35 ms·
23andMe updates their TOS to force binding arbitration
- consumer451 3y agoMy mother innocently used this service, and filled out the form identifying all relatives by name. The results she received were entirely unenlightening, 50% of my DNA is now in their sketchy database, and I have no way to opt-out of anything. I truly despise this organization.
- hsbauauvhabzb 3y agoI fully agree with everything you say, but until legislation is enforced you can hardly blame a company for capitalizing on the lack of privacy laws (you can still hate them). Point is, start demanding legislation around data privacy and security to anyone who will listen.
- marginalia_nu 3y agoYou can absolutely blame a company for unethical but legal actions.
- hsbauauvhabzb 3y agoExactly what will that achieve?
- marginalia_nu 3y agoIf you drink a cup of coffee and say "this is too hot for me!", what will that accomplish? Nothing, as it's a judgement and not an action. We may act on a judgement though, let the coffee cool down, or avoid dealing with the unethical company.
- hsbauauvhabzb 3y agoBut you avoiding the company doesn’t prevent the company from infringing on your dna privacy if a family member submits theirs. My point is, until legislation changes, it will get worse before it gets better and misdirected anger won’t achieve a valuable outcome.
- consumer451 3y agoI feel like I can blame the humans involved with 23andMe specifically, as they are the specific humans who allowed unknown 3rd parties to have enough of my DNA to profile my family and myself. However, I entirely agree with your last statement. I would like to call upon anyone who appreciates privacy to get behind a neural bill of rights. While it sounds a bit "tin foil hat" at the moment, non-invasive brain–computer interfaces are coming very soon. Especially using infrared techniques. Today, TSA scans your face, soon enough it will be your brain. This is not a joke. If the USA misses the boat on regulating neural interfaces, we will sail through the final frontier of personal privacy, and even agency. I highly recommend that everyone listens to, or reads the transcript of Sean Carroll's podcast with Nina Farahany on the topic. It is dense with legal and technical information. "Nita Farahany on Ethics, Law, and Neurotechnology" https://www.preposterousuniverse.com/podcast/2023/03/13/229-nita-farahany-on-ethics-law-and-neurotechnology/ https://www.preposterousuniverse.com/podcast/2023/03/13/229-...
- gorgoiler 3y agoBy “unknown third parties” do you mean the hackers? The breach was bad but not that bad — it didn’t include your genetic material. > The stolen data included the person’s name, birth year, relationship labels, the percentage of DNA shared with relatives, ancestry reports and self-reported location. https://techcrunch.com/2023/12/04/23andme-confirms-hackers-stole-ancestry-data-on-6-9-million-users/ https://techcrunch.com/2023/12/04/23andme-confirms-hackers-s...
- consumer451 3y agoI meant 23andMe partners, and yes, also the hack, and future hacks. This DB is a goldmine and I take an extremely pessimistic view on infosec. Information wants to be "free" after all. Look at the KSA agents who were implanted at Twitter as an example. I would have to assume that nation state actors would also implant employees at 23andMe. The publicized hack is the one we, and 23andMe, know about. It's just too juicy a target to keep safely guarded in perpetuity. Simply by compiling this information, you are more or less guaranteeing it falling into the wrong hands eventually. This is an example of information which never should have been compiled.
- thrtythreeforty 3y agoThere's no law against being a dirtbag but I am definitely still going to blame you for being a dirtbag. You could always choose... not to be a dirtbag. I would rephrase your point, "don't be surprised when a company capitalizes on lack of laws" -- this I agree with. It's virtually a force of nature.
- dudul 3y agoWhat does "innocently" mean in this context?
- jen20 3y agoI'd assume: "with the understanding of a layman who believes the marketing claims they make without understanding the problems inherent".
- deleted 3y ago[deleted]
- consumer451 3y agoMeaning that she was over 70, and just wanted to learn some ambiguously defined information about her family history. There were some unknowns as far as where her great-grandparents came from. Maybe "naively" would be a better term. We are all law abiding citizens, what do we have to hide, right? Well, she did not read the T&C as far as how this information would be shared, and did not consider the implications of how she was making a choice for the people who she named on the family form, and did not consider the inevitable infosec implications which we are now all enjoying.
