13 ms·
No federal privacy law? After the 23andMe hack, it's time to take action
- andrewstuart 3y agoNo one will take action. Outside Europe privacy isn’t a priority for politicians.
- hollow-moe 3y agoNo, even in Europe they don't care, it's just for pr and the image.
- f233f2 3y ago[flagged]
- LikelyABurner 3y agoIs that why the EU is trying to break my encryption, scan my devices for CSAM, and grab all its visitors' biometric data? To "protect my privacy"? This narrative needs to end. The EU does not care about privacy. They care about making headlines about sticking it to foreign companies.
- WendyTheWillow 3y agoWhat's missing is a catastrophic privacy event. People have been yelling from rooftops about how terrible losing your privacy could be, but the horror stories aren't coming true. There aren't any wide-scale or pervasive negative consequences of a loss of privacy, and there are a lot of immediate positives. An insurer needs to start disqualifying anyone who, I dunno, is shown in Google Maps to be out at bars past 11 PM or something like that. Until you can show the practical problems associated with a lack of privacy, people won't care, and I would even argue that those people aren't entirely unjustified in that belief.
- hanniabu 3y ago> What's missing is a catastrophic privacy event *that directly affect politicians
- supertrope 3y agoThe Video Privacy Protection Act was passed after Supreme Court nominee Robert Bork's VHS rental history was leaked to a newspaper.
- supertrope 3y agoI imagine it would take something like a sympathetic party like a child being identified, located, and murdered using breached data before a "Megan's Law" for data privacy passes.
- adolph 3y agoThey could probably add a cell phone alert to it. I wonder what color they would use? Amber, Silver, Blue and Camo (not certain if Clear counts) are already used: https://www.dps.texas.gov/section/intelligence-counterterrorism/statewide-alert-programs https://www.dps.texas.gov/section/intelligence-counterterror...
- BobaFloutist 3y agoNever trust a law named after a child.
- WendyTheWillow 3y agoNope, as that's basically like being struck by lightning. Needs to be both common and punishing, as that's what the doomsayers are claiming is inevitable.
- BobaFloutist 3y agoWhat's missing is a catastrophic privacy event. People have been yelling from rooftops about how terrible losing your privacy could be, but the horror stories aren't coming true. I would argue that the identification of the Golden State Killer (https://www.latimes.com/california/story/2020-12-08/man-in-the-window https://www.latimes.com/california/story/2020-12-08/man-in-t...) was pretty catastrophic for him. Now in this particular case the magnitude of his crimes make it a little hard to feel bad for him, but once the method is established the only thing we have restricting its replication for more petty crimes is the discretion of law enforcement, and explicit legislation.
- mnd999 3y agoJust be sure to change you DNA if you were impacted by the hack.
- johndhi 3y agoI hope I can sign up for 'clone monitoring'
- supertrope 3y agoCRISPR!
- raverbashing 3y agoIn the same way you change your mother's maiden name in case of breaches I assume
- AlbertCory 3y ago"taking action" is personal: just don't give personal information, like your DNA (!) to anyone. You can't control what your relatives do, unfortunately.
- faeriechangling 3y agoYou can take personal accountability for driving collective change, which is what is required here. 23andMe's business practices should not be legal, they are recklessly endangering the lives of people who have never used their service or agreed to their terms, and the only thing I can see that can stop them is legislation.
- dekhn 3y agoWhat specifically are you going to make illegal?
- teej 3y agoTheir business practice of getting hacked?
- LelouBil 3y agoYou share a lot of DNA with your parents, and your children. If one of them used 23AndMe, now a par of your DNA is with them.
- AlbertCory 3y agoI said, "You can't control what your relatives do, unfortunately."
- faeriechangling 3y agoBusiness practices of not caring about securing the populations genetic information with even basic measures such as enforced two factor authentication and compromising the lives of many innocent non-customers through a basic low-skill attack like credential stuffing. I would straight up say they need to be regulated as a healthcare provider and be subject to the security provisions of HIPAA. That would be a start.
