DNA database that found Golden State Killer is potential national security leak
technologyreview.com
technologyreview.com
I think there is a legal issue here around wether uploading your medical data to a 3rd party service allows that service to take ownership of your medical data and allows them to do what they please with it.
DNA absolutely falls under PII (personally identifiable information). I can't understand how a company to collect and use this information without (it appears) any rules or regulations.
Not only is it a security risk and a privacy violation but it has implications for every aspect of your life and the lives of your children and immediate relatives. I can't understand how this can be run out of someone's house with a part time volunteer staff with no security.
Mind Blown.
But that's the promise of software and the internet. The ability to compete globally with minimal effort.
Whether or not you should be requiring the consent of all people with similar DNA is the real question -- but given Americans' obsession with individual rights I don't see it changing. In their eyes, why shouldn't they be permitted to upload and share their own DNA?
So this isn’t about sharing a selfie, this is about sharing a group photo, where other people are partly out of frame, but you can still make out who they are. And if we stitch together enough photos, we can make out a lot of people, people who never even took a photo.
Although, some would be sharp to point out that in the case of a selfie most of your facial features are also not your own. So it’s mostly a question of where we draw the line as to what is personal and what is shared. But in the case of a murder, if we had an actual selfie of the killer at the scene, we would be able to solve the case fairly quickly using standard investigative methods.
Simply if they aren't a "medical" institute and you give them your health data it's theirs to do what they want and HIPAA plays no role.
HIPPA only matters if the organization deals in medical insurance. Most people are surprised to learn this fact.
> Most Health Care Providers—those that conduct certain business electronically, such as electronically billing your health insurance—including most doctors, clinics, hospitals, psychologists, chiropractors, nursing homes, pharmacies, and dentists.[0]
My gym nor personal trainer are covered by HIPPA as just a simple example of health-adjacent businesses for which HIPPA provides no recourse.
> Covered entities are defined in the HIPAA rules as (1) health plans, (2) health care clearinghouses, and (3) health care providers who electronically transmit any health information in connection with transactions for which HHS has adopted standards. Generally, these transactions concern billing and payment for services or insurance coverage.[1]
[0]: https://www.hhs.gov/hipaa/for-individuals/guidance-materials... [1]: https://privacyruleandresearch.nih.gov/pr_06.asp
https://personcenteredtech.com/2013/05/16/am-i-a-hipaa-cover...
Like I said, most people are very surprised to learn this fact.
But that's not true. Third parties, companies which do not in any way "bill insurance" or may not even provide healthcare services directly may be considered a covered entity.
>Entities that provide data transmission of PHI on behalf of a covered entity (or its business associate) and that require access on a routine basis to that PHI (such as regional Health Information Organizations (HIOs)) are considered to be business associates under HIPAA
Regarding the BAA exception, if you ever signed a BAA it becomes clear that your interactions with the other party to the BAA are HIPAA covered, even if your normal course of business is not. If a covered entity sends you PHI and they didn't have a BAA in place prior, that would constitute a breach.
[0]: https://news.ycombinator.com/item?id=21465420 [1]: https://customercare.23andme.com/hc/en-us/articles/115013843... [2]: https://customercare.23andme.com/hc/en-us/articles/360026466... [3]: https://smiledirectclub.com/privacy/
Police made a fake profile online with the killer's DNA. At first they got a match for a relative. It turned-out it too was a fake profile created by another LE agency with the GSK's DNA.
This is not illegal.
At worst, their fake account gets closed by the site and they have to go through proper channels if they want to proceed further.
HIPAA only applies to "covered entities" - basically if you don't accept insurance, you don't have to be HIPAA compliant.
As a general rule: if it's not an insurance company or medical provider (who accepts insurance) HIPAA does not apply. Hint: the "I" in HIPAA stands for insurance.
Just because you emailed your great aunt to tell her you have the flu doesn't mean HIPAA suddenly applies to Gmail.
Given that the intelligence agencies regularly and aggressively hack every telecom and networking company out there, it's pretty likely that they have already hacked the commercial DNA databases, no? Why wouldn't they?
I'd like to think there is someone out there trying to protect my data, but it's much more likely they are just aggregating everything into a single genome DB that will inevitably get hacked or leaked.
The Stasi had a whole range of methods and means to try to track down people who said or did anything critical of the East German communist regime. Collecting scent samples was used to try to identify those, for example, who had distributed flyers or who wrote critical graffiti.
