28 ms·
23andMe changed its terms of service to prevent hacked customers from suing
- henry2023 3y agoAbout 5 or 6 years ago, I thought about sequencing my DNA with them. I'm glad I didn't seriously consider it or actually go through with it.
- benchtobedside 3y agoWorth noting that 23andMe, plus many other low cost genealogy/health-focused companies do not sequence your DNA. Instead, they perform what is called a genotyping microarray test, which looks at less than 0.1% of your genome. To quote from 23andMe: "In order to be genotyped, the amplified DNA is “cut” into smaller pieces, which are then applied to our DNA chip (also known as a microarray), a small glass slide with millions of microscopic “beads” on its surface. Each bead is attached to a “probe," a bit of DNA that matches one of the genetic variants that we test. The cut pieces of your DNA stick to the matching DNA probes. A fluorescent label on each probe identifies which version of that genetic variant your DNA corresponds to." Source: https://customercare.23andme.com/hc/en-us/articles/227968028-How-23andMe-Personal-Genetic-Service-Works https://customercare.23andme.com/hc/en-us/articles/227968028...
- pkilgore 3y agoExporting raw genetic data is conveniently "temporarily unavailable" at the time time this bullshit is happening, which is something I'm almost certain discovery would prove is an intentional choice by them.
- stuaxo 3y agoWill this work I wonder ?
- JohannesH 3y agoI don't know if this is the case or not, but surely this should not hinder legal action on anything that happened before the TOS changed right?
- adocomplete 3y agoThanks for sharing. Will def opt out and roll into the class action suits already filed. Take security seriously people. Especially when dealing with super sensitive data.
- brianwawok 3y agoWhy did you send them your DNA? It was pretty obvious from day 1 that sending some random startup on the internet my DNA was a bad move.
- mauvehaus 3y agoNot everyone opted in as such. My wife has an identical twin who sent in a test.
- 6177c40f 3y agoNo, I don't think that that's obvious. At least in the US, there are already protections for genetic information (including but not limited to GINA [1]). In the long run, I think keeping your genetic information private will be untenable- the potential benefits will outweigh the drawbacks. Plus, anyone sufficiently motivated could get your DNA somehow, you shed your DNA everywhere you go, no getting around that. So what's left is to urge your representatives to maintain and strengthen regulations on how that information can be used, and in the long run we'll just have to trust that that will be enough. [1] https://en.wikipedia.org/wiki/Genetic_Information_Nondiscrimination_Act https://en.wikipedia.org/wiki/Genetic_Information_Nondiscrim...
- skilled 3y agoThe article doesn't add anything new from previous discussion, 23andMe updates their TOS to force binding arbitration (https://news.ycombinator.com/item?id=38551890 https://news.ycombinator.com/item?id=38551890) - (372 points | 6 days ago | 243 comments) One interesting thing about this story though is that it appears that 23andMe is outright refusing to make a comment to anyone. Every single site that has covered the story and bothered to email them have added a, "23andMe has declined to comment" disclaimer. Pretty scummy.
- kelthan 3y agoYes, from the perspective of any user/consumer of the service. But since they are facing litigation, any lawyer will tell you that keeping your mouth shut until the action is adjudicated is THE best course of action, regardless of what some politicians and corporations may do these days. The only other thing that they could say would be "We do not comment on matters involving pending litigation." But that's just a longer way of saying "No comment." It's not any more satisfying for the customers or partners understandably seeking answers to what happened, how, and why.
- aeurielesn 3y agoI don't understand how this is even legal but it has been widespread adopted without a backlash.
- scottLobster 3y agoThe older I get, the more I learn that "legal" doesn't mean what's on the books, it means what some entity cares to enforce.
- Maxion 3y agoAnd because court cases are so expensive, what really matters is who has more money to spend on lawyers.
- mrkramer 3y agoI'm not a lawyer but I doubt that this will matter in the court because the time of actions matter; or in another words at the time when user registered they agreed to TOS A and later when 23andMe changed their TOS A to TOS B they achieved nothing because you can't unregister users and register them again and force them to agree to the new TOS B. I mean they can ask you to agree to new TOS but you don't have to because TOS is not a law, it is a voluntary legal agreement between a company and a customer. Retroactively enforcing something is not possible not even for the governments e.g. if I pay my corporate tax of let's say 20% in 2023 to the government, government can't say like 5 years later: you know what corporate tax is now 30%, compensate for all the differences in the past.