- krunck 3y agoFor the short term if you don't want your data leaked, don't give it away to others. For the long term support research into Homomorphic_encryption.
- deleted 3y ago[deleted]
- TurkishPoptart 3y agoIf a cousin, aunt, or uncle used this service, does that automatically mean my DNA is visible/accessible?
- bee_rider 3y agoI get the need to tie in to a recent big news story for exposure reasons, but I think it would be good to be more explicit about the different problems. We have businesses that are explicitly built on violating privacy. We have businesses provide services that require them to collect some private info. I’d put 23andme in this bucket. We have businesses that have lax security, and actually get their systems broken into. We have businesses that have fine security, but don’t force users to have good, unique passwords and 2FA. 23andme is in this bucket, right? The first, we should be happy to run them out of business, like we should actively write laws that try to destroy them. The third, we should fine them to the point where skimping on security is never a rational decision (and if that runs companies out of business, fine). The second seems not too bad, every medical-field-related service is going to have some private info necessarily (for example), as long as they don’t exploit it that seems fine. The fourth seems not so bad, there are all sorts of services that are not so important. I don’t have 2FA on, like, random forums and video games, who cares? Combining two and four is pretty bad though.
- thfuran 3y ago>every medical-field-related service is going to have some private info necessarily (for example), as long as they don’t exploit it that seems fine. HIPAA is rather stringent, but we don't have anything like that for most other domains where a company might legitimately need confidential information. Instead we have the third party doctrine.
- bee_rider 3y agoYeah the medical field was probably a bad example, because of course HIPAA already exists. But lots of services exist that collect data that somebody might consider private as a necessary side effect of doing their thing.
- thfuran 3y agoBut there's no particular reason or privacy regulation needs to be as narrow in scope as HIPAA.
- robbywashere_ 3y agoGood luck out-lobbying Google and Meta for privacy
- dvngnt_ 3y agousing unique passwords would have prevented this from happening on the user side but I agree with sensitive data 2fa should be mandatory
- pavel_lishin 3y agoI heard one of the users was wearing a very revealing skirt and browsing through a bad neighborhood.
- dvngnt_ 3y agonot really understanding your point in both instances the hacker or the attacker is the responsible one not the victim. but the user in 23 and me could use basic password practices to prevent this form of attack. in the street, there's no clothing that can keep you safe
- faeriechangling 3y agoSome of the users were logging into 23andMe after midnight unaccompanied!
- swarnie 3y agoWasn't it time to take action after the Equifax leak, or the facebook-cambridge leak? Yahoo? Marriott International? Yahoo again somehow? Nothing will change. Its time for people to stop expecting things from their corpo-overlords or the governments they've purchased.
- michaelbuckbee 3y agoI'm aware HN has a dim view of the GDPR, but I previously worked in compliance and it was a sea change in how big corporations and organizations viewed data collection. User PII and especially sensitive data suddenly was viewed as "toxic" and that having it around was something that could only bring them hassle. California's data privacy acts are similar (but much more narrowly focused). Also, I always like to sum up what the intent of these acts typically are and what compliance means: - Tell people what data you're going to collect and, what you do with it, who you share it with - Keep their data reasonably secure - Delete it if they ask
- ryandrake 3y agoUser data should be treated like uranium, not like oil. Both are valuable, but you don't want to just accumulate and store uranium. You want only as much as you absolutely positively need, hold it securely, and then to get rid of it as soon as you don't need it anymore.
- syndicatedjelly 3y agoWhy doesn't this breach constitute some sort of HIPAA violation? I.e. exposure of personally identifiable information
- thfuran 3y agohttps://www.hhs.gov/hipaa/for-professionals/covered-entities/index.html https://www.hhs.gov/hipaa/for-professionals/covered-entities...
- syndicatedjelly 3y agoReading that table, it sounds like 23AndMe should be classified as a Health Care Clearinghouse. I'm assuming they send samples to a lab for processing, and then convert those results into a standardized data format.