When they found a piece of graffiti or a flyer then they took a dust cloth, which was usually yellow, and left it for a while lying next to the flyers covered by a protective piece of aluminum foil and then they had their sample. The cloth was then sealed in a pickling jar and stored. If the Stasi later came across a suspect in the process of the investigation, they tried to get a sample from this person as well -- of course, secretly. A trained dog was given the two smells, and if they matched, the Stasi had a concrete name.
https://www.dw.com/en/the-stasi-had-a-giant-smell-register-o...
Apparently back in 2007, German authorities were using this same method to track activists trying to disrupt the G8 Summit:
In a reminder of methods used by the East German Stasi secret police, German authorities are collecting human scents to trace activists they believe may try to violently disrupt the G8 summit in June. It's proving highly controversial, and there's no scientific evidence that the method is infallible.
https://www.spiegel.de/international/germany/stasi-methods-u...
Have a look at this scene from the fantastic film "The Lives of Others": https://www.youtube.com/watch?v=nkRxvEjprBM
>A DNA sample from one of the men killed in the U.S. drone attack was successfully matched with a close relative of Mansour, the interior ministry statement said.
https://www.foxnews.com/world/pakistan-dna-test-confirms-tal...
I like the claims with al-Baghdadi's n-th death being DNA confirmed. US obtained a supposed blood sample of al-Baghdadi from his right hand man in return for a promise of $25 million and US residency for himself and his entire family. Then, someone in a tunnel, unseen by anyone other than a dog, was blown up by an explosive belt, leaving no remains but small chunks that could be identified. These were then DNA confirmed to be identical to whoever the blood sample was taken from.
> The informant also obtained Baghdadi’s underwear and blood sample that was used for the DNA test to confirm his identity before the raid took place.
https://www.nbcnews.com/news/world/kurdish-source-provided-k...
> U.S. intelligence tested those samples and got positive DNA matches for al-Baghdadi, kicking the hunt into high gear. The informant stole the underwear about three months ago and the blood sample was taken roughly one month ago, a Kurdish official said.
Curiously the articles suggest they used the blood sample in advance of the raid to confirm it was al-Baghdadi, with no suggestion of what they were comparing it to.
OK, thanks, I was unaware of that. You've changed my mind on the issue that we don't really know who the guy in the tunnel was. So we really did get him.
Captured Feb. 4, 2004 as a civilian and released that Dec. 8 as he was seen as no threat.
https://www.politifact.com/punditfact/statements/2014/jun/19...
https://www.businessinsider.com/abu-bakr-al-baghdadi-declass...
> "Ibrahim Awad Ibrahim Al Badry, also known as ‘Abu Bakr al-Baghdadi’ was held as a ‘civilian internee’ by U.S. Forces-Iraq from early February 2004 until early December 2004, when he was released," the Pentagon said in a statement. "He was held at Camp Bucca. A Combined Review and Release Board recommended ‘unconditional release’ of this detainee and he was released from U.S. custody shortly thereafter. We have no record of him being held at any other time."
This is also interesting. He didn't start at Bucca:
https://theintercept.com/2016/08/25/u-s-military-now-says-is...
That's also a way to not mention the fact that he also served time in the infamous Abu Ghraib prison around the same time the reports on the on-going torture there were finalized.
As such there's a very good chance he not only witnessed but also experienced that [0] kind of torture, just like neither Abu Ghraib, nor Bucca were exceptions during that time [1].
In that context, it wasn't just a random coincidence how ISIS paraded their prisoners around in "horrible orange suits", as Trump put it, completely missing the reference [2], like many US Americans.
[0] http://100photos.time.com/photos/sergeant-ivan-frederick-hoo... (NSFW)
[1] https://en.wikipedia.org/wiki/Iraq_prison_abuse_scandals
[2] https://en.wikipedia.org/wiki/Guantanamo_Bay_detainee_unifor...
I provided a link to an article documenting the evidence he was there and detailing that he was there when they were extensively brutally torturing the prisoners. Abu Ghraib is in the link title.
You could create a culture of - after every injection - sterilising the needles in the presence of the injectee. This would be moderately burdensome but wouldn't avoid the need for blood samples for medical diagnostics so wouldn't really protect against malicious actors taking the role of medical professionals. That sort of behaviour simply shouldn't be acceptable to anyone, not even spies.
As pointed out in other threads, the DNA of your relatives is almost certainly in multiple databases already and that will probably be enough to identify you (or at least narrow things down to a few people). We need laws and cultural standards (in all the cultures) for how that information is controlled and used but I have no idea how we get there.
