6 ms·
I’m one of the leaked. I’m highly technical, security literate. I use unique secure passwords for everything. Fuck these guys. Fuck their bullshit misdirection
by itsafarqueue 3y ago
I’m one of the leaked. I’m highly technical, security literate. I use unique secure passwords for everything.
Fuck these guys. Fuck their bullshit misdirection.
This is the equivalent of corporate doxxing. Until individual execs in these mega-corps that piss in the face of their users bear individual consequence for this type of thing it’ll keep happening.
Because until then there’s no requirement to actually really give a shit. We’re grist in the money mill.
The lack of consequence has me seething more than the breach.
> Edit: the victim shaming in comments here is staggering.
- getu4543hji 3y agoI did 23andme and although I'm not happy about this, I admit I'm growing numb to all the leaks of information, and I kind of went into it with the assumption that it might be leaked at some point. https://www.nih.gov/news-events/news-releases/nih-s-all-us-research-program-returns-genetic-health-related-results-participants https://www.nih.gov/news-events/news-releases/nih-s-all-us-r... https://www.nytimes.com/2013/06/18/science/poking-holes-in-the-privacy-of-dna.html https://www.nytimes.com/2013/06/18/science/poking-holes-in-t... As you can surmise from those, the issues about DNA sharing are more general than 23andme, or even private companies. I mean, therapy notes have been leaked, and hospitals have had medical records compromised. I do genetics research and although 23andme does have sensitive information, the level of information they have is relatively low. People with certain polymorphisms might be at risk but most of it is pretty crude, and I suspect many of the people affected might know through nongenetic ways that they were at risk anyway. I think the genetics revolution people were predicting doesn't exist, or to the extent it does, it will require something different than what 23andme has. Google or Apple has more damning and accurate information about someone than 23andme. If 23andme or anyone else had some mind-blowing insights into you personally based on your genes, they'd certainly sell that to people and they don't. Most of their selling points are in genealogy and things like that. I don't mean to sound dismissive, this sucks and 23andme could/should have done things differently. It's just I think as a society we need something other than "live as a technohermit" or "implement such strict security you're at risk of shutting yourself out" and "become a permanent victim of darknet hackers and authoritarian tyrants". I also think people overestimate the information value of the genetic information 23andme has. Yes, it's significant, but it's really at this point limited to what they offer. There's no would-be 8yo serial killers out there that, if we only had 23andme information, would be able to "prevent" them from killing in some real-life version of Minority Report crossed with Gattaca. Maybe someday, with different information, but not now.
- Ylpertnodi 3y ago>Until individual execs in these mega-corps that piss in the face of their users bear individual consequence for this type of thing it’ll keep happening. No, Until individuals stop using these mega-corps that piss in the face of their users and also bear individual consequence for this type of thing it’ll keep happening.
- huytersd 3y agoDid you use a fake name and a prepaid debit card to make your purchase? Well I’m glad I did though they can just track me based on relatives that also use the platform if they really wanted to.
- tymscar 3y agoHow do you know? Where can you check?
- sorokod 3y agoYou shared your DNA data on the internet, time to review your security fundamentals.
- andersrs 3y agoEven if you didn't they'll likely have a relatives data.
- sorokod 3y agoTrue, but we should be responsible for ourselves to start with.
- dekhn 3y agoYou can get my entire DNA data, https://my.pgp-hms.org/profile/hu80855C https://my.pgp-hms.org/profile/hu80855C I can assure you I know more than a little about security, considered all the reasonable risks, and concluded that it's not really increasing my risk and is unlikely to do so any time in the future.
- autoexec 3y agoIf that's really you, I give you a lot of credit for being bold. You and the CEO of LifeLock both. Hopefully your confidence doesn't blow up in your face the way his did, but when/if it does, you'll probably never know why it's happening to you exactly. The easier it is to link that data to your identity the riskier it'd be. I haven't seen the 23andme data, but if it includes names, addresses, email addresses, family members, etc they're going to be a lot worse off than you likely are.
- dekhn 3y agoMy real name is David Konerding, so the linkage now is trivial. Again, I've evaluated the risk profile associated with my genome data and concluded that it's effectively non-existent, and will continue to be so. My data isn't 23andme- it's a whole genome. 23andme's data collection is very limited, and in my experience, fairly optimistic about its predictive ability for health.
