Karma seems to always work things out.
Karma seems to always work things out.
Technically, 23andme is also pretty bad, which is hard to understand given that they employ very competent people and they are well funded. Seems like a space ripe for disruption. Their biggest competitor, DecodeME, never really aimed at B2C and just used customers to harvest data, then sold to a pharma.
23andme genetic risk scores are mediocre at best. Promethease makes better predictions. For example, in my case I have a high risk MHC allele, which is both trivial to predict and well understood since the 1980s. Never popped up on their reports, yet it is the first item you see if you feed your 23andme raw data to Promethease, or if you analyze the data yourself.
Basically you either have hot backups you can delete from (this is bad for obvious reasons), or your backups expire in a given time (this is most common), or you have each record encrypted with an encryption key that is saved in other ways so you only have to destroy those to make the data irretrievable.
Of course, that system has to be backed up, etc, etc.
My theory is that you’re making a concession somewhere in the backups to a separate keyring system. Either there is no cold backup, or you don’t do cold backups at all, or your cold backup is actually semi-warm and needs to be hooked up to a system intermittently to be reconciled against production (in which case, the backups need backups to protect against a failure on the reconciler system.) The onus is on the answerer to tell me how they would avoid one of those concessions. Respectfully, anything else/less is just fluff like, “it’s totally possible.”
I'm confused. Are you saying those are small concerns? Because I'm saying the backup mechanism for the keys surely need to be resilient to all of those.
Ironically, I've responded to deletion requests made by email in which the person did not have any records in our systems, until receiving the deletion request containing their name and email address.
https://verasafe.com/blog/do-i-need-to-erase-personal-data-f...
Yeah, right. ANYTHING you put in the cloud or any other digital media no longer belongs to you. I suspect 23 sold this valuable data, that any insurance company would kill for, to the highest bidder. When will we learn we cannot trust any company with our info?!?
They say they provide your data to (to various levels, not necessarily genetic data):
- Service providers (Fedex knows you receive a shipment from 23&me, physical storage of your sample, someone hosts their servers)
- Sharing to people/entities at the users direction
- Any future commonly owned entities (23&me goes through a merger, new org has your data)
- Valid court orders ("23andMe will not provide information to law enforcement unless required by law to comply with a valid court order, subpoena, or search warrant")
> Delete your 23andMe account and personal data, including your personal information, genetic data, and other information collected through your use of the Service.
> Upon receiving your confirmation we will process your request to delete your data, and you will no longer be able to sign-in to your account. Please keep in mind it may take up to 30 days to fulfill your request.
What's your basis for your claim?
“The federal Clinical Laboratory Improvement Amendments (CLIA) of 1988 and California laboratory regulations require the lab store your de-identified genotyping test results and to keep a minimal amount of test result or analysis information,” an email from 23andMe said. “Our laboratory will retain your genetic information and a randomized identifier on their secure servers for a limited period of time, 10 years pursuant to CLIA regulations.”
I was friends with a former exec. At a party I remember him callously mentioning that you can’t delete data off their platform. I inquired a bit more and he pointed me to one of the laws referenced above
23andme is not lying in a legal sense. They seem to be deceptive though
So they delete everything they have under your name and the lab retains a copy of your sample and the sample results?
On paper, this is sufficient because a sample + results is no more useful to someone nefarious then a piece of hair found on the ground...
It only becomes a problem if they fail to delete any identifying information that could connect it to you...
If you had not mentioned this i would have thought they weren't testing people at all.
Back then, few people had the mindset of, "if they own my data, they own me." But we're starting to see it take hold.
I would, however, love to send my DNA to a company if they could provide the results without knowing any information about me whatsoever. For instance: I would be more than willing to buy the kit with cash and send it back with a burner email. Has anyone heard of such a service?
1. https://en.wikipedia.org/wiki/Joseph_James_DeAngelo#Investig...
Just remember that no matter who in charge you think is neutral or bad or great, things change, attitudes change, shit happens (remember the Patriot Act?)...
It isn't paranoid to say 'I don't trust the future, let's act cautiously instead of frivolously with things that have the potential to be extremely valuable to me, extremely impactful to society, and in which currently sits the greatest unexplored potential of this generation'.
But ok. Next time you go in for surgery tell the doc not to wash their hands because you aren't a scaredy cat.
Refusing to willingly take stupid risks is different than trying to live a life without them at all.
Your would-be future employers may reject you because of this data. Why hire someone with a higher risk of certain diseases or disables? It'd be illegal, but companies don't care about breaking the law if it's profitable and it'd basically take a whistleblower for anyone to know it happened. They certainly won't tell you that's why you weren't hired.
You could be denied housing or be targeted by extremists. More likely though, you'll be targeted by pharmaceutical companies. If the police didn't already have a copy of your DNA on file you might now have a place in every police line up, in any state in the US, for every crime committed where DNA evidence is collected. You could get wrongly flagged as a match through human error or statistics but either way it'll be on you to hire the lawyer who will have to prove your innocence.