- deleted 3y ago[deleted]
- pokstad 3y agoSue your mother
- anon35 3y agoThis 2021 New Yorker article: How Your Family Tree Could Catch a Killer (https://www.newyorker.com/magazine/2021/11/22/how-your-family-tree-could-catch-a-killer https://www.newyorker.com/magazine/2021/11/22/how-your-famil...) was incredibly illuminating and changed my perspective on our sense of privacy. With a surprisingly small fraction of the world's population sequenced, we can still match a sample to a person whose sequence we don't have. To quote the article: "Genetic genealogy, it turned out, could function as an all-purpose de-anonymizer". So perhaps be less upset that Mom signed up; our DNA really isn't ours in the same way the documents on our hard drive. You were never going to be able to opt-out.
- throwoutway 3y agoAnd now a nation state hacker can use the same database to identify U.S. citizen descendants (to what generation?). Good luck with "illegals" style espionage
- CuriousCosmic 3y agoOr you know just a normal hacker (see this incident when a DB identifying 1 million people with Ashkenazi jewish ancestry from 23andMe data was leaked: https://www.bleepingcomputer.com/news/security/genetics-firm-23andme-says-user-data-stolen-in-credential-stuffing-attack/ https://www.bleepingcomputer.com/news/security/genetics-firm...)
- jacquesm 3y agoThey just had to have that data eh? Idiots. This is criminally irresponsible. This makes me so angry it is hard to describe.
- consumer451 3y agoThis feels like a "think of the children" type of appeal. I personally don't have any murderous history to hide. But there are unintended consequences with all of these losses of privacy. As a peer comment has rightly pointed out, nation state adversaries now have these same profiles. Maybe they can find a common DNA profile for an efficient bio-weapon. Oops. I escaped an authoritarian regime as a child, thanks to the same mother. I hold no ill will towards her, but I am deeply aware of the issues that bad actors can create with by compiling huge databases of otherwise unnecessary information.
- epistasis 3y ago23andMe claims that no DNA information was revealed, and I'm having trouble finding a primary source that claims that the SNP info was taken. From a more detailed article: > ... which exposed sensitive personal information that included things relevant to ancestry trees, birthdays and general geographic locations. In some cases, the company said that the hack could have exposed the pictures and display names of affiliated family members also using the company’s services through the accounts that were primarily breached. 23andMe insists that no actual genetic material or DNA records were exposed > ... A 23andMe spokesperson told Engadget that hackers accessed the DNAR profiles of roughly 5.5 million customers this way, plus Family Tree profile information from 1.4 million DNA Relative participants. >DNAR Profiles contain sensitive details including self-reported information like display names and locations, as well as shared DNA percentages for DNA Relatives matches, family names, predicted relationships and ancestry reports. Family Tree profiles contain display names and relationship labels, plus other information that a user may choose to add, including birth year and location. When the breach was first revealed in October, the company said its investigation “found that no genetic testing results have been leaked.” https://www.engadget.com/23andme-hack-now-estimated-to-affect-over-half-of-customers-165314743.html https://www.engadget.com/23andme-hack-now-estimated-to-affec... Presumably the journalist at Stackdiary translated "DNAR profile" into "genetic profile," which is a term with no standard definition, but if it had one, I would have guessed it would mean at least some DNA info. 23andMe could be lying or ignorant of what happened, but that would also mean that there would also be another news cycle when further disclosure was mandated.
- lsllc 3y agoPerhaps you can file a DMCA takedown with 23andMe for the illegal copying of your proprietary code (instigated by your mother!).
- blindriver 3y agoTo make you feel better, it doesn't have to be your mother to identify you. If a cousin were to have done it, you would still be easily identifiable. Basically anyone in your blood line using any of the services would make you easily identifiable.
- m463 3y agoMaybe you CAN ask for deletion.
