4 ms·
> If I could do so anonymously, I'd do it in a heartbeat You can. See "How to use 23andMe without violating your genetic privacy", https://www.abine.com/blog/
by throwaway4567 11y ago
> If I could do so anonymously, I'd do it in a heartbeat
You can. See "How to use 23andMe without violating your genetic privacy", https://www.abine.com/blog/2013/23andme-without-violating-your-genetic-privacy/ https://www.abine.com/blog/2013/23andme-without-violating-yo....
- biot 11y agoUnlike the author of that article, don't publish screenshots of your exact results online. With the percentage risk and the ethnic background, it's likely trivial for 23andme to identify exactly which fake profile Sarah A. Downey used for her test.
- dfc 11y agoOnce I checked out, I went to my real, personal inbox to complete the 23andMe registration by clicking the confirmation email, which was forwarded to me from the alias email address. LOL. Thanks for posting this bit of comedy.
- throwaway4567 11y agoHow was that problematic? I don't see the issue, especially given that the author was on a VPN and using Firefox in Private Browsing mode while running DoNotTrackMe.
- ikeboy 11y agoMost email is sent unencrypted, so the NSA likely has a record of that email and can cross-reference it with the 23 account if needed. Even the header would probably be enough in this case, just to identify the particular masked email with the real email behind it.
- throwaway4567 11y ago> Even the header would probably be enough in this case, just to identify the particular masked email with the real email behind it. Are you implying that an HTTP header sent in the request to 23andme upon clicking the confirmation link would contain the forwarded email address of the user? Unless the user were on a web page that included their email account name in the URL (and thus visible in the REFERER header), I don't see how that would happen. And I don't think I've ever seen an email system that puts the account name in the URL.
- ikeboy 11y agoNo, the email header sent by abine when they forward the email from 23andme. That contains their real email address in plaintext, and might also contain the masked address; if not, a timing attack given the time of 23's emails and the time of the forwarded email might work. If the actual email is unencrypted, then the NSA gets everything for free.
- troels 11y agoOf course, now you have to trust that Abine won't pas your information on to NSA.
- throwaway4567 11y agoI would be more concerned with information being passed to providers of life, disability, or long-term care insurance. The Genetic Information Nondiscrimination Act (GINA) prohibits the use of genetic information in health insurance and employment, but not those areas. That seems unlikely, though. The article's approach is probably enough to prevent one's genetic information from being passed on to such insurance providers.
- SapphireSun 11y agoThis doesn't sound very anonymous... for one - he's giving them his DNA. Unless he has an identical twin that's fairly unique. Secondly, an adversary can guess he's an abine employee or knows one. That narrows the search space considerably. Whenever you donate DNA to a large DNA aggregating project, you can be fairly trivially re-identified via a few ways. Even if you control all the other information, if a relative contributes DNA, your match will be close enough to narrow it down to a few relatives (including you). The FBI has famously used this technique to find serial killers and identify seriously messed up paternity. If it were me, I'd get the NIH Confidentiality Certificate. At least you have legal protections then.