We're moving toward a digital caste system (several really) where the data governments and corporations have on you will determine what you're allowed to do, how much you'll pay for things, and what opportunities you'll have. Every scrap of data you surrender will be used against you by anyone willing to pay for it, used in whatever way they think will benefit them, at any time, and you'll probably never even realize what happened. Just like right now, where companies don't tell you that they used your personal data to determine how long to leave you on hold. There's no telling what kinds of harms this could bring you, and there's no taking your data back to prevent any of it either.
I hope that data never comes back to haunt you. I'd sure hate to need to count on that never happening though.
It doesn't really matter if you're the guy who gets arrested for riding his bike (https://www.nbcnews.com/news/us-news/google-tracked-his-bike...) or the guy who gets arrested because of his DNA (https://www.science.org/content/article/forensics-gone-wrong...) or the guy who gets arrested due to facial recognition (https://www.cnn.com/2021/04/29/tech/nijeer-parks-facial-reco...) it's going to suck for you either way. They're all just different types of ammo that will eventually be used against you somehow or other.
Do you really think a judge would allow a guilty verdict based on stolen genetic data obtained from a hacker?
Do you really think braindead landlords and HR people would make decisions based on Promethease or whatever future tool replaces it?
Monetarily the genetic data is marginally valuable at best, which is the same reasons 23andme revenue comes almost entirely from novelty-seeking consumers rather than industry.
Maybe that part is far fetched. But insurance people will make user off it I'm sure. By letting this data out there you might be opting in to higher costs, or hassle getting insurance at all, that way.
At the begin of Hitler's reign, the Nazis started to ask people at many occasions for so-called "Ariernachweis" papers. Those were collections of documents to show that someones ancestors were pure according to their race theory. Many people didn't question this at the beginning. Later that data was used to round up minorities, i.e. to commit the wellknown atrocities.
Once data is centrally collected, you cannot know for which future purposes it'll be used. So, the question with regards to companies like 23andme should be: Do you trust the current owners, all future owners, and current and future business partners to not misuse and safeguard your DNA data?
> Monetarily the genetic data is marginally valuable at best Tell that to big pharma, health insurers, adoption agencies, dating sites, and companies that produce addictive products for consumers.
> Do you really think braindead landlords and HR people would make decisions based on Promethease They have shown to make decisions based on DEI declarations. I rest my case.
The judge won't have any idea how the innocent person's data got entered into the government's DNA database. The same way that judges doesn't care how police got your fingerprints on file (They got mine when I was in grade school. Teachers lined all the kids up in the hallway and the police fingerprinted us all. They told us it was in case we were kidnapped.). The judge cares about how the DNA was collected at the scene of the crime. It's enough that it matched DNA in the government's database. Even if it was discovered that the DNA came from 23andme's data I doubt they would care.
> Do you really think braindead landlords and HR people would make decisions based on Promethease or whatever future tool replaces it?
They already perform illegal background checks on employees and renters. (see https://money.cnn.com/2014/04/09/pf/data-brokers-ftc/index.h...). Whatever interesting data can be extracted from the DNA that was leaked will be added to the dossiers data brokers have on the victims.
Your fear is misguided and you have already lost the game.
If there’s any reason not to care, it’s not the lack of impact, it’s the impossibility of securing the data. I could sit here all day and convince you that you should care and then your cousin would get a dna analysis done and that would ultimately make all your caution mostly irrelevant. The only effective way to ensure genetic privacy is a legislative effort to control access to genetic databases, trying to avoid being put in such a database is only going to slow down how fast this happens.
Running -80C freezers is not cheap! I have 3 -80C freezers in my lab, those large chest-freezers, and each uses 22 kWh per day for a total of 66 kWh per day. Apparently the average US household consumes 29 kWh per day, so we use up 2 houses per day.
Our freezers certainly don't hold the 14 million samples 23andMe supposedly has, more like in the low thousands. They'd need the power-usage of a city to keep all those samples OK!
Storing this for an effectively indefinite amount is not uncommon. I used to work at a clinical genetics lab, and some material had to be stored (by law!) for a whopping 120 years.
https://globatic.blogspot.com/2013/10/the-23andme-full-and-r...
Google is pretty good at security, no?
https://cloud.google.com/blog/products/management-tools/lear...
I also think we can learn a lot about security from Google even if they comply with federal court orders requesting user data. "Willingness to comply with federal court orders" and "competence at securing data against cyberattacks" are two different things.
https://www.zdnet.com/article/google-the-nsa-and-the-need-fo...
To break the cycle, it helps to share concrete evidence of Google misbehaving rather than just presenting it as a fact that everyone knows. You get what you incentivize. If the feeling that Google sucks on privacy isn't linked to specific Google misbehavior whenever it is brought up, Google execs will correctly realize that users will feel the same no matter what decisions they actually make.
As a concrete point for discussion, in the zdnet article it states:
>After the news about NSA snooping first broke over the summer, Google decided it was time to start encrypting its datacenter-to-datacenter communications.
Is there an analogous security story from more recently where Google didn't try to address the problem in a similar way?
>Have you ever seen security done right anywhere? In my experience, it's always the bare minimum.