- onlyrealcuzzo 3y ago> I mean they can ask you to agree to new TOS but you don't have to because TOS is not a law Aren't they forcing you to agree to the new TOS to continue using the product?
- mrkramer 3y agoThen pull out and sue them for maliciously enforcing new TOS. People should collectively sue them.
- freeAgent 3y agoPerhaps, but if someone ignores the email and never logs into or interacts with 23andMe in the meantime, the post hoc change in ToS should have no impact on their ability to join a class action lawsuit.
- corethree 3y agoYou got it wrong. They can throw a big TOS in front of you next time you login. Most users will just accept. Additionally they sent an email out saying that you have 30 days yo tell them you want to "opt out" otherwise by default they assume you accept the new TOS agreement.
- verve 3y agoTo duck out of the new ToS, just write this email to legal@23andme.com-- To Whom It May Concern: My name is [name], and my 23andMe account is under the email [email]. I am writing to declare that I do not agree to the new terms of service at https://www.23andme.com/legal/terms-of-service/ https://www.23andme.com/legal/terms-of-service/.
- bunnyfoofoo 3y agoEmail is arbitrationoptout@23andme.com
- verve 3y agoThe email I got from 23andMe linked me to legal@23andme.com.
- micromacrofoot 3y agosend it to both!
- hughw 3y agolegal@23andme.com rejects my email with the message "Account disabled". So yeah, definitely cc the other address.
- ceejayoz 3y agoYeah, but the actual terms say arbitrationoptout@23andme.com. I wouldn't put it past them to say "ah but you didn't email the right address".
- covercash 3y agoI emailed this one and cc’d the legal@ address just to be sure.
- 3y ago
- kelthan 3y agoAutomatically opting-in customers to a more restrictive TOS is pretty suspect, especially given the timing. IANAL, but I'm pretty sure that a court would not allow that, given that the TOS was changed AFTER the breach and it's pretty clear that the company is trying to avoid legal issues after-the-fact. I would expect the court would evaluate any breach under the TOS that was in effect at the time of the breach, rather than under a new (and arguably suspect one) that was put in place after it, arguably in an attempt to "rewrite history".
- thereddaikon 3y agoAnd just because a TOS says something doesn't mean it will necessarily hold up in court. They aren't law.
- kelthan 3y agoRight. Also, the practice of having a sticker on a shrink-wrapped box of software that read "By opening this package you agree to the Terms of Service contained within", where the TOS was inside the box that you needed to open the package to read, was deemed unenforceable back in the 90's. It's the reason that TOS' are now displayed as a pop-up during installation. Not that many more people actually read them before installing the software, but at least they are given the option to. I suspect that a competent lawyer could fairly easily argue that this "automatic opt-in" is the same thing in a slightly different format.
- dannyw 3y agoFederal Arbitration Act severely, and nearly completely, ties courts hands around throwing out binding arbitrations. Of course, if people don’t accept the new terms, they are still bound by the one ones. But if you don’t opt out…
- kelthan 3y agoBut having the company update a TOS that automatically removes rights from the consumer, after the consumer already agreed to a TOS that didn't previously restrict those rights is likely not going to hold up in court, either. Especially when the TOS changes were made after an event likely to trigger litigation. This isn't a case of a minor change to consumer rights in the TOS like changing who would arbitrate a case. It's a significant restrictive change to the rights of the customer in favor of the company. And it was made after a security breach that affected a huge portion of the companies clients which is likely to trigger lawsuits of the form that the TOS now seeks to restrict. This is clearly a case of attempting to close the barn door after the horse was spotted in the next county over.
- d2049 3y agoI would have presumed that security-minded people, which includes those who work in tech, would not so easily give away their genome, and that most of 23andMe's customers are a slice of the general population. But then I read about things like WorldCoin and that people who go to startup parties jump at the chance to give away scans of their retinas and I'm befuddled. Why would anyone willingly do that?
