Remember That DNA You Gave 23andMe?

kinther@lemmy.world to News@lemmy.world – 376 points –
Remember That DNA You Gave 23andMe?
theatlantic.com
109

DNA might contain health information, but unlike a doctor’s office, 23andMe is not bound by the health-privacy law HIPAA. And the company’s privacy policies make clear that in the event of a merger or an acquisition, customer information is a salable asset. 23andMe promises to ask its customers’ permission before using their data for research or targeted advertising, but that doesn’t mean the next boss will do the same. It says so right there in the fine print: The company reserves the right to update its policies at any time. A spokesperson acknowledged to me this week that the company can’t fully guarantee the sanctity of customer data, but said in a statement that “any scenario which impacts our customer's data would need to be carefully considered. We take the privacy and trust of our customers very seriously, and would strive to maintain commitments outlined in our Privacy Statement.”

We take it very seriously, just not as seriously as money.

“I mean, we would have to receive a pretty excellent offer to violate our customers’ privacy—which is super important to us. (We reserve the right to also accept offers ranging from “pretty decent” to “doable,” or in the event of our profits not really getting us hard anymore, we may also accept “any” offer.) Your privacy is very important to us.”

There needs to be government protection of your DNA, but the government probably doesn’t want that

The worst thing is I’ve never consented to them having my DNA but they have half of it anyway thanks to my brother…

My identical twin brother who gave it to them...

That is one of the rare situations where it likely works to your advantage. Any negative thing you do with with your DNA will be pinned on your brother because its his name associated with the DNA you share.

I thought identical twins usually had like a dozen of so diffing mutations by the time they reach adulthood.

I'm not familiar with 23andme enough to know if their markers would pick up on it.

The dna tests they do for criminal investigations aren't that exact. Don't know if they would do the more expensive tests when there are twins involved though.

I remember I didn't and thank fucking god, because this would have been me:

https://www.nbcbayarea.com/news/tech/23andme-user-data-stolen-shkenazi-jewish-users/3336464/

Still waiting for the fallout from that. It won't be pretty.

Yeah. Why am I not surprised.

You're not surprised at the leak, or you're not surprised that squid is Jewish?

The moderator of /c/Jewish is Jewish? No shit.

Don't let this sort of thing out to the general Lemmy population or they'll try to steal my latkes!

Jesus Christ. between this and the third reich ohio sherriff, we may be in for a very bad time. Dude is referring to immigrants as a plague of locusts, and calling on his violent right wing extremists to target those he sees as political opponents.

Climate change is just going to continue accelerating the amount of migration we see from less developed countries. This type of violent extremism needs to be nipped in the bud before it destroys us.

HA ! Sweet vindication! I've been preaching to friends and family not to use these DNA companies for this and other reasons. They called me a loon and I should get my tin foil hat. I cant wait to see their faces

Tried to read article but it fades out and can't resd whole thing. Anyone got the article I can read?

23andMe is not doing well. Its stock is on the verge of being delisted. It shut down its in-house drug-development unit last month, only the latest in several rounds of layoffs. Last week, the entire board of directors quit, save for Anne Wojcicki, a co-founder and the company’s CEO. Amid this downward spiral, Wojcicki has said she’ll consider selling 23andMe—which means the DNA of 23andMe’s 15 million customers would be up for sale, too.

23andMe’s trove of genetic data might be its most valuable asset. For about two decades now, since human-genome analysis became quick and common, the A’s, C’s, G’s, and T’s of DNA have allowed long-lost relatives to connect, revealed family secrets, and helped police catch serial killers. Some people’s genomes contain clues to what’s making them sick, or even, occasionally, how their disease should be treated. For most of us, though, consumer tests don’t have much to offer beyond a snapshot of our ancestors’ roots and confirmation of the traits we already know about. (Yes, 23andMe, my eyes are blue.) 23andMe is floundering in part because it hasn’t managed to prove the value of collecting all that sensitive, personal information. And potential buyers may have very different ideas about how to use the company’s DNA data to raise the company’s bottom line. This should concern anyone who has used the service.

DNA might contain health information, but unlike a doctor’s office, 23andMe is not bound by the health-privacy law HIPAA. And the company’s privacy policies make clear that in the event of a merger or an acquisition, customer information is a salable asset. 23andMe promises to ask its customers’ permission before using their data for research or targeted advertising, but that doesn’t mean the next boss will do the same. It says so right there in the fine print: The company reserves the right to update its policies at any time. A spokesperson acknowledged to me this week that the company can’t fully guarantee the sanctity of customer data, but said in a statement that “any scenario which impacts our customer's data would need to be carefully considered. We take the privacy and trust of our customers very seriously, and would strive to maintain commitments outlined in our Privacy Statement.”