- landemva 3y agoI do not understand why anyone with tech knowledge would have participated in this honeypot. Please help me understand why there was trust.
- jjtheblunt 3y agois the essence of the privacy concern that data showing predisposition for diseases (or whatever sort of weakness) can be dystopia-used to discriminate (insurance, etc)? Or just privacy in general?
- brigadier132 3y agoHow about creating a virus to give a disease to everyone of a specific race
- Arch485 3y agoAssuming that technology even exists, you wouldn't need 23andMe to get the relevant genetic data.
- jjtheblunt 3y agoyou'd have to define "race" but the idea seems legit considering crispr-cas9
- dekhn 3y agoThat's science fiction. No matter what you read in the popular press or scientific journals, engineering a virus specific enough to perfectly target a group of people sharing a common genetic history with perfect specificity and sensitivity, is still not something we could do. I also don't see this as being technically possible for some time.
- jjtheblunt 3y agoI keep re-reading what you wrote, and I think it's less far fetched than you imply, for the following reasons. Huge datasets labelled as to ancestry exist, characterizing distributions of alleles that imply "race", which is how Ancestry and 23andme, for American company examples, do some of their analyses. At least two Nobel prizes were recently awarded, one to Doudna and Charpentier related to Crispr-CAS9 for context-sensitive genome edits, and another for mRNA (which was in development for a decade or so before the entire Covid repurposing arose). So, I think the part missing, to your point, is the "vector" that would deliver a sequence of patch files, perhaps via CRISPR-cas9 etc, which would perhaps bind to the constellation of race-implication genome sites to collectively build some proteins of whatever sort of interest, whether for fitness repair or fitness reduction in the host.
- mikenuts 3y ago23andMe is trying to have us believe that multiple tens of thousands of their customers were hacked in a credential stuffing attack. With 1500 matches per person, assuming no overlapping relatives, you'd need somewhere around 10,000 successfully hacked accounts to get the amount of data they have (~14 million). In reality, many people have overlapping relatives with other people, so many more than 10,000 accounts would have needed to be attacked, all without 23andMe noticing anything suspicious. This seems very unlikely to me. And while 23andMe claims that a credential stuffing attack was at the root cause of this leak, the hacker(s) who first posted about this leak on Hydra Market over 2 months ago claim that they simply used (abused?) an API that 23andMe offered to their academic and research collaborators. The hacker(s) claimed to have 300TB of data, including raw data, but have not proven that the scope of the attack was that large. But if their claim is true, then the breach was definitely not due to a credential stuffing attack, but fits well with the hacker(s) claim of using an API. So, if the extent is as claimed by the attacker(s), then it is much more likely that one of 23andMe's API was used to scrape everyone's data, not a credential stuffing attack. Either one of their collaborating researchers got hacked, or they had (have!?) an access control vulnerability in their API which allowed the attacker to again scrape everyone's data. I cannot find much information about the API 23andMe offers, but I did find one on RapidAPI (https://rapidapi.com/23andme/api/23andme https://rapidapi.com/23andme/api/23andme), and indeed if there was some sort of access control vulnerability or some sort of hack of an escalated user then with even 1 individual as a starting point, they could download the data using various endpoints (there's even an endpoint for the entire individual's genome...) and then get the relatives of that individual (an endpoint for that too) and then recursively do the same for all relatives until every person has been downloaded once. At this point in time, I am highly suspicious of 23andMe's defense but until the attacker releases proof that they have raw data we can't really prove that they're wrong/lying about the actual magnitude of the attack. But I do believe their claim of using an API makes a lot more sense than the way 23andMe proposed, so I am very worried.
- gosub100 3y ago> and then get the relatives of that individual so you're saying they used a genetic algorithm ? sorry, couldn't resist.
- deleted 3y ago[deleted]
- lanewinfield 3y agoHow are you verifying you were in the leak?
- backtoyoujim 3y agoWhat's crazy is that onlyfans content creators get so much slack for sending out video and audio of their phenotype. 23andMe grabs a person by the source code and somehow that isn't considered obscene.