Second paragraph: if I don't trust the magician/doctor not to make the needle reappear after it goes in the waste basket, I don't see why I would trust them to not substitute some other liquid for the sterilizing fluid. Even an on-site incenerator is hard to trust, if we're assuming CIA involvement. These people actually hired a magician (John Mulholland) to write a document explaining magician stagecraft to CIA officers as part of the MK-ULTRA program -- they tried to destroy it when they realised congress was going to request those documents, but a copy survived and got republished decades later. I wouldn't trust my own eyes to notice when a well trained agent swapped needles in front of me, and I can't imagine any on-site procedure I would trust as much as taking a needle home with me. As for blood tests, I don't see why I should have to opt into these to recieve vaccines. Medicine can be modular.
Third paragraph: I get that the cat is out of the bag for most people in my country -- I have second-degree relatives who are already in the database. This isn't (yet?) the case for many people living in the third world, which is where most of the backlash to this practice actually occured. I also think that insisting on practices that make future generations more difficult to track are reasonable, even if it will take some time for the genetics to get swashed around enough for these efforts to matter.
https://www.theguardian.com/world/2011/jul/11/cia-fake-vacci...
I think we'll have to agree to disagree over the possibility or desirability of running low-trust vaccination campaigns. FWIW I upvoted your first comment, even though I disagree with part of it.
Edit: missing word - think
I can happily agree to disagree about such things, but I will point out that you still have to live in a world with crazy idealists like myself who will become potential disease vectors if not provided a low-trust mechanism for vaccinating themselves. That isn't intended as a threat, just food for thought when considering cost/risk analysis from your own worldview.
[0] https://www.wired.com/2010/09/afghan-biometric-dragnet-could...
[1] http://archive.boston.com/news/nation/washington/articles/20...
The gig is up.
It's a law felons give their DNA in some jurisdictions. Felons have families. Felons have great grand mothers. Felons have 2nd cousins. There are 6.1 million felons. I'd image the US is pretty much mapped out by now.
https://www.legalmatch.com/law-library/article/mandatory-dna...
Some police agencies (NYC, for example) collect DNA samples on arrest. And if you're found not guilty, the arrest was wrong, or whatever, they still keep the DNA forever. [1]
But it's not like they conduct knock-and-spit dragnets. Oh, wait... [2]
Even worse is that social service agencies do it. Don't be born in California, because the fact that you suddenly exist means the state gets your DNA. [3]
https://www.nytimes.com/2019/08/16/nyregion/newyorktoday/nyp...
https://www.newsweek.com/police-dna-database-nypd-swab-testi...
https://sanfrancisco.cbslocal.com/2018/05/08/california-biob...
As sibling asserts, no you may not refuse. However:
> State law requires that parents are informed of their right to request the child’s sample be destroyed, but the state does not confirm parents actually get that information before storing or selling their child’s DNA. [0]
[0] https://sanfrancisco.cbslocal.com/2018/05/08/california-biob...
> The gig is up.
Absolutely. Also the Pentagon has another excellent source: It stores DNA fingerprinting for US armed forces personnel (so as to identify the remains of MIA/ KIA soldiers). If you could get your hands on that it would probably help fill in the family trees of people involved in intelligence work - I think it is fairly common for extended families to have lots of people working in defence and intelligence.
Presumably the Chinese can combine the family trees from these DNA databases with information from scraping Facebook/ LinkedIn etc and data from the Office of Personnel Management breach. IMO they should be able to connect DNA samples to people in the US very effectively, the DNA will map to a person or a few people and the Chinese will know the work - including intelligence work for the US government - that those people do. So, for example, if they pick a suspicious USB key or document they can take the skin cells of those who handled the object and identify them.
https://news.ycombinator.com/item?id=3722982
Unfortunately felons don't get a say in the matter but the rest of us do.
This is a common misconception, as long as we are talking US companies and US agencies, they don't need to do much of that, thanks to the third-party doctrine [0] they do not even need a legal warrant.
Now add in the fact how popular ancestry tests have become, and how even that data is openly monetized, it's not that far of a reach to assume US intelligence agencies have been building their own aggregated DB.
If you don't think that squads of spies for Russia, China, the US, Israel, India AREN'T working at these companies you are woefully naive.
