6 ms·
DNA testing company vanishes along with its customers' genetic data
- alsetmusic 2y agoThis sort of thing was only a matter of time. The clock is also ticking on 23andMe going bankrupt and selling their assets (your PII) to stay afloat. https://hoodline.com/2024/11/23andme-in-turmoil-stock-plunge-and-layoffs-spur-concern-over-fate-of-users-genetic-data/ https://hoodline.com/2024/11/23andme-in-turmoil-stock-plunge...
- akira2501 2y ago> This sort of thing was only a matter of time. In the current single vendor model. An intermediary could accept the samples, blind identities, then provide a "one time" mechanism for retrieving results. Bill Burr's take was pretty good. "What.. I'm going to spit in a tube and mail it into the internet?"
- JumpCrisscross 2y agoYou can download your data from 23andMe and request deletion, FYI.
- fyver 2y agoand hope they're really deleted and not just marked as deleted.
- st-keller 2y agoSad state of affairs - this is so messed up. No trust anywhere! I’m senior Software Architect in Germany and some years ago we built an app that handles highly confidential tax-related data. And we did everything to stick to the highest standards: Strong encryption, distribution of keys and data into different datacenter operated by different companies, protocols of deletion of data, implementing every aspect of DSGVO, including Art.35 - „creation of a DSFA (Assessment Of Consequences of Data Privacy Measures)“ more than 100 pages thick. Guess what: When I tell customers that we cannot read and really delete their data - they straight up accuse me of lying!
- AtlasBarfed 2y agoConsider these statements: - state level actors can basically break into any computer system given enough time - corporate databases have a gigantic amount of information on everyon - states want all of that data I hope the conclusion is as straightforward as it seems to me. OK, not exactly what you are responding about Let's talk about corporate IT systems, let's get into "deleted". Is it: - deleted from backups? Almost universally this answer will be no. - deleted from each and every database and system in your presumably huge corporation, which may involve literally thousands of IT systems? I'd guess no. - is it deleted by moving the data to a separate "deleted data" table or database, thus sequestering the data from the "active data" rather than deleting it, just in case you want to "undo"? - is it deleted from all system logs? - is it deleted from all records systems that may have minimum retention periods legally or by policy? - what about data warehouses or data lakes that repackage/mirror data?
- csomar 2y ago> When I tell customers that we cannot read and really delete their data - they straight up accuse me of lying! I'd accuse you too. If you can't read their data, then the data doesn't exist? Also, if you can't read read their data, how are the customers seeing it on their dashboard?
- st-keller 2y agoI try to explain it shortly: The encrypted data is in a different datacenter than the keys needed to decrypt the data. The services we implemented to bring both together run in an secured environment that has no services implemented to access the servers and where physical access is restricted. Errors and monitoring data gets out, PII does not. Everything is documented and was inspected and certified by a 3rd party. If a customer requests to delete his data we instantly delete the key, a litte later we delete the (already useless) data and all backups will lose this information about a month later too. And of course we did that not because we are nice people (though we belive we are). We did it, because we had the hypothesis that a reputation to handle the user-data with proofable utmost respect to security and privacy would be more valuable than having access to this data. People not believing us or accusing us of lying obviously defy that hypothesis.
- AtlasBarfed 2y agoThe key word in that sentence: "request"
- pvaldes 2y agoIf is a Russian company is no mystery what happened. Sanctions hit the company, closing it.
- ginkgotree 2y agoSaw this coming years ago. 23andme is next.
- yeetusus 2y agotfw all your immediate relatives did the test even after you explicitly told them not to
- waste_monk 2y agoThat's why I swallow a pinch of cobalt-60 every day, to make sure my DNA is unrecognizable to adversaries.
- ashoeafoot 2y agoNo insurance on you and your family
- kylehotchkiss 2y agoWhat an interesting thing to microdose. How’s your productivity on it?
- bossyTeacher 2y agoisn't cobalt-60 radioactive?
- financetechbro 2y agoI believe that is the point
- brikym 2y ago[flagged]
- analog31 2y ago... and from what I can tell, most people just wanted to know their nationality.
- neuronexmachina 2y agoFor reference, the company is Atlas Biomed. I remember seeing their product show up all the time on Amazon (they have a box design that looks kind of like a multicolored QR code).
- gnabgib 2y agoOriginal source: https://www.bbc.com/news/articles/cz7wl7rpndjo https://www.bbc.com/news/articles/cz7wl7rpndjo Submitted with no discussion (11 points) https://news.ycombinator.com/item?id=42096208 https://news.ycombinator.com/item?id=42096208
- dang 2y ago(It's best to only link to these if there are interesting comments there. That's the convention on HN, and we get complaints when people click on the link and there's no there there.) (But links to where there are interesting comments are super valuable, so please don't stop with those!)
- brikym 2y agoYes I'm sure the valuable data has been safely deleted and definitely not sold to data brokers, insurance companies or government agencies.
- ivan_gammel 2y agoLooks still alive, probably just closed their UK branch. https://atlas.ru/about https://atlas.ru/about They are subject to FZ 152, Russian equivalent of GDPR, as well as DNA-specific regulations which AFAIR are more strict. Not sure though if they care about foreign users.