I think there's a lot of ground between doing the bare minimum for security and hardening your organization against the NSA. Every step towards greater security is a step I support, even if your organization isn't able to reach the "hardened against the NSA" level.
I'm happy for you if you want to harden yourself against the NSA, but I dislike black-and-white thinking. I care about harms to users which come from non-NSA threats too. Case in point: the original post about hackers selling 23andme data -- presumably to clients who are not the NSA, in some cases.
If every discussion of how to improve security gets derailed into a discussion of how evil the NSA is and how practically no one is secure against them, then organizations will continue to do security badly, and we'll see more breaches like this 23andme breach. Fatalism is a self-fulfilling prophecy. I see it every day here on HN.
[0] https://abcnews.go.com/US/2-us-navy-sailors-arrested-alleged...
My take is, if targeted advertising is the biggest thing you're worried about in terms of cybersecurity, you are probably doing reasonably well at staying secure.
I'm not particularly worried about Google stealing my credit card number and making fraudulent purchases. But I am worried about criminal organizations doing this.
There's so much FUD on HN about big tech companies, but I'm skeptical that their wickedness actually lives up to the hype. I suspect it is more of a clickbait miasma (journalists hate Google because they took revenue from the media industry) than anything based in fact. Google provides free and useful products (Google Search, Gmail, Android) to people across the world. Billions of people use this stuff voluntarily -- why?
If Google is "about as user hostile of an organization as there has ever been", it should be easy for you to come up with at least 3 examples off the top of your head (no searching for "14 ways Google is evil" listicles) of them being at least as nasty (on a per capita basis relative to the population of people they have relationships with) as the literal mafia. It should be no trouble at all. So, could you please do that for me?
2 - They've created an illegal advertising monopoly https://www.justice.gov/opa/pr/justice-department-sues-googl...
3 - Violate the law to illegally collect data on children, say multiple states https://www.ftc.gov/news-events/news/press-releases/2019/09/..., https://iapp.org/news/a/google-new-mexico-ag-settle-coppa-al...
Over a billion people smoke cigarettes, doesn't make it a good idea. Most of the worlds population can't afford an iPhone, so are left using Android.
Is it unreasonable to think they're probably doing something else illegal that hurts us right now? Or that they'll use their ill gotten treasure hoard to buy the resolution of their choice when they're caught again?
Why? Because there's no telling what happens to it. It's a failure of judgement to believe that just because a company is reputable today that it will be reputable tomorrow. Companies change owners, they change board members, they get bought and sold. And _hacked_.
So let's stop this nonsense of giving everyone a free pass because it was a "solid, reputable company". Maybe we can give grandma a pass, but someone on a technically minded forum such as HN should know better.
One thing I've come to realize over the past couple of decades is that with internet/tech/VC startups in particular, the statements they make about goals, philosophy, core values, and ethics are subject to change as needed to secure more funding, increase revenue, or in case of acquisition.
You really cannot trust what any company says until they've been in business at least ten years with an unbroken record of responsible, trustworthy operation. And even then it can all change with a merger.
People have been screaming this from the rooftops even back then.
I am interested in genetics, but I didn't trust google, and I trusted a google spouse company even less (it's like John Lennon's Google, and Yoko Ono's 23andMe, when I didn't trust Lennon to begin with) and my data hasn't been spilled. Half of you are thinking of all sorts of epithets to call me, but fact is, I was right about 23andMe. From a decision-making standpoint, slam dunk for me and anybody who listened to me. It was not an unusual position to take. "What. Could. Go. Wrong?"
(I'm fully aware they probably already have my data from numerous blood tests I've taken from normal medical checkups, etc. but what could I have done about that?)
The link between 23andme and Google is tangential at best. Anne Wojcicki and Sergey Brin were married and that’s it, but they are completely two different people.
I have no idea how you’d ever consider 23andme a reputable company. Reputation comes from 20+ years of history — your actions, not what you say. 23andme is not even 20 years old yet — how can you trust something that young?
Really? You're being either very generous or very naive here, because even back then it seemed blindingly obvious that it's a bad bloody idea to trust a tech company of nearly any kind to safeguard your data securely or honestly. Then double the paranoia when it comes to your genetic information. For somebody working in the tech space in particular to have not been be cynical about this is plainly absurd.
I think there's plenty of room for a new competitor to make money, but you can bet that any similar service is going to be just as bad for people's piracy and security. Nobody is going to collect and store that kind of data without either selling it or being forced to turn it over.
https://www.forbes.com/sites/nicolemartin1/2018/12/05/how-dn...
Because it seemed harsh to me, maybe I don't care about them security of some data and so use a weak password; that's on me, surely?
Based on the feedback I hear from my non-tech friends and family, not allowing them to use their single password used for everything would be a good way to exclude those folks from using whatever service you're trying to sell them.
Then again we walk about touching things, leaving convenient DNA samples for anyone to collect throughout the day. It’s only because sequencing is relatively high cost at present that we have the illusion of privacy. Once we go in equivalent terms from mainframes to single board computers in the DNA world, then anyone can pretty much have at your personal genome.
Would love to see how the criminal forensic science guys adapt their narrative to this impending reality.