It doesn't cover this particular attack, but it does discuss the way databases were used to identify the victims of a murder that took place decades ago. In that case, there was a lot of work done tracking down branches of family trees, and asking living people to submit their DNA to these databases to help fill in the gaps that prevented positive identification of the victims.
If so, it potentially opens a world of other crappy possibilities too. :(
This will lead very quickly to no more anonymous adoptions. I'm in favour of open adoption as studies have shown it's healthier for the child but that's my own personal bias outside of the technology.
Edit : DNA testing...
One of the downfalls of being a technical individual in this case. Your autocorrect or muscle memory got the best of you!
Data analysis costs vary widely, depending on what you want.
https://www.bloomberg.com/news/articles/2019-11-06/breach-at...
Whoops!
Any subsequent marital issues or extracurricular activities of the individuals concerned cannot erase the fact that the venture was literally bootstrapped by Sergey Brin and Google.
https://techcrunch.com/2009/06/18/all-in-the-family-sergey-b...
https://www.vanityfair.com/style/2014/04/sergey-brin-amanda-...
> 23andMe chooses to use all practical legal and administrative resources to resist requests from law enforcement, and we do not share customer data with any public databases, or with entities that may increase the risk of law enforcement access.
See: https://www.23andme.com/law-enforcement-guide/
The GSK (EDIT: their 4th cousin) actually used GEDmatch which is a service that openly cooperates with law enforcement.
GSK did not actually use GEDmatch, but his 4th cousins did.
The website identified 10 to 20 distant relatives of the Golden State Killer's (sharing the same great-great-great grandparents)
They "resist". All that means is they ask for a proper legal document, such as a warrant.
Warrants are easy to obtain. Judges give them out like candy, and I'd be incredibly surprised if after the success of the Golden State Killer case, that 23&me doesn't get 100's or 1000's of search requests per month.
Sure, they are probably not ever getting the full dataset, but you don't really think they are actually contesting the legal authority of the government to do this right? 23&me is not your doctor. You have no HIPAA protections.
That means in all likelihood it is still there, and may actually still be being served to other users.
> That means in all likelihood it is still there, and may actually still be being served to other users.
Thank goodness things like CCPA will change this.
Perhaps a prepaid credit card bought with cash and having the kit mailed to a PO box?
You would need your own home lab kit that can do all of the diagnosis in your home, without being connected to any external networks at all.
To reduce exposing "who" you are, then you would have to ensure that nobody currently related to you, or future offspring, ever get their DNA stored, are never arrested, are never in a medical facility that stores DNA samples, and so on. You would also want to verify that nobody related to you has ever been arrested or provided their DNA willingly or otherwise.
DNA can also be used in conjunction with computer modeling to draw a picture of approximately what you look like. That image can be compared to state ID card data. This was done for a brief period in Japan, using chewing gum stuck to bus stop benches, to show off their software. Here [1] is one example from 2013.
In summary, to remain anonymous, you would need a kit that you operate at home, that does 100% of the diagnosis and reporting in your home, with no DNA and no data leaving your home whatsoever.
[1] - https://www.smithsonianmag.com/science-nature/creepy-or-cool...
It should also be valuable for screening candidates for security clearances. Are the relatives named by the candidate related to the candidates DNA relatives? If not, further investigation is warranted.
Even if the CIA create a complete web of fake identities in the DNA database, how do you stop a real relative uploading their DNA?
Might find cases of infidelity more than anything. Talk about awkward.
https://www.telegraph.co.uk/news/2019/05/31/oneperson-10-mis...
That is for the UK. It may vary a lot by ethnoreligious and socioeconomic groups in different countries.
The two objections are 1) exposing genetic health info 2) foreign countries can identify our spies.
For #1, I have news for you: insurance companies already build risk profiles of you, DNA profiles are not going to tip the balance of your premiums against what they already know. This ship has sailed. (and TBH if they didn't insurance would likely be even more unaffordable and out-of-reach than it already is)
For #2, I can't say.
But think of the benefits: how many more crimes would be solved? How many LESS innocent people would go to prison for crimes they didn't commit?
Plastic straws, browsing history and DNA indexing are white people problems, IMHO. Look at what it's like to be black in America in 2019: Botham Jean was sitting in his own apartment, eating ice cream, watching a ball game when a white off-duty Dallas police officer broke in and murdered him for no reason.
She'll be out of prison in 5 years.
The rise of body cams has the last 10 years has shown these types of incidents happen more frequently than we ever wanted to admit.
