Hacker leaks millions more 23andMe user records on cybercrime forum
techcrunch.com
techcrunch.com
23andMe's blame is an obfuscation of the problems which underlie this situation.
1. There is the matter of having insufficient granularity in their sharing options within the DNA Relatives program. It comes with two general levels, which is not enough.
2. 23andMe limits one to seeing the closest 1500 matches who have opted-in to DNA Relatives. That would have allowed a hacker to collect data on most people in the database despite having only a few thousand compromised accounts. (Haplogroups, ethnic origins predictions, names, profile data, a list of relatives, and information on geographic origins.)
3. The 1500 match limit would be helpful, in theory, however for some time (recently) it was possible to see profiles beyond those 1500 matches. I'm not certain if these were limited to only those who shared matching DNA segments but who fell outside of the 1500 match limit. And I can't be certain if this was part of the method exploited by these malicious actors.
> If you choose to participate in the DNA Relatives feature, you have multiple privacy options to suit your individual preferences. For complete privacy, you can opt out of DNA Relatives entirely.
How is a feature opt-in if you need to opt-out to get "complete privacy"? What does complete privacy mean in this case and how does it compare to privacy that you can reasonably expect?
I call bullshit on their statement that the feature is opt-in.
But "opt in" and "opt out" as verbs mean "choose to/not to participate". So you can in fact "opt out" of an "opt-in" feature. It means choosing to keep the default of not opting in.
You could rephrase the 23andme statement to be something like “users of this feature can choose from a range of privacy settings. For complete privacy, do not use this feature (which is the default setting).”
Karma seems to always work things out.
Technically, 23andme is also pretty bad, which is hard to understand given that they employ very competent people and they are well funded. Seems like a space ripe for disruption. Their biggest competitor, DecodeME, never really aimed at B2C and just used customers to harvest data, then sold to a pharma.
23andme genetic risk scores are mediocre at best. Promethease makes better predictions. For example, in my case I have a high risk MHC allele, which is both trivial to predict and well understood since the 1980s. Never popped up on their reports, yet it is the first item you see if you feed your 23andme raw data to Promethease, or if you analyze the data yourself.
Back then, few people had the mindset of, "if they own my data, they own me." But we're starting to see it take hold.
One thing I've come to realize over the past couple of decades is that with internet/tech/VC startups in particular, the statements they make about goals, philosophy, core values, and ethics are subject to change as needed to secure more funding, increase revenue, or in case of acquisition.
You really cannot trust what any company says until they've been in business at least ten years with an unbroken record of responsible, trustworthy operation. And even then it can all change with a merger.
I would, however, love to send my DNA to a company if they could provide the results without knowing any information about me whatsoever. For instance: I would be more than willing to buy the kit with cash and send it back with a burner email. Has anyone heard of such a service?
People have been screaming this from the rooftops even back then.
Why? Because there's no telling what happens to it. It's a failure of judgement to believe that just because a company is reputable today that it will be reputable tomorrow. Companies change owners, they change board members, they get bought and sold. And _hacked_.
So let's stop this nonsense of giving everyone a free pass because it was a "solid, reputable company". Maybe we can give grandma a pass, but someone on a technically minded forum such as HN should know better.
Really? You're being either very generous or very naive here, because even back then it seemed blindingly obvious that it's a bad bloody idea to trust a tech company of nearly any kind to safeguard your data securely or honestly. Then double the paranoia when it comes to your genetic information. For somebody working in the tech space in particular to have not been be cynical about this is plainly absurd.
I am interested in genetics, but I didn't trust google, and I trusted a google spouse company even less (it's like John Lennon's Google, and Yoko Ono's 23andMe, when I didn't trust Lennon to begin with) and my data hasn't been spilled. Half of you are thinking of all sorts of epithets to call me, but fact is, I was right about 23andMe. From a decision-making standpoint, slam dunk for me and anybody who listened to me. It was not an unusual position to take. "What. Could. Go. Wrong?"
(I'm fully aware they probably already have my data from numerous blood tests I've taken from normal medical checkups, etc. but what could I have done about that?)
If you had not mentioned this i would have thought they weren't testing people at all.
Yeah, right. ANYTHING you put in the cloud or any other digital media no longer belongs to you. I suspect 23 sold this valuable data, that any insurance company would kill for, to the highest bidder. When will we learn we cannot trust any company with our info?!?