Certain parties might take an obvious interest in the secrets of Americans’ genomes. Insurers, for example, would probably like to know about any genetic predispositions that might make you more expensive to them. In the United States, a 2008 law called the Genetic Information Nondiscrimination Act protects against discrimination by employers and health insurers on the basis of genetic data, but gaps in it exempt providers of life, disability, and long-term-care insurance from such restrictions. That means that if you have, say, a genetic marker that can be correlated with a heart condition, a life insurer could find that out and legally deny you a policy—even if you never actually develop that condition. Law-enforcement agencies rely on DNA data to solve many difficult cases, and although 23andMe says it requires a warrant to share data, some other companies have granted broad access to police. You don’t have to commit a crime to be affected: Because we share large chunks of our genome with relatives, your DNA could be used to implicate a close family member or even a third cousin whom you’ve never met. Information about your ethnicity can also be sensitive, and that’s encoded in your genome, too. That’s all part of why, in 2020, the U.S. military advised its personnel against using consumer tests.

Read: Big Pharma would like your DNA

Spelling out all the potential consequences of an unknown party accessing your DNA is impossible, because scientists’ understanding of the genome is still evolving. Imagine drugmakers trolling your genome to find out what ailments you’re at risk for and then targeting you with ads for drugs to treat them. “There’s a lot of ways that this data might be misused or used in a way that the consumers couldn’t anticipate when they first bought 23andMe,” Suzanne Bernstein, counsel at the Electronic Privacy Information Center, told me. And unlike a password that can be changed after it leaks, once your DNA is out in the wild, it’s out there for good.

Some states, such as California, give consumers additional genetic-privacy rights and might allow DNA data to be deleted ahead of a sale. The 23andMe spokesperson told me that “customers have the ability to download their data and delete their personal accounts.” Companies are also required to notify customers of any changes to terms of service and give them a chance to opt out, though typically such changes take effect automatically after a certain amount of time, whether or not you’ve read through the fine print.

Consumers have assumed this risk without getting much in return. When the first draft of the human genome was unveiled, it was billed as a panacea, hiding within its code secrets that would help each and every one of us unlock a personalized health plan. But most diseases, it turns out, can't be pinned on a single gene. And most people have a boring genome, free of red-flag mutations, which means DNA data just aren’t that useful to them—at least not in this form. And if a DNA test reveals elevated risk for a more common health condition, such as diabetes and heart disease, you probably already know the interventions: eating well, exercising often, getting a solid eight hours of sleep. (To an insurer, though, even a modicum of risk might make someone an unattractive candidate for coverage.) That’s likely a big part of why 23andMe’s sales have slipped. There are only so many people who want to know about their Swedish ancestry, and that, it turns out, is consumer DNA testing’s biggest sell.

Read: DNA tests are uncovering the true prevalence of incest

Wojcicki has pulled 23andMe back from the brink before, after the Food and Drug Administration ordered the company to stop selling its health tests in 2013 until they could be proved safe and effective. In recent months, Wojcicki has explored a variety of options to save the company, including splitting it to separate the cash-burning drug business from the consumer side. Wojcicki has still expressed interest in trying to take the company private herself, but the board rejected her initial offer. 23andMe has until November 4 to raise its shares to at least $1, or be delisted. As that date approaches, a sale looks more and more likely—whether to Wojcicki or someone else.

The risk of DNA data being misused has existed since DNA tests first became available. When customers opt in to participate in drug-development research, third parties already get access to their de-identified DNA data, which can in some cases be linked back to people’s identities after all. Plus, 23andMe has failed to protect its customers’ information in the past—it just agreed to pay $30 million to settle a lawsuit resulting from an October 2023 data breach. But for nearly two decades, the company had an incentive to keep its customers’ data private: 23andMe is a consumer-facing business, and to sell kits, it also needed to win trust. Whoever buys the company’s data may not operate under the same constraints.

Thank you that was super helpful. Never trusted any of these companies and glad I haven't given them my dna.

she'll consider selling 23andMe-- which means the DNA of 23andMe's 15 million customers would be up for sale, too.

When a hacker sells DNA it's mega illegal but when a company does it it's all peachy albeit controversial? BS.

Its always fun being ridiculed, mocked, and insulted by your family because you dare to point out the dangers of something obviously dangerous.

And yet, when shit hits the fan.. who do they come running to begging to fix it?

Why, You, of course.

because you must forever clean up the shit, but you can never prevent the shit.

I'm not bitter or anything.

I'm so glad I never sent them my DNA. It was tempting from a genealogy perspective. But my concerns about privacy and them selling on customer information always weighed heavier than that temptation.