How many people are hurt in real life by things like DNA indexing? Please. It must be nice to be so rich to worry about frivolous non-problems like these. A national DNA index could keep a lot of innocent (mostly minority) people out of prison but oh no god forbid a white person be revealed to have a genetic marker for Alzheimers and their insurance premiums go up. The horror.
https://www.chemistryworld.com/news/synthetic-gene-cost-slas...
Basically, I'm asking: is this really true? Given a drop of your blood I can frame you today for anything plausible for under a $1000? It's kind of difficult to believe.
They can only test a relatively small group of SNPs, and they chose the ones that (at the time) believed differed the most from one person to the next, so as to maximize the probability of being able to distinguish between individuals.
But if you've got everyone's DNA, then you can calculate those SNPs for everyone, and then easily create kits that would allow you to frame anyone you want just by leaving behind samples of "their" DNA at the crime scene of choice.
So, if I really can make a sample of "fake DNA" (that will be indistinguishable from the "real" for forensics purposes) for a couple hundreds dollars, I really can frame anyone I know for anything (right now!), because getting a sample of their DNA isn't really that difficult.
It doesn't quite add up in my head, because if it's so simple, why the courts would even consider it hard evidence?
The kind of DNA sequencing you do on the population/genome scale is of relatively low quality and depends on a reference genome. It is not a de novo sequencing. Particularly challenging are repetitive sequence areas; high-throughput sequencing utilizes short reads that cannot be unambiguously assembled or mapped in these areas. If you have two sequences that have AGAGAGAGA... on their ends, you cannot determine to what degree they overlap. Only reads that span the repetitive sequence with sufficient margins can be unambiguously assembled or mapped.
DNA fingerprinting, however, relies precisely on robust characterization of these repetitive sequences. These sequences experience many errors during replication that produce high diversity in a population. Your unique suite of sequence lengths is used to identify you. This is assessed with restriction digest fragment length polymorphism analysis (RFLP analysis), an entirely different technology from high-throughput sequencing.
These repetitive sequences are also difficult to synthesize, for the same reasons it fails in real organisms. RFLP analysis is, therefore, about the most robust way you generate a DNA 'fingerprint'.
This situation changes if the sequencing technique used generates longer reads. Thus-far, the economical option always uses short reads, and this technique is perfectly suitable for the kinds of analysis done. It would take a breakthrough in sequencing technology for this to change, which is certainly plausible, but is not the current reality. A future concern, perhaps, but science fiction for now.
It's easy to see the short-term, first-order positive results. However the power to abuse such information is basically unlimited.
How are people going to use a DNA database to commit genocide?
How are these people going to be killed en masse? What would stop someone from using the same method without a DNA database?
This argument makes no sense...the thing stopping genocide now is not the inability to identify people based on their genetic characteristics.
Instead we rely in inaccurate authentication measures like birthdays and names and photos...hence endless suffering.
DNA would positively or negatively identify people.
Besides, people are already voluntarily doing this at airports as part of the CLEAR program. So your horrible awful terrible nightmare scenario...literally goes on every day at major American airports.
Only when you have a sample to compare it to that definitively came from the perpetrator (not just “was found at the scene and can indicate that whoever it came from was present”.)
That's actually not all that common.
The fact we all have to suffer thru terrible, imperfect authentication techniques like looking at your birthday shows we should have a database to save us all the grief.
Honestly all your arguments are actually GREAT reasons to have a national DNA index.
Who suffers from government lists of potential terrorists, criminals, and their relatives? It's not a "white people" problem. That would be a problem faced primarily by dark-skinned people.
And really, what else would the government do with a database of the DNA of every person in the country, other than use it to track and profile people of color? Could you imagine being "stop-and-frisked" for your DNA to see if you were related to any known criminal, and then questioned under suspicion that you might know where they are hiding?
It seems simply crazy to say in one breath that government and police abuse their power, and then in the next say you want to give them authority to keep files on every single person with impunity.
Cops already check your ID to see if you're related to any known criminal! Literally, this "nightmare scenario" you're envisioning happens every day in America. E.g.: https://theintercept.com/2019/06/28/nypd-gang-database-addit...
It's comical that you think this is some 1984 thing that will happen if we enable DNA indexing...the fact you don't know it already does happen shows just how far removed your experience is with police from those of black and Hispanic people in America.
If you're Arab flying into the country? Even worse.
If anything DNA indexing would allow innocent, unaffiliated people to not have to endure the indignity of what they currently go through.