I think there's plenty of room for a new competitor to make money, but you can bet that any similar service is going to be just as bad for people's piracy and security. Nobody is going to collect and store that kind of data without either selling it or being forced to turn it over.
https://www.forbes.com/sites/nicolemartin1/2018/12/05/how-dn...
Because it seemed harsh to me, maybe I don't care about them security of some data and so use a weak password; that's on me, surely?
Based on the feedback I hear from my non-tech friends and family, not allowing them to use their single password used for everything would be a good way to exclude those folks from using whatever service you're trying to sell them.
Then again we walk about touching things, leaving convenient DNA samples for anyone to collect throughout the day. It’s only because sequencing is relatively high cost at present that we have the illusion of privacy. Once we go in equivalent terms from mainframes to single board computers in the DNA world, then anyone can pretty much have at your personal genome.
Would love to see how the criminal forensic science guys adapt their narrative to this impending reality.
I only know the meaning where it is a deliberate thing to attract bad actors. Is the entire company not meant to provide genetic information?
They can be unavoidable but need to be well protected. Most companies fail at this.
All it takes is one employee to pip install the wrong library or fall victim to a phishing attack or 3rd party vendor attack and its over. And on a long enough time scale, it happens.
https://en.wikipedia.org/wiki/Honeypot_%28computing%29
TL;DR: A honeypot is like a bait car in a police sting operation; It's something that looks like a vulnerable system with something of value to attackers, but in reality is a fake meant to catch intruders or collect data on them.
They are just lying, and you know they know they are doing something unethical, because they wouldn’t need to make up nonsense phrases otherwise.
It sucks since I have zero trust that they would actually delete my data if I asked them too, and even if they do is that data still living somewhere fed into some model or research or whatever.
I hate to say that there is a part of me that kinda doesn't want to know if my data is a part of this, this just feels different than a credit card or some shopping data leaking.
Even worse since I have not gone to 23andme in a while, I feel like this was likely also before I cared about proper password security so it would not surprise me.
My data is probably in this breach too, and I am not going to waste one second of my life on regret over it.
Stay tuned to find out if you get something from the class action lawsuit. Like the experion hack, you may at least get an interesting coffee table artifact when they mail you a pathetically small check.
Maybe this doesn’t matter today but who knows what it’ll be valued at 50 years from now?
Don’t upload your saliva to the internet folks.
There are easier ways to find Jews...
If you call criminal convictions "little more", sure.
Many people consider that a good thing, but I'm not talking about moral valence or vibes - the point is they are an industry supplier of PII that sends people to jail.
Your argument only makes sense if you believe you are innocent of all present and future crimes, which is an impossible fact to know by the very fact that you do not know the laws in the future.
pretty bold claim -- as with any additional justice element the innocent will be trampled to some degree.
Here's the thing : it doesn't just open up criminals for prosecution, it also opens up the 23andme population to an even larger arrangement of possibilities for self-incrimination and 'incorrect or misdirected pursuits of justice'.
It's nice that a well known murderer was found out, but the reality of the situation is that we likely wouldn't hear very loudly the stories of innocent folks with cases mishandled by a law enforcement bureaus that were enabled by 23andme or similar services. It looks bad on the law enforcement agencies and it looks bad for the corporation.
Seems like there is at least some value.
But let's wait until it's clear whether raw data was actually leaked.
I remember a few years ago there was a button to download raw data.
So if you can log in you can just download.
But I registered under a false name, gave the test kit to my dad, and had him test one of my aunts too.
So it wasn't as exact but it was good enough to sate my curiosity.
Everything gets hacked sooner or later. A famous hacker once said that you should assume that everything you say or write will one day be public information.
Edit: And before anyone says "how could you do that to your father", if you knew him you'd understand. He's practically off grid and he's going to die soon, the aunt is already dead.
Do you mean like for drug discovery and other medical research? Why would that be a bad thing?
But it still removes my ability to delete my data, especially when 23andMe has proven that they are not properly safeguarding this data.
Also me donating this data to a research organization vs being lured in by 23andMe's marketing are drastically different things.