- xvector 3y agoI am a security engineer. When I signed up for 23andme, I assumed with certainty that it would be hacked and all data leaked at some point. I balanced that with the value of knowing potentially important health/genetic bio markers. In the end, I valued knowing these bio markers above the privacy of my genome. The former is actionable and I can use it to optimize my health and longevity; the latter is of vague value and not terribly exploitable outside of edge-case threat models.
- smarkov 3y agoExactly my thoughts. I'd be more upset if a combination of my name and email/phone number got leaked than if my DNA was made available public.
- tuwtuwtuwtuw 3y agoWhy would you be upset if your name+phone combo was leaked? Mine is all over internet so wonder why you feel it would be bad.
- smarkov 3y agoI simply don't want to deal with spam or scams. If I'm exposing my contact details it would be a separate set that is dedicated to dealing with communication coming from the public.
- themaninthedark 3y ago
- josefritz 3y agoThere is no retcon possible from a TOS update. They're a soft target for a class action lawsuit right now and they know it.
- kryptiskt 3y agoI have a vague recollection that some company fairly recently squirmed when it got tons of arbitration cases. It would be really funny if 23andMe got dragged to the arbitrator a million times.
- nielsbot 3y agoI think there was a general pattern of people striking back against mass forced arbitration by saying "ok, that's fine, we'll all go to arbitration at once". And companies ended up having to foot the bill for hundreds or thousands of arbitration cases... Newer arbitration clauses that I've seen now cover this scenario. Something like "If many identical cases come forward at the same time, you agree to combine your cases in a single arbitration action" Looks like CR wrote about it: https://www.consumerreports.org/money/contracts-arbitration/consumers-using-mass-arbitration-to-fight-corporate-giants-a8232980827/ https://www.consumerreports.org/money/contracts-arbitration/...
- dev1ycan 3y agoI don't feel bad for anyone who sent their dna to a private capitalistic company. It was always obvious this was gonna happen. Especially when these companies paid so much to politicians like Bernie Sanders to appear on their ads to seem "benign".
- JohannesH 3y agoBy that logic no privately owned company would ever be held accountable for anything they did wrong.
- nazgulsenpai 3y agoDo you feel bad for people who had relatives use the service without them knowing, making them party even though they did not consent?
- RIMR 3y ago23andMe thanks you for your lack of sympathy for their victims.
- helsinkiandrew 3y agoForcing customers to use arbitration hasn't always been in the companies interest - if only a fraction of the 7M effected customers started the arbitration process it could cost a lot more than a class action suit. Didn't Uber drivers get a large payment from them in this way? https://www.reuters.com/legal/litigation/uber-loses-appeal-block-92-million-mass-arbitration-fees-2022-04-18/ https://www.reuters.com/legal/litigation/uber-loses-appeal-b...
- kelthan 3y agoTrying or arbitrating a large number of cases individually is far more expensive than litigating a class action suit. But only if the people pushing the arbitration hold firm, rather than agreeing to the initial settlement offering.
- freeAgent 3y agoI once looked into arbitration against a local company based on their ToS. Initiating arbitration would have cost me several hundred dollars, not to mention time, which was more than my dispute was worth.
- zlg_codes 3y agoArbitration almost always favors the company, why else would they push for arbitration instead of respecting your rights?
- someotherperson 3y agoAn alternative take is that they changed their terms of service so that if/when this happens again they'd have more control over the fallout. I think they're totally expecting to get railed for the last one and are preparing for it, but this doesn't mean they can't prepare for the future as well. I imagine other providers will also revise their TOS.
- khana 3y ago[dead]
- tjpnz 3y agoWhich companies offer similar services sans all the bullshit and privacy issues? I'm not interested in finding long lost relatives and even less interested in having my data sold or shared with LEO.
- xlbuttplug2 3y agoI am not familiar with either offering but this was on HN a few days ago: https://news.ycombinator.com/item?id=38578951 https://news.ycombinator.com/item?id=38578951
- emddudley 3y agoI have tried to quickly diff the previous TOS with the new one and I wasn't able to identify any big changes. I would like to know what the actual changes are. I see a lot of articles criticizing the new TOS, but no one is showing the actual wording differences. Does anyone have an actual diff?