- vintermann 3y agoThe worst is the classic social media tactic of using user-submitted data to attract others. Imagine there came a responsible DNA service tomorrow, which used differential cryptography or something, so that you could share DNA and look for relatives with some semblance of privacy. They wouldn't get off the ground, because your relatives? They're on this service, or Ancestry or MyHeritage or FamilyTreeDNA, which are every inch as sleazy, US or Israeli megacorporations which you can trust as far as you can throw them (which isn't an inch).
- deleted 3y ago[deleted]
- orbz 3y ago“… encourage a prompt resolution of any disputes and to streamline arbitration proceedings where multiple similar claims are filed“ Someone’s getting ready for some fallout from data leaks.
- LispSporks22 3y agoHeh they are really having it both ways!
- mindvirus 3y ago"If you have not notified us... you will be deemed to have agreed..." Is changing the terms of a service agreement with no confirmation/acceptance from the user even legal or enforceable?
- ellisv 3y agoYes, companies do it all the time.
- nerdponx 3y agoThat doesn't mean it's legal or enforceable, that just means they do it all the time.
- amethyst 3y agoPart of the initial terms of service that you agree to is that the terms can be changed by the company at any time as long as they give you X days of notice.
- 1letterunixname 3y agoIANAL, but I believe it works the same way to say physical property. If you don't "defend" it by objecting to it or putting up fences, and let people move in or say they are changing things, it's effectively qui tacet consentire videtur (silence gives consent).
- justinpombrio 3y ago
- deckeraa 3y agoThe more TOS I read through, the more it seems we need a "common law" solution. (I use the term "common law" loosely here) Something like a couple of pre-defined categories for software services (e.g. info provider, social network, real-world interface) with pre-set rules (e.g. the client cannot attempt to break the social network; the owner of the social network cannot re-sell data to a third party). We have something like this for brick'n'mortar retail already -- each store can't just make up their own rules but rather has to operate within a societal framework. The system we have right now leads to every corporation being incentivized to claim as much legal ground as possible in the TOS, leading to a de-facto corpo-state. It also undermines the rule of law in a cultural sense since many things in the TOS may be deemed unenforceable when actually challenged in court. The users will always be is a several disadvantageous bargaining position.
- ronsor 3y agoTerms of service and end-user license agreements essentially serve more as private legislation than an actually negotiated contract.
- squirrel6 3y agoWell stated. The only reason it’s not actually legislated is probably because this was just the path of least resistance.
- gen220 3y agoIt's difficult because digital ToS are so tightly tailored to your business, and digital businesses are so malleable and formless. If you went through the effort to standardize your ToS, it would only be "useful" to a tiny handful of businesses at specific points in their growth trajectory. Regulations like GDPR are a top-down approach to the privacy component of a Terms of Service (i.e. there are only so many variations to the privacy sections within a ToS that comply with GDPR), but there are so many more components than just customer data locality. That being said, as a privacy-respecting entrepreneur, coming up with a "user-respecting" (i.e. win/win, legible, minimally-demanding/withholding) ToS is a sizable challenge. It'd be nice to have templates. I basically resort to reading the ToS of companies I respect in similar verticals.
- owlninja 3y agoSo would it be wise to opt-out?
- toomuchtodo 3y agoIt costs nothing to preserve you rights. To opt out, email legal@23andme.com notice you do not agree to arbitration.
- cebert 3y agoWhat benefit would you get out of doing that?
- postalrat 3y agoI'd assume you are able to sue them through court.
- toomuchtodo 3y agoThe ability to join a class action. You may get very little or nothing, but litigators will extract for 23andme’s data security failures. Private actions fill a gap when regulators and statute are inadequate. If there is no cost, business as usual continues. (I have opted out and intend to join a class action; I also own customer IAM in my day job, and am aware of the effort that would’ve prevented the root cause)
- spondyl 3y agoThere is perhaps one upside. As it turns out, when binding arbitrarion is forced, those very same companies can't handle the caseloads that come with thousands of cases being filed individually so it can be a bit of a footgun https://www.nytimes.com/2020/04/06/business/arbitration-overload.html https://www.nytimes.com/2020/04/06/business/arbitration-over...