Excerpt for the second part:
> To determine whether a natural person is identifiable, account should be taken of all the means reasonably likely to be used, such as singling out, either by the controller or by another person to identify the natural person directly or indirectly. To ascertain whether means are reasonably likely to be used to identify the natural person, account should be taken of all objective factors, such as the costs of and the amount of time required for identification, taking into consideration the available technology at the time of the processing and technological developments.
So they don’t call for an exact probability, but if you can prove you did appropriate threat modelling and put controls in place to counter those threats you should be fine. You are literally doing more than most companies if you manage that.
My mom did.
She never asked me, or anything. But half my material is right there, in an irrevocable database, now leaked online for the world. And I have no genetic rights or any claim, even though half is explicitly mine.
Honestly I am not sure where I stand on that issue. Or rather it's probably to do with society wide regulation not individual rights ...
If a stranger had asked OPs mom for OPs phone number out of the blue, there are many moms that wouldn't share a PHONE NUMBER without asking the phone number holders permission.
But fewer would ask their relatives if it's ok to stick a decent portion of their DNA into a database.
Should mom not be allowed to give out her number. She had it first. Or should mom need to clear every use of her data with her kids because it might affect them.
Should OP get mom’s permission before emitting genetic material on a lover because that material is half of mom’s dna?
I think this is not a path that can be exactly logiced out, so I stick with “do what you want with your data.”
Anger is better directed at legislators for not regulating these sorts of businesses under HIPPA and similar laws. Your mom’s medical records also contain a bunch of sensitive information about you and yet you probably don’t get mad each time she visits the doctor despite the privacy risk this incurs.
Treating 23andme like a lighthearted way to enhance your genealogy hobby or whatever is actually so fucking wild. This shit is not a game, only a SMALL fraction of the victims are 23andme’s customers. 23andme’s responses to me are proof enough the entire company should be shuttered because they are grossly negligent and don’t understand what business they are in or what they just did or how they fucked up.
And digging around the breachforums DOT is/Thread-23andMe-Great-Britain-Originated-4M-Genetic-Dataset , you see stuff like
"The data includes information on all wealthy families serving Zionism. You can see the wealthiest people living in the US and Western Europe on this list."
This link combined with the 2nd one doesnt look good in any stretch of imagination. These are antisemitic leaks intended for harassment and/or hit lists. It definitely looks BAD. But again, it's already in the world now.
-------------------------
Here's the schema of said data ( breachforums DOT is/Thread-DNA-Data-of-Celebrities-1-million-Ashkenazi-REPOST ):
profile_id; account_id; first_name; last_name; sex; birth_year; has_health; ydna; mdna; current_location;region_1;region_2;region_3;region_4;region_5;subregion_1;subregion_2;subregion_3;subregion_4;subregion_5;population_id1;population_id2;population_id3
I've had someone give one as a gift, so glad I didn't do it.
Not that i really care, you're not going to find a password or my first pets name in my DNA.
Fuck these guys. Fuck their bullshit misdirection.
This is the equivalent of corporate doxxing. Until individual execs in these mega-corps that piss in the face of their users bear individual consequence for this type of thing it’ll keep happening.
Because until then there’s no requirement to actually really give a shit. We’re grist in the money mill.
The lack of consequence has me seething more than the breach.
> Edit: the victim shaming in comments here is staggering.
And while 23andMe claims that a credential stuffing attack was at the root cause of this leak, the hacker(s) who first posted about this leak on Hydra Market over 2 months ago claim that they simply used (abused?) an API that 23andMe offered to their academic and research collaborators.
The hacker(s) claimed to have 300TB of data, including raw data, but have not proven that the scope of the attack was that large. But if their claim is true, then the breach was definitely not due to a credential stuffing attack, but fits well with the hacker(s) claim of using an API.
So, if the extent is as claimed by the attacker(s), then it is much more likely that one of 23andMe's API was used to scrape everyone's data, not a credential stuffing attack. Either one of their collaborating researchers got hacked, or they had (have!?) an access control vulnerability in their API which allowed the attacker to again scrape everyone's data.
I cannot find much information about the API 23andMe offers, but I did find one on RapidAPI (https://rapidapi.com/23andme/api/23andme), and indeed if there was some sort of access control vulnerability or some sort of hack of an escalated user then with even 1 individual as a starting point, they could download the data using various endpoints (there's even an endpoint for the entire individual's genome...) and then get the relatives of that individual (an endpoint for that too) and then recursively do the same for all relatives until every person has been downloaded once.