- slingnow 3y agoWhy do the actual work when you can just come to the HN comment section and rant about what you think it means!
- e28eta 3y agoComparing: https://www.23andme.com/legal/terms-of-service/full-version/4.1/ https://www.23andme.com/legal/terms-of-service/full-version/... https://www.23andme.com/legal/terms-of-service/full-version/ https://www.23andme.com/legal/terms-of-service/full-version/ two things jump out at me, as a layman: insertion into the middle of Limitation of Liability "WITHIN THE LIMITS ALLOWED BY APPLICABLE LAWS, YOU EXPRESSLY ACKNOWLEDGE AND AGREE THAT 23ANDME SHALL NOT BE LIABLE FOR ANY DAMAGES" Lots of changes to the Dispute Resolution, and new content re: Mass Arbitration. However, the previous ToS still had binding arbitration clauses, and stuff about class actions.
- emddudley 3y agoAh, I really appreciate this. I did not know that the old TOS was available under the /4.1 link. And I like the full-version links! In case the older version goes away, here is the archive.org version from October 25, 2023: https://web.archive.org/web/20231025013949/https://www.23andme.com/legal/terms-of-service/full-version/ https://web.archive.org/web/20231025013949/https://www.23and...
- tokai 3y agoMeh not really binding in the EU, as its not done in good faith and it disadvantage consumers. I see no reason to write them and tell them you don't agree, if you are a EU citizen.
- newsnotfound 3y ago[dead]
- pizzalife 3y agoI interviewed for a security position there a few years ago, but they cut the role before the interview process was over. Kind of feels like they didn't prioritize security - you reap what you sow.
- hmottestad 3y agoCould have been that they found someone internally.
- pizzalife 3y agoCould be, but I've interviewed with dozens of companies and I've never had that experience elsewhere.
- tamimio 3y agoGladly I never used any of these services, not just knowing my ancestors origins will add zero value to my life, but also I don’t trust any cloud services to store my passwords or notes, let alone a biometric I will never be able to change, alive or not.
- TheBlight 3y agoThe slightly annoying thing with this data, though, is that even if you don't provide your data your privacy can be violated via any relatives' data that did decide to use the service.
- FredPret 3y agoReminds me of Paypal that keeps spamming me with Terms of Service update emails. It doesn't exactly build trust.
- SpaceManNabs 3y agoWhat exactly was breached isn't clear... Very worrying
- wly_cdgr 3y ago[flagged]
- eadler 3y agoIn case anyone is interested I've been compiling as much factual information on arbitration here. Not yet complete but reasonably useful and well sourced https://grimreaper.github.io/arbitration/docs/problems/ https://grimreaper.github.io/arbitration/docs/problems/
- ashtronaut 3y agothank you this is really helpful!
- robg 3y agoJust email to say you opt out.
- TheCaptain4815 3y agoI almost laughed out loud when I got the email a few days after the leak. There's no way a company can just change the TOS AFTER a major leak, right?
- dekhn 3y agoyes, companies can change TOS when they want regardless of what happened before, so long as they weren't legally prevented from doing so.
- Fischgericht 3y agoAs someone living in the EU, these kind of things puzzle me a lot. How can a legal system exist, where it's possible to deny a (consumer) contract party access to the legal system and law of the land? (In the EU we do have arbitrations clauses, but they are only legal between businesses and tightly regulated. Arbitration "courts" must be neutral. And you can not put them into ToS.) Also, I was under the impression that all sane legal systems on this planet are based on the broad principle of "pacta sunt servanda" = "agreements must be kept". One party of a contract never can change the contract without consent from the other party. We do have the concept of "silent approval" for consumers over here, too, but that only applies to minor changes to terms that are not a "surprising" change to the consumer. It recently was ruled that for example Netflix increasing prices without active consent is not legal in the EU. There is not much that is not regarded as "surprising" by courts here. "You are not allowed to sue us after having lost your personal data, then lying about it" clearly would be regarded as surprising. Im summary: Every aspect of that whole 23andMe story would be impossible in the EU. The amount of data they collected, the way they stored it, the way they tried to hide the breach, and them trying to prevent their customers to get access to the law. I wonder how on earth the US legal system could deteriorate so much that such a story becomes possible. [Disclaimer: I am not bragging about living in the EU. I did not have any influence on my place of birth. I do not wish to imply that the EU is "superior" to the US. I am just trying to give an outside perspective.]