- AlexandrB 3y agoSeems the law critters at 23andMe have thought of that. From the Ars Technica coverage[1]: > The updated terms also explain a new process for mass arbitration. This requires that "if 25 or more demands for arbitration are filed relating to the same or similar subject matter and sharing common issues of law or fact, and counsel for the parties submitting the demands are the same or coordinated," this "will constitute a 'Mass Arbitration.'" Any mass arbitration dispute will be settled by the National Arbitration and Mediation, "a nationally recognized arbitration provider." [1] https://arstechnica.com/tech-policy/2023/12/23andme-changes-arbitration-terms-after-hack-impacting-millions/ https://arstechnica.com/tech-policy/2023/12/23andme-changes-...
- 4death4 3y agoHave terms of service ever successfully been challenged for failing to meet the requirements of a contract? Like if I make an Uber account for my mom, and she uses it, at what point is she bound by the ToS?
- guntars 3y agoNot that I'm aware, but happy to stand corrected. They pretend they are enforceable, we pretend to abide by them.
- mminer237 3y agoOrdinarily, ToS do meet all the requirements of a contract. Both sides assent to certain promises. They make an offer of the terms and you accept it by checking the box or whatever like they ask. That's what a contract is: https://matthewminer.name/law/outlines/1L/1st+Semester/LAW+505-002+%E2%80%93+Contracts+I/#assent-1 https://matthewminer.name/law/outlines/1L/1st+Semester/LAW+5... Even where you don't make the account, a court would assumedly find she agreed to the contract by virtue of quantum meruit by consenting to have you make it and her continuing to use the account. If you sign your mom up for a credit card in her name, what makes her have to repay the debt if she uses it?
- neilv 3y agoRegardless of TOS, relatives who never agreed to the TOS may still have standing. Will some non-TOS-signing relative who was impacted by the data breach lead a trillion-dollar class action suit? (Class action, with the goal of putting a healthy fear of the public into abuse-inclined industry. Not the class action goal of letting a misbehaving company pay off liability with a small percentage of their gains from misbehavior, in exchange for making a few lawyers wealthy.)
- catchnear4321 3y agodo note you can and should send a response that says “no.” then you get to keep the existing terms, which are likely slightly better. hence the hoop through which you must jump.
- metadat 3y agoSubmit your request here: https://customercare.23andme.com/hc/en-us/requests/new https://customercare.23andme.com/hc/en-us/requests/new The email that sent the ToS update message is a do-not-reply address.
- deleted 3y ago[deleted]
- RyanShook 3y agoTo: arbitrationoptout@23andme.com Subject: Request to Opt-Out of Updated TOS 23andMe Team, I am contacting you regarding the recent changes to the 23andMe Terms of Service, dated November 30, 2023. My name is [your name as registered with 23andMe], and the email associated with my 23andMe account is [your 23andMe account email]. I hereby formally request to opt out of the newly updated Terms of Service. I do not consent to the terms as outlined in the recent update. Thank you for processing my request promptly. [Your Name]
- guiambros 3y agoWhere did you get the arbitrationoptout@23andme from? The email I get says to "please notify us", and the link is a mail-to legal@23andme.com. That's the email I used yesterday to say I do not agree with the new terms.
- tropdrop 3y agoThe article points out that the mass-sent email used a different email address than that of the ToS. arbitrationoptout@23andme is the email in the ToS. Jury is out whether this hyperlink mix-up was intentional...
- throwaway2037 3y agoConfirm here: https://www.theverge.com/2023/12/6/23991132/warning-23andmes-new-terms-of-service-include-a-class-action-waiver-and-forced-arbitration https://www.theverge.com/2023/12/6/23991132/warning-23andmes... 23andMe is only giving users 30 days from when they receive the email to opt out of the new policy, which you can do by contacting arbitrationoptout@23andme.com.