At this point in time, I am highly suspicious of 23andMe's defense but until the attacker releases proof that they have raw data we can't really prove that they're wrong/lying about the actual magnitude of the attack. But I do believe their claim of using an API makes a lot more sense than the way 23andMe proposed, so I am very worried.
so you're saying they used a genetic algorithm ? sorry, couldn't resist.
23andMe grabs a person by the source code and somehow that isn't considered obscene.
My data isn't 23andme- it's a whole genome. 23andme's data collection is very limited, and in my experience, fairly optimistic about its predictive ability for health.
There are a lot of lessons to learn from the 20th century, but I don't think "you have to hide your ancestry" is one of them.
I don't understand privacy nuts.
What exactly is someone going to do with my DNA? Any entity that's a threat to use it for something nefarious is going to get it from me pretty easily. They could grab any number of physical items that I've touched or left my hair on etc.
Should they do a better job of protecting the data? Yes. Am I going to freak out over something that will likely not affect my life in any way? Nope.
Genetic data sounds important but in the bigger scheme of things, it's probably the least manipulatable data about a person on the internet.
My genetic data is less weaponizable than if I uploaded hundreds of pictures of myself and my shared my social graph to Facebook, if I shared my political opinions on Twitter, if I commented/posted on Reddit boards of my interests and hobbies. It's also less weaponizable than the multitude of "invisible" data that I feed to Google, my incompetent local government, service providers, every shop that is shipping something to my home address.
I lose genetic data everywhere I go, every day. 50-100 hairs fall of my head, and I leave fingerprints on everything I touch. I "lose privacy" every day by walking into somebody else's photo/video/TikTok, and by mishandling of it by poor government/business entities.
Life's too short.
No, Until individuals stop using these mega-corps that piss in the face of their users and also bear individual consequence for this type of thing it’ll keep happening.
https://www.nih.gov/news-events/news-releases/nih-s-all-us-r...
https://www.nytimes.com/2013/06/18/science/poking-holes-in-t...
As you can surmise from those, the issues about DNA sharing are more general than 23andme, or even private companies.
I mean, therapy notes have been leaked, and hospitals have had medical records compromised.
I do genetics research and although 23andme does have sensitive information, the level of information they have is relatively low. People with certain polymorphisms might be at risk but most of it is pretty crude, and I suspect many of the people affected might know through nongenetic ways that they were at risk anyway. I think the genetics revolution people were predicting doesn't exist, or to the extent it does, it will require something different than what 23andme has.
Google or Apple has more damning and accurate information about someone than 23andme. If 23andme or anyone else had some mind-blowing insights into you personally based on your genes, they'd certainly sell that to people and they don't. Most of their selling points are in genealogy and things like that.
I don't mean to sound dismissive, this sucks and 23andme could/should have done things differently. It's just I think as a society we need something other than "live as a technohermit" or "implement such strict security you're at risk of shutting yourself out" and "become a permanent victim of darknet hackers and authoritarian tyrants". I also think people overestimate the information value of the genetic information 23andme has. Yes, it's significant, but it's really at this point limited to what they offer. There's no would-be 8yo serial killers out there that, if we only had 23andme information, would be able to "prevent" them from killing in some real-life version of Minority Report crossed with Gattaca. Maybe someday, with different information, but not now.
I'm not sure how they worded this but it's their shortcoming, not their customers. Customers reuse passwords and will continue to do so. For sensitive PII it's far easier to enforce 2FA or Google SSO than to change customer behaviour.
Regardless, the key quote from the linked article:
"23andMe blamed the incident on its customers for reusing passwords, and an opt-in feature called DNA Relatives, which allows users to see the data of other opted-in users whose genetic data matches theirs. If a user had this feature turned on, in theory it would allow hackers to scrape data on more than one user by breaking into a single user’s account."
Not all compromised credentials are used in credential stuffing attacks.
I saw this idea somewhere on here a few months ago, and since then, granting users the ability to set their own passwords seems like a dumb thing to do!
Forcing passwords onto users is a sure fire way to get people to write their passwords down and constantly get locked out of their account. In some circumstances that’s not a problem. For local domain access, that’s completely unworkable. For websites it makes a little more sense since users can use password reset via email, but if you’re going to expect people to rely on that then you might as well allow them to set a password and use email as 2FA.