- deleted 3y ago[deleted]
- pyuser583 3y agoThe real issue is that lawyer can “try” anything with almost no consequences. I doubt this will work. But there’s “no harm in trying.”
- Fischgericht 3y agoOver here there are "consumer associations" that have the right to sue in such cases in the name of all consumers. That works quite well. Due to this traditionally those things are not even tried. That has changed with (mostly US) businesses entering the EU. A good example is booking.com, who again and again and again invented new dark patterns to then get sued for it, making it clear those are illegal. We had the same with the airline industry with their advertised prices not matching the actual final price with all taxes and made-up fees. But by now even Ryanair has given up and no longer tries those tactics. But there are no big financial penalties for losing such cases in court. I guess it's the bad PR these court cases generate every time that makes those businesses after a while giving up trying to screw over consumers...
- jakedata 3y ago23andMe would like to point out that hackers already have access to 99.9% of your DNA right now. That means they are at most only 0.1% at fault for anything else.
- lowbloodsugar 3y agoOk, but where is the class action?
- jbombadil 3y agoI honestly don't understand how "If you don't opt out within 30 days you'll be bound to the new TOS" works. I have heard of two big "trends" of how people think about legal contracts: [1] What is written there and what both parties agreed to is the truth. [2] A contract is supposed to be a "meeting of the minds". If it's proven that one party was being deceitful, then the contract (or that part) doesn't hold. If we go by [1], then the company can change the TOS by sending me a notice with "if you don't opt out, then you're bound by these terms"... but so should I. I should be able to send a letter to 23&me saying "if you don't disagree these are the new terms: if my information is ever hacked, you owe me 10M dollars in damages" If we go by [2], then sending a notice like that is absolutely invalid. They have no way of proving that I read that notice within 30 days, so there was never a "meeting of the minds".
- lolinder 3y agoThe theory is that you start the contract with the terms specifying that changes put forward by the company (but not the user) are automatically accepted with 30 days' notice. That's where the meeting of the minds occurs: in theory, from that point on, you've agreed that the terms can change. However, I'm not sure if that's ever been tested in court as a valid theory, and regardless it certainly shouldn't be legal (any more than noncompetes).
- deegles 3y agoI got downvoted in another thread for suggesting that a company might do exactly this
- master_crab 3y agoI’ll give you a upvote if you link it!
- theGnuMe 3y agoHuge HIPPA violation as well.
- deathanatos 3y ago> Huge HIPPA violation as well. It's HIPAA. IANAL: And unless 23andMe meets the HIPAA definition of a "covered entity", which I'm not sure they do, they're not going to be covered by HIPAA.
- theGnuMe 3y agoRight but the hackers are not covered entities.
- deathanatos 3y agoThat's not how HIPAA works. 23andme would be, or would not be, the covered entity, and the entity bound by HIPAA.
- theGnuMe 3y agoI dunno, they offer blood tests ordered by a clinician. That probably creates a covered entity.. then the hackers get the phi data, they for sure do not have a business associates agreement with 23andme. May only matter for the blood draws.
- hsuduebc2 3y agoExactly.this behavior is why I never gonna send my DNA to any of these services. Certainly not US. I hope than EU will have some regulations for this soon.
- bulbosaur123 3y agoAs a customer from EU who has been affected by this, how do I sue them? Can I join the class action? Didn't use ancestry feature, but from what I understood my data has been leaked as well.
- Imnimo 3y agoWell at least, 23andMe promises that it also can't participate in a class-action lawsuit against me. So that's pretty fair.
- WalterBright 3y ago"reports revealing that attackers accessed personal information of nearly 7 million people — half of the company’s user base — in an October hack." Breaking into a system should never provide access to 7 million people. The database should be divided up into multiple "cells" each with its own separate access restrictions. It's the same idea that spy networks use to prevent one compromised spy from bringing down the whole system. Or you can think of it like watertight compartments in a battleship.