- heliodor 3y agoThere are two processes at play: - refuse the updated terms of service - refuse the arbitration The previous version of the TOS had arbitration too, so I'm not sure what all the stink is about. Both versions tell you that you have 30 days to opt out of arbitration by emailing arbitrationoptout@... As usual, the journalists failed at the job and are spreading misinformation. Current version: https://www.23andme.com/legal/terms-of-service/full-version/ https://www.23andme.com/legal/terms-of-service/full-version/ Previous version linked at the bottom: https://www.23andme.com/legal/terms-of-service/full-version/4.1/ https://www.23andme.com/legal/terms-of-service/full-version/... Go to both and search for arbitrationoptout@ and you'll see they both have the 30-day opt-out.
- whatshisface 3y agoThere is no way the courts will uphold this scheme where you sign away your right to go to court through inaction.
- lostdog 3y agoYou are completely wrong. The courts encourage this. Specifically, Republican appointees to the supreme court favor arbitration, because it is better for corporations.
- CrendKing 3y agoWhat prevents 23andMe from simply deleting the opt-out emails they receive and claiming they never received anything, in case someone did sue them?
- houston_Euler 3y agoWouldn't the sender have a time-stamped copy?
- justneedaname 3y ago2 Generals problem
- lcnPylGDnU4H9OF 3y agoCourts aren't dumb, though. It's a lot harder for an average person to fake something in their gmail outbox than it is for someone working for a corporation to delete emails from an inbox. Google could also possibly be sent a subpoena.
- mminer237 3y agoThe sender could simply show in his outbox that he did send such and 23andMe would be in even worse legal trouble then?
- CrendKing 3y agoI asked because unlike paper mail where the deliverer is one trust-able government/commercial body, email by its distributed nature is delivered by hosts everywhere in the internet. How does plaintiff generally gather evidence to prove the email was indeed delivered in these cases?
- dbg31415 3y agohttps://www.gsb.stanford.edu/insights/why-binding-arbitration-game-rigged-against-customers https://www.gsb.stanford.edu/insights/why-binding-arbitratio...
- Kye 3y agoRemember to change your DNA and enable 2FA on all your cells.
- 1letterunixname 3y agoI roll my genes every 3 months and use 4FA.
- dreamcompiler 3y agoPeople who are not 23andMe customers might nevertheless be harmed by these breaches due to the peculiar nature of DNA data, and they could conceivably sue without being bound by any TOS.
- Obscurity4340 3y agoIs there an actually privacy-respectful genome service like this or is 23&me literally the only game in town(the world)?
- xbar 3y agoThere is not any privacy-respectful business that won't eventually be acquired by private equity and squeezed for every just-this-side-of-legal dollar they can get. Don't give away your genetic information if you can avoid it.
- Ephil012 3y agoYour best bet is probably to go through a doctor and get testing from a medical genome sequencing service that is covered under HIPAA. I am not 100% sure if this is bulletproof, but it is probably better than going through a DTC company. Plus, most DTC companies like 23 and me use imprecise genome sequencing and not full genome sequencing like many medical providers do.
- Obscurity4340 3y agoSo 23&me isn't even like the gold standard re:genomic analysis/testing? They're basically just the Dell of testing?
- kornhole 3y agoYou have to go through all of this and give away your body's code to corps and governments just to learn maybe your grandparents were from some part of the world?
- robomartin 3y agoI can’t count the times I have advised friends and family against using certain products and services, only to be ignored or be accused of being paranoid. In some cases the response is “well, you can already find anything about anyone on the internet” or “they already have everything”, etc. It’s incredibly frustrating to watch some of these highly consequential breaches happen. I have yet to have someone come back to me to say “You know, you were right. I am sure many/most HN readers have come across this to varying degrees. Not sure there’s a fix. The only people who eventually get it are those who are unlucky enough to eventually suffer the consequences of their lack of interest in privacy and data safety.
- throwaway2037 3y agoCan someone please confirm: Is forced binding arbitrage allowed in EU/EEA/EFTA? If no, what happens if you are a customer from France or Germany? It seems like this contract is totally unenforceable! A bit deeper, I really wish it was illegal to create intentionally unenforceable contracts. Too many companies create these incredibly scary contracts that no mortal human can understand, let alone know if unenforceable.