- thfuran 3y agoNo, the clearinghouses are middlemen between healthcare providers and health plans. They are a covered entity who deals in processing data for and from other covered entities. I don't think 23andme fits any of the bins. They're just a non-healthcare-related company that ends up with data that would otherwise have only been available to healthcare providers (and the other covered entities they deal with).
- syndicatedjelly 3y agoI see. Sounds like HIPAA was written for a world that no longer exists.
- thfuran 3y agoIt was written with a narrow focus on regulating the healthcare system rather than explicitly and comprehensively protecting a class of data, so it just wasn't meant to impose any restriction on every other party a person might disclose medical information to.
- ilamont 3y agoThank you for calling this what it is - a hack - despite 23andme's strenuous efforts to paint this as the fault of millions of users (see https://blog.23andme.com/articles/addressing-data-security-concerns https://blog.23andme.com/articles/addressing-data-security-c...) rather than owning the vast technical or management failure that allowed this to continue undetected for months. Without the risk of a giant fine or, say, jail time, many tech giants can and do get away with managing their data security badly. That's right. It's happened before, and will continue to happen as long as there are no consequences. Note that 23andMe is not the first online genealogy service to get hacked: - In 2017, MyHeritage had 92 million accounts hacked https://www.hackread.com/dna-testing-website-myheritage-hacked-user-accounts-stolen/ https://www.hackread.com/dna-testing-website-myheritage-hack.... - In 2020, MyHeritage users were targeted in a separate phishing scheme. https://blog.myheritage.com/2020/07/security-alert-malicious-phishing-attempt-detected-possibly-connected-to-gedmatch-breach/ https://blog.myheritage.com/2020/07/security-alert-malicious... - GEDmatch admitted “all user permissions were reset” in a 2020 attack. https://www.buzzfeednews.com/article/peteraldhous/hackers-gedmatch-dna-privacy https://www.buzzfeednews.com/article/peteraldhous/hackers-ge... - Ancestry and Ancestry affiliated companies have had multiple security breaches over the past 10 years (https://www.hackread.com/software-firm-leaks-ancestry-com-user-data/ https://www.hackread.com/software-firm-leaks-ancestry-com-us...) - Ancestry has also destroyed people's archives when it decided it was no longer profitable or important enough to keep them. https://slate.com/technology/2015/04/myfamily-shuttered-ancestry-com-deleted-10-years-of-my-family-history.html https://slate.com/technology/2015/04/myfamily-shuttered-ance... - Last year, FamilySearch belatedly admitted a breach had exposed “users’ full names, genders, email addresses, birth dates, mailing addresses, phone numbers.” https://grahamcluley.com/seven-months-after-it-found-out-familysearch-tells-users-their-personal-data-has-been-breached/ https://grahamcluley.com/seven-months-after-it-found-out-fam... These are incidents that have been made public as required by law. There are surely thousands of other smaller incidents that are not reported, as well as major breaches that the companies themselves don’t even know about yet. And it will continue for years to come until lawsuits or brutal regulations with teeth are enacted.
- jonny_eh 3y agoTo be fair, 23andme wasn't hacked, at least not with the traditional definition. Their users who were reusing passwords got hacked. That said… Should they have required 2FA? Yes. Should they have taken proactive action on behalf of their users when they appeared in "Have I Been Pwned"? Yes.
- Ajay-p 3y agoThe United States is unlikely to have a national privacy law in the foreseeable future due to the extensive lobbying by companies that depend on violating the privacy of its citizens. For the same reasons we are unlikely to have true Net Neutrality, there is too much money opposed to it.
- AequitasOmnibus 3y agoThe United States can’t even carry out basic governmental functions. The House of Representatives is without a speaker going on a month now, and each election cycle is degrading to the point that it may stop functioning properly. We are unfortunately well beyond the point of expecting the legislature to legislate, let alone pass robust beneficial laws.