[1] https://haveibeenpwned.com/API/Key
(23andme customer using Apple SSO, have strong opinions on customer IAM, passwords must die)
https://www.troyhunt.com/understanding-have-i-been-pwneds-us...
Yeah I know there's the whole genetic disorder screening thing which might receive more updates in the future, but I think most of their customers probably did this for the novelty of knowing where they came from.
I mean, 23andme has one of the ultimate methods of account recovery available to it. (ignoring that people tend to leave copies of their DNA everywhere, but then you could just mail that in under a John Doe and find out all the same info anyway).
Which feature? Unless they didn't ask their user's email (which I'd find surprising), they could have added e-mail based TFA any day without asking their users to do anything.
This is a forum of engineers and builders - if a lot of data were being exfiltrated from your cloud accounts right now, would you know? What would your response plan look like? Maybe this could be a good way for all orgs to review those practices and make sure they have a plan.
23AndMe's product is their user's DNA, packaged nicely in easy to digest formats.
Shame on them for slacking off on security when bad actors could do actual dangerous things with that DNA data.
Makes me think that "data privacy" should be added into schools' mandatory health class requirements or something. Though most likely any prescribed curriculum would have been lobbied to death & not actually teach valuable information.
What is private about dna?
This relates to the biggest problem with biometrics: it represents an effectively static attribute about an individual. It cannot be reset and therefore we place this enormous responsibility on the reading mechanism and pipeline to the authentication process to attest that the human using it is doing so with consent.
23andMe Sued over Hack of Genetic Data Affecting Thousands - https://news.ycombinator.com/item?id=37895586 - Oct 2023 (20 comments)
Who hacked 23andMe for our DNA – and why? - https://news.ycombinator.com/item?id=37886543 - Oct 2023 (3 comments)
23andMe Accounts Hijacked and Data Put Up for Sale on Hacker Forum - https://news.ycombinator.com/item?id=37810755 - Oct 2023 (2 comments)
Nice work by the genetic testing industry lobbyists.
But the data revealed in analyzing the DNA (e.g. if you have a genetic disorder) should be PHI.
It's odd how something could go from "not PHI" to "now this is PHI" just by processing something like a piece of hair.
"At what point does it turn into PHI" would be a difficult question to answer.
IMO protection of DNA related data deserves something different than HIPAA.
>“We plan to engage constructively with policymakers on the best enforcement regime,” Haro said, reiterating that the coalition wants “a uniform national data privacy law” that treats all companies the same.
>The federal Health Insurance Portability and Accountability Act, a.k.a. HIPAA, includes penalties ranging from $100 to $50,000 per violation — that is, per hacked record. Violations also can carry criminal charges resulting in jail time.
Health and Human Services has a FAQ page[1] which states:
> genetic information is health information protected by the Privacy Rule. Like other health information, to be protected it must meet the definition of protected health information: it must be individually identifiable and maintained by a covered health care provider, health plan, or health care clearinghouse.
However, according to many other sources[2][3], the interpretation of these rules DOES NOT apply to companies like 23&Me. I assume the company is not considered "a covered health care provider, health plan, or health care clearinghouse", but (again) the HHS definitions are (intentionally?) vague/misleading[4].
I suppose you need to be very familiar with regulatory law to actually make sense of this junk. (I don't know the history of these regulations and carve-outs, but the tin-foil-hat part of me wants to blame lobbyists/legal-corruption for the lack of common-sense and simply worded regulations.)
[1] https://www.hhs.gov/hipaa/for-professionals/faq/354/does-hip...
[2] https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6813935/
[3] https://lawforbusiness.usc.edu/direct-to-consumer-generic-te...
[4] https://www.hhs.gov/hipaa/for-professionals/covered-entities...
For such a company that handles this data, I would have expected much harder security measures
DNA analysis is very important, and probably, should be mandatory for everyone planning to have children (to reduce the number of people with incurable or very expensive to treat diseases and save healthcare budget), but with current level of privacy protection the data will just leak around. Also, when DNA screening will become mandatory, government will probably require that it gets a copy of everybody's DNA. Looks like this war is already lost.
23&Me allows you to delete your data and your account if you no longer want to participate.
The fact that the genetic data isn't involved means this story isn't relevant to people panicking about sharing their genetic data with 23&me.