- hmottestad 3y agoWhat if you want to run a query to compare your DNA to everyone else’s to see if you have any relatives that are registered already? Wouldn’t that need access to the entire database and essentially be a point of weakness?
- WalterBright 3y agoI am no expert on such systems. But it seems to me that the comparisons should only be run within the cells. The caller only passes the one to compare it to, and the only thing that comes back from each cell is any matches. That way, only the specific cell has access to its data.
- hmottestad 3y agoYou might be interested in homomorphic encryption. It allows for mathematical operations on encrypted data. I don't know if any database actually supports it, but it should allow for things like SUM operations on a column of encrypted numbers with a result that is also encrypted.
- TaylorAlexander 3y agoI haven't logged in in years. Is it possible for me to cancel my service without agreeing to updated terms?
- jnsaff2 3y agoSociopaths.
- b800h 3y agoI'm in the UK and I've not received a notification that the terms have changed. Is this because our law is more consumer-friendly?
- 1vuio0pswjnm7 3y ago"In October, the San Francisco-based genetic testing company headed by Anne Wojcicki announced that hackers had accessed sensitive user information including photos, full names, geographical location, information related to ancestry trees, and even names of related family members." For those who do not know, her sister is a longtime Google marketing person since 1999, who worked on AdWords, AdSense, DoubleClick, GoogleAnalytics and the money-losing data collection and advertising subsidiary YouTube. It seems personal data collection for profit runs in the family.
- clwg 3y agoShe was also married to Sergey Brin for 8 years.
- zlg_codes 3y agoI'm getting to a point where I automatically assume any business is both taking my money and trying to totally fuck other parts of my life behind my back to make more money. If capitalism is so great why is it so incompatible with being a good and honest person?
- alephnan 3y ago> If capitalism is so great why is it so incompatible with being a good and honest person? Capitalism was never about that. It was about having acting in their own self-interest as to maximize economic efficiency. That model works great when you are selling commodities and physical products. Capitalism in the era of personal information as currency is a entirely different beast that needs to be reworked.
- happytiger 3y agoThere’s a word for changing the terms after a deal is signed to benefit one party over the other: fraud.
- skyfaller 3y ago"I am altering the deal. Pray I do not alter it any further."
- happytiger 3y agoI mean, exactly. Don’t know why you’re getting downvoted for this quote. It’s hilarious.
- tacocataco 3y agoThis website prefers dry commentary over meme replies. Not my preference, but it's not my website so I do my best to reel in the clown show.
- stainablesteel 3y agoits insane that a company can just change a tos after you buy their product why can't i be locked into what i chose to purchase?
- hmottestad 3y agoChanges to the consumer law in Norway tries to account for digital services that a product you bought had at the time of purchase and that no longer work. Also where a lack of an update has caused something to not work an expected. The actual ramifications of this are yet to be seen, since the changes come into effect from next year. It will be interesting if this means that apps need to be updated to support new iOS and android versions, or if phones will need to get security updates, or if cloud services must be available, or if a feature can be removed from an app or not.
- gkanai 3y agoWas never interested in this service previously and will never consider them in the future. Did 23andme not expect themselves to be hacked?
- DesiLurker 3y agoThis should be a reminder to DELETE YOUR 23&ME ACCOUNT and destroy the samples asap. God knows who this horrible company will sell all that info to next.
- leemailll 3y agoI don't support this, but I'm surprised they only do this until now.
- gavinhoward 3y agoSo glad I never became a customer of 23andMe. I hope that I would have cause to go after them if they leaked DNA from a relative, and that DNA was used to cause harm to me.
- johndhi 3y agoI'm a lawyer. Some of the assertions here are a bit extreme, as is the headline, imo. The company can add a class waiver to its terms when it wants to. Whether it's enforceable against people who have a claim predating the terms update will be an interesting legal issue to debate. But let's not call them the devil.
- 1vuio0pswjnm7 3y ago23andMe DNA kits make great x-mas gifts. 50% off!