I think your expectations on how many crimes a DNA database would solve is vastly over-estimating. For example, even if a rape case collected DNA evidence, most of them never actually process those kits. You can't solve a crime if you never look at the evidence to begin with.
I think a DNA database is a solution in search of a problem.
Power to do what? Identify you? They already (try to) do that! A DNA index is just a superior authentication mechanism, one that would involve a lot less suffering for those being identified.
The not processing of rape kits has been shameful and many nonprofits are working to rectify that problem: https://www.rainn.org/articles/addressing-rape-kit-backlog
You don't experience the problem because you're likely wealthy and probably white. The fact that rich whites can so easily dismiss even the idea of police authentication as a problem just shows that rich white America isn't even aware what poor black people go through in this country every single day.
I can’t imagine what it’s like to dismiss problems based on the ethnic demographics you believe they impact.
For example: https://www.nytimes.com/2013/06/26/us/supreme-court-ruling.h...
That url smells like amateurism, hopefully I'm wrong
EDIT login1.php does a POST to login2.php and site still runs php5. I'd imagine this site's already been hit with every scanner under the sun.
The attitude of the founder is very concerning. He doesn't seem to grasp how serious managing over a million DNA records is, even after experts and researchers try to tell him.
The should temporarily pull the site down, or at least disable the search until work can be done, as Mr. Ney suggested to them. The site isn't a money maker, what would be the harm?
I'm not sure this is the analogy you want to use. The wolf ended up eating the boy in the end of that story, didn't it?
"Already known". So when the hell are they going to take their service down until they find a way to secure it??
First, we don't actually have the ability (as far as I'm aware) to use a particular genetic sequence to activate some drug that would work systemically. Second, we don't have the ability (as far as I'm aware) to recognize an identifying sequence, then do DNA damage elsewhere in a life-sustaining gene. Lastly, it takes so long to identify the output of a gene (protein, siRNA, rRNA, or whatever) and make a drug targeting that output that even if you were able to target a coding region, it would be far faster to kill them by more traditional means.
It's far easier to take an already-deadly disease that kills indiscriminately, modify it to have shorter incubation time and higher kill rate (so it burns itself out before going pandemic) and shoot it at a target on a spitball or with a Bulgarian umbrella, while they're on their way to meet with everyone else you want to kill.
Either way, that's still leaving biological evidence all over the crime scene, and has the potential to kill a lot of people you weren't specifically targeting. So the preferred methods of assassination will likely continue to be poisons, firearms, and explosives for a long time to come.
IE, not possible, period.
Human DNA is almost identical in every human that lives, and genes are present in everyone that are not active. You'd try to target a given group of people with e.g. brown skin and short stature and you'd end up killing your neighbors plus some other random people half a world away.
DNA isn't computer code, it's a random stew.
Imagine a virus that has a 90% mortality rate among East Asians, but only a 10% mortality rate amount Europeans. Or vice versa. It breaks the concept of mutually assured destruction because the attacker might believe that other nations do not have the ability to strike back, or they can construct feasible defenses against a counterstrike. Release the virus then close your borders and ports.
It also would of course be easier for a non-state actor to construct a world-destroying biological weapon compared to an arsenal of nuclear weapons. You can hide a biological weapons lab anywhere.
Viruses and bacteria already can jump zoonotically (between distant species), it would be trivial to adapt to within-species targets.
As I recall, the individual I was talking to said that the didn't think it was possible to carry out that exact scenario today, but that it was close enough to reality to not be science-fiction, and would definitely be possible eventually.
Police matched the killer's DNA with one of his relatives' DNA in the DB, started digging in his family and found someone matching the profile of the killer.
Police then watched him and got his DNA from a can he threw away to give them the exact DNA match.
Genealogy DNA tests only use 0.07% of a person's DNA (that's 0.0007 or seven ten-thousandths). Plus it's in the non-coding or "junk" zone of the chromosomes. Not much opportunity to figure out people's health issues from that little DNA.
[0] https://customercare.23andme.com/hc/en-us/articles/218392668...
(I'm not saying that their aren't false positives, just that improvements are being made as technology improves.)
False positives only matter when you are trying to be definitive about disease diagnosis. That is why clinicians follow up with more sensitive DNA tests after something like 23 and me detects a deleterious variant. For something like ancestry, the number of true positives is so ridiculously large that a few false positives don't matter.
The site themselves aren't important but they are physically linked to important sites. DNA is a chain, if you which section you are in and roughly what it looks like you can infer someones disease state.