- bux93 3y agoNo, not if the customer is a individual ("consumer"). Directive 2013/11/EU, article 10 states "Member States shall ensure that an agreement between a consumer and a trader to submit complaints to an ADR entity is not binding on the consumer if it was concluded before the dispute has materialised and if it has the effect of depriving the consumer of his right to bring an action before the courts for the settlement of the dispute." https://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:L:2013:165:0063:0079:EN:PDF https://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:L:... This does not preclude the customer signing away their rights after the dispute arose, as part of a settlement agreement for instance.
- acatton 3y agoNot only if you're a consumer. There are multiple cases in Germany of Oberlandesgerichten (~= "Circuit courts") voiding arbitration clauses in B2B contracts as well. Subway (the sandwich chain) is a good example of that. They were kinda screwing their franchisees and were forcing them to do arbitration in NYC, even for German franchisees. This was voided by the northern German "circuit court"[1] [1] https://www.omsels.info/wp-content/uploads/OLG-Schleswig-Urteil-vom-26.-September-2013-16-U-Kart-49-13.pdf https://www.omsels.info/wp-content/uploads/OLG-Schleswig-Urt...
- deleted 3y ago[deleted]
- sofixa 3y ago> what happens if you are a customer from France There are no French customers of 23andme because non-court ordered DNA tests are illegal here.
- clwg 3y agoSociety and lawmakers need to update the TOS and legislate these companies out of existence and their databases need to be wiped. Privacy laws really need to be updated for both collection against individuals as well as taking into account what the aggregate data represents.
- nicman23 3y agoi wanna see them try
- Taranis 3y agoHow is it, that after the fact (the hack), can the TOS be changed to mitigate damages from their lack of security? If this is the case, why worry about security then if all we need to do is change the TOS after the fact. No, I suspect a good lawyer or two can challenge this.
- unixhero 3y agoIt is not strange to have binding arbitration instead of court, in the choice of law clause and dispute resolution clause.
- rvba 3y agoHow is this sfuff even legal? Retroactive change of contract?
- lordfrito 3y agoHow do unilateral TOS changes like this work in practice? If the previous TOS didn't force binding arbitration, can they unilaterally impose this change on existing users? Basically forcing existing users to "agree" to this? What recourse do existing users have? I don't use / won't use 23andMe, because of issues like this (the nature of the relationship changing unilaterally). I don't like sharing private data, nothing is more private than my DNA.
- momento 3y agoThey sent out an email saying you can disagree to the TOS. I wonder what would happen if you did.
- dutchbrit 3y ago“ If you do not notify us within 30 days, you will be deemed to have agreed to the new terms.” - surely this wouldn’t hold up in court?
- jvanderbot 3y agoJust to share a positive from 23andMe, given all the bad press around here. I got on this service a couple years ago. I am adopted and had spent a long time trying to track down one side of my biological family. I had very little to go on other than a first name and general whereabouts 40+ years ago. As it became more popular, I had half siblings and, eventually, my biological father reach out to connect. Its been great knowing I have that connection finally. We're planning to meet soon. This is a huge benefit of this kind of "opt in" service, but I recognize how devastating it might be if someone was concealing my existence for, say, religious reasons and a data leak or loose privacy settings from a common relative revealed something. It's a nuanced issue, but my experience has been immensely positive in that it gave me something I may never have had.
- TheRealDunkirk 3y agoThanks for reminding me that I needed to cancel my account. I should have done it years ago when they announced they were being bought out by private equity, and before the inevitable security breaches. Oh well, better late than never, I guess. And, before the "why did you ever do this?!" replies, my wife really wanted to do it, all the way back when they first started, and I relented. Our common 0.3% "sub-Saharan African" results is still a running joke.
- eadler 3y agoIn case anyone is interested I've been compiling as much factual information on arbitration here. Not yet complete but reasonably useful and well sourced https://grimreaper.github.io/arbitration/docs/problems/ https://grimreaper.github.io/arbitration/docs/problems/
- newsnotfound 3y ago[dead]