacy that is often unrecognized.
"Doing bad things isn't a big deal because of all the other bad things already being done." is not a good justification:
Should an individual feel free to "dox" you with impunity because Google and Facebook have been doing it to you for years anyway?
Unless you have secret illegitimate children or you left DNA behind at a crime scene, using DNA analysis services can only benefit you.
Also since 23andMe is selling data to pharmaceutical companies, they very much benefit from your DNA.
I considered using these under a fake name, but from reading the article, it seems like that wouldn’t be enough.
I do see the appeal that this indformation has for individuals, of course.
If you give a company your dna voluntarily and agree to the terms permitting them sell it though... different story.
https://www.theatlantic.com/magazine/archive/2016/06/a-reaso...
https://www.idtdna.com/pages/products/custom-dna-rna/dna-oli...
Even if they could synthesize DNA from that information, they'd need to mix it with SOMETHING to show that it's not planted. Is the information collected by 23andMe even close to accurate enough to do something like this?
Can anyone recommend a sequencing service that offers some semblance of a reasonably solid privacy guarantee (in exchange, of course, for a suitable fee)?
Your inputs will be very dearly appreciated.
Of course, uploading fake DNA with your real name would have other implications — your relatives that upload their own DNA and look for matches might suspect infidelity on the part of your parents... and relatives of the "fake DNA" might think the same of their father/grandfather/etc.
So if you tried that, the stranger would have to be a very carefully selected family member in any case. Someone from your mother's side, same gender, not likely to submit his/her DNA, AND not likely to be in DNA databases already due to prior arrests. (Also, it goes without saying that they can't be adopted.)
But even taking all these precautions, I'm pretty sure a detective would still work it all out.
Not necessarily. There was a case where a DNA test of a woman's children showed that they did not share any of her DNA. Social Services was threatening to take them away from her. When she had another child, they court ordered an officer to be present during the birth and collect DNA from both of them at that time. Even still the DNA "proved" she was not the mother. It was only after another similar case was discovered that they were able to determine that she was a chimera, basically that she was her own twin, and had two different DNA strands.
IE, DNA is my personal property, hence, I own my family. Come off it.
You cannot claim to be concerned about individual privacy when your recommendation for how to protect your privacy is to intimately examine your family member's actions and then actively attempt to prevent them from doing something that is -- according to your ethics -- their right.
Don't keep anything for the swim back.
> One of the biggest strengths of PCR(e) for DNA typing is the degree to which DNA can be amplified. Starting with a single DNA molecule, millions or billions of DNA molecules can be synthesized after 32 cycles of amplification. This level of sensitivity allows scientists to extract and amplify DNA from minute or degraded samples and obtain useful DNA profiles. In this context, the sensitive nature of PCR works in a lab's favor, but it can cause problems if great care is not taken to avoid contaminating the reaction with exogenous DNA.
https://www.promega.com/~/media/Files/Resources/Profiles%20I...
> Because extremely small samples of DNA can be used as evidence, greater attention to contamination issues is necessary when identifying, collecting, and preserving DNA evidence. DNA evidence can be contaminated when DNA from another source gets mixed with DNA relevant to the case.
Hell, with just a few comments I can identify people/alts on HN (or other social media sites)...
https://twitter.com/AustinGWalters/status/104189476543920128...
Lobbying has corrupted US democracy, freedom, privacy, and legislation to the point that these may never recover. The moment something GDPR-like will be drafted, those snakes (large corporations & lobbies) will do their best (aka bribe $$$$$$$$$$$$) to stop this. (for those who don't like the word bribe, feel free to replace with 'donate' - but imho paying someone elected to change their mind and go against the people's interests, is pure bribery-fraud)
Once a USA-GDPR moves in (which will never happen), people will start to wake up and smell the coffee, and realize that the threat is real. That awakening will lead to another issue.
The 3-leter-agencies (whether in the Light or in the Dark) will also fight this tooth and nail. Now they have a sweet deal. They spy on everyone, people are stupid/naive/careless enough to publicise every-thing they do/eat/say. In a USA-GDPR scenario where civilians will start 'thinking' again, agencies will have to try harder (aka increased budget/spending) to hoard the same amount of information.
It's "California only", but companies have little choice but to implement it for the entire US (much like car manufacturers building all US cars to meet Cali emission standards).
Also: This means there is enormous potential to pollute their signal with tons of false noise. I hope(dangerous word) that this has already happened, or is in progress.
"When you purchase our Services or create a 23andMe account and register your kit, we collect Personal Information, such as your name, date of birth, billing and shipping address, payment information (e.g., credit card) and contact information (e.g. email, phone number and license number)."
https://www.23andme.com/about/privacy/#jump-link-content-the...
They are asking for some unusual stuff like DOB and license number.
>> As DNA databases grow, so too does the potential for abuse. “Misuse of surreptitious DNA is potentially a big problem,” says Debbie Kennett, genealogist and author. “You can imagine celebrities and politicians being stalked to get illicit DNA samples for paternity testing without consent.” <<
Certainly, there must be worse outcomes than some powerful men running the risk of being shown to be someone’s dad?
Happy to be corrected by someone with actual knowledge of course.
In these countries a family is not just the basis for raising children - families can often act as a sort of "corporation" where everyone is cooperating to enhance the wealth and future prospects of the group.
There was a lot of confusion around family relationships during WWII with the occupation of the Japanese and again after WWII with the Chinese Communist Revolution as children were adopted when their parents went missing or were killed in the war.
If people inside a family are found not to be related to one another there's a serious potential for the social fabric to start breaking down.
That's quite a stretch.
look at birth control for an example