I have already been advising people to be cautious about such online services, or to use fake personal details where possible. I will now advise even harder.
https://jacquesmattheij.com/your-genetic-information-is-not-...
Then there is the point of what if I found I have some genetic disease and there is not much I can do about it. Not sure living with that knowledge would be better.
What I really don't like about these companies is that they are never transparent, you only find out after the fact what you bought into.
To that end, I'm curious on how they could have protected this better? Almost certainly doable, but I don't know of many ways you can protect people that are on my contact list from getting leaked if my contact list is leaked. Which is essentially what this is.
How easy is it to submit random DNA (cow, cat, dog, chicken, etc. or even fake?) and get yourself enrolled in their system to then legitimately have access to the next 1500+ "relatives?".
Given a few grand to spend on testing kits I reckon you could get the same results stuffing this DNA, as this "golem" guy did by credential stuffing.
23AndMe made the classic mistake to assume that biometrics are a type of authentication and allowed anyone to access the records of 1500 other people just by submitting some DNA....
You really must not fundamentally understand how this works. You are matched to people who also took a 23&me test and share DNA with you. The amount shared is how they infer relations.
There are people who do not even have 1500 matches, submitting a sample of animal DNA will quickly result in sequencing failure as the test is based upon the human genome and is effectively “written in the hardware”.
Fabricating a DNA is extraordinarily difficult because you need hundreds of cells with genetic material in order to even produce results. It would be so much easier to steal a sample from a known relative than it would be to genetically engineer some cells.
Then you are relying on that password manager, what if you lose access to it or the data with your keys? Welp...
It is. That way you only trust your password manager and not every single app you use (that can easily dump your password when you login, or might even store it as plaintext).
If a password manager is open source and you know how to audit it, you could do that. Otherwise you can ask somebody you trust who knows better.
> what if you lose access to it or the data with your keys
That is a possibility indeed. You should make backups, of course.
We’ve been working very hard on this problem, and recently devised a scheme known as backups. It’s like a whole copy of your data someplace elsewhere!
Snark aside; popular password managers have extensive recovery and replication capabilities.
By reusing a password, you're basically doing this already.
And please, don't say "insurance companies would love that data!".
Your raw data hasn't leaked unless it was your account in particular that got used, but you could be put on some guy's "Jew list", which you may or may not care about.
One of the questions is "should I also add my DNA" in there.
And if my DNA has been leaked then it wouldn't matter unless this leak is anonymous.
With that in mind I wonder if you could use this data to sort of populate this project. I also wonder if that would be legal or not.
I don't think it's a surprise that COVID normalised it for people to hand over their genetic material to anyone (swabs) without any option for refusal (no test? no live).
They should have to pay a shit load of insurance if dealing in this type of business with lots of personal data.
And the mistakes for making this type of mistake should be monumental.
Chubb's and AXA have been offering this for a couple years now and I know some large companies have taken out a policy.
The issue I've heard is the large providers rarely pays out as the pools are small and the risk profile for breach insurance is still actively being worked on so the exposure is potentially massive, so a lot of companies are forgoing Cyber Liability insurance.
There needs to be active regulatory work to solve this chicken-and-egg situation
Users shouldn't have to dick around with a more complicated 2FA system just to protect themselves from password reuse.
1. Makes it easier for users to lose passwords
2. Makes the user more susceptible to targeted hacking
3. Increases the number of passwords in note-taking services which may themselves be hacked
Edit:
Also, until a critical threshold is met of adoption among services, some users will just re-use the random password for other services.
A lot of this is mitigated by making the password non-human-friendly, essentially forcing users to use password management tools. That could be too much to put on users, until those tools become much more ubiquitous/effortless for the average computer illiterate user (basically the same point you're making about 2FA).
Though I don't necessarily grant your points. Password reuse means you're susceptible to nontargeted attacks which is strictly worse than your concerns, like #2.
i.e. Filtering out weaker attacks doesn't mean you're more susceptible to stronger attacks.
If I see a user try to sign up with an email + password in the breach list, I'd like to tell them to pick a different password, for instance.
It’s a shame because the relative matching is a really fantastic tool and has been able to connect a lot of people who would otherwise not have met.
People submit more weaponizable (behavioural) data to Facebook, Google and HN every day.
But also, if they were legal, with the GDPR they would have to obey much stricter rules about the data they collect.