But I feel a lot of sympathy for those who used their services. For a while they incessantly advertised them, including via paid endorsements from many 'trusted' podcasters and YouTubers. The company's failure should bring to the fore a drive for new laws in many countries to protect consumers' DNA from being monetized and exploited. But sadly we all know it won't.

So the fun thing about genetics is... if you said no, but they conned enough of your family, they got a good part of your genome anyhow.

In my case, Mom was somewhat interested about it when it came out. Dad too. And i told them no to, because, well one, sharing data bad. But also, this buisiness is a one off. There are no repeat customers and it was destined to be sold to the highest bidder.

For once, my parents listened. But good god. This company has already been mined by police to use genetic info from relatives to convict their family members. https://www.nytimes.com/2021/12/27/magazine/dna-test-crime-identification-genome.html

Murder convictions and serial rapists going to jail, i got no problem with, but that slippery slope exists. And from years of experience, im not inclined to give the authorities my data, even by proxy. The abuse potential is immense and history is not on the average citizens side.

multiple family members of mine bought 23andme kits, so the company has my data as well. even though I wanted nothing to do with them.

There are no repeat customers and it was destined to be sold to the highest bidder.

I didn't even think of this, but very glad I didn't submit either.

Remember That DNA You Gave 23andMe?

No. When did I do that?

Ah, by not sending them money every month you agreed to them coming into your room while you slept to harvest your unique juices.

Should have known to opt out of that thing you never signed.

When your cousin did it a few years ago. Now they have a lot of your DNA too.

I’m still glad I did.

Lead me to finding my biological family.

And as far as side effects go, there’s not much they can use it for that will bother me.

This whole "meh I don't care about privacy, take my data" attitude among younger generations is going to cause us SO MANY PROBLEMS in 20 years.

And what are these problems you foresee?

Being denied medical insurance because you have a genetic predisposition for certain diseases.

New government comes into power, decides homosexuality is illegal. Digs into your post history, finds your comments supporting homosexuality, you go to prison.

Someone takes a bunch of photos of you, uses AI to create a lifelike video of you doing a lewd sex act, and then blackmails you with it.

Identity theft cases go through the roof.

Employers refuse to hire you because of an argument you had on facebook when you were 14.

You're really REALLY craving ice cream. Predictive algorithms knew you would be craving ice cream right now. So your personal price for ice cream at every store is now 3x what it usually is.

You call in sick to work, but actually go to visit a sick friend. Your car reports your location to your boss, and you're fired.

It really shows how far we have fallen when these examples (to which, top notch, grade A examples, mind you) sound terrifyingly real. Some even sound like they have happened in some capacity. You could write horror stories for the modern age.

Regarding the second argument: unless something really bad happens in the country, wouldnt it be impossible to put someone in prison for breaking a law that didnt exist you did the action?

I know this is prohibited in the romanian constitution and i know that the entire document was inspired by the american constitution so i just assumed that it was a common thing to have in a constitution. I have seen a lot of people(including americans) use being charged for a crime that didnt exist when you committed it as a pro-privacy argument and im not sure if other countries just forgot to put one of the most important thing in their constitution

Illegal? Probably. Impossible? No.

Impossible unless something really bad happens in the country

If something really bad happens in the country and they would lookin your history of comments if you supported something, couldnt they also ban privacy and charge you for that?

Please correct me if im wrong

Something really bad can happen. It has happened before in many countries, and will continue to happen as long as we have humans.

Yes, privacy can be made more difficult. Certain privacy friendly services (example VPN, there are others) could be banned.

But, the less information they have on you, the better off you'll be.

That relies on the assumption that a dictatorship would follow the rules.

unless something really bad happens in the country, wouldnt it be impossible to put someone in prison for breaking a law that didnt exist you did the action?

yeesh, this'll age like rotten eggs.

Honestly most of these sound like America problems, insurance, employers digging through history, cars reporting to workplaces, etc.

Companies already have profile information on me, or 95% accurate generalisations for my demographic. And no way would such price gouging tactics be allowed in my country.

The most plausible ones, such as a government targeting me - well the only other option is to live my life underground and that defeats the whole purpose of pride. So yeah I'll gladly risk being myself publicly in spite of the risks.

Look at the end of the day, things could change 180 a new oppressive and more American like government could come in and make my life shitty. But the thing is, if they've already managed to come in, they're going to make my life shitty regardless of what information I have out there.

You sweet naive fool. "That would never happen, it's ILLEGAL!" Grow up. They are already doing it.

That’s nice American, why don’t you go focus on a real issue like gun control instead of fearing an imaginary future where fascists are in power but can only find public information about a person to persecute them with?

Maybe you could focus on the lack of universal healthcare, rather than private insurance raising your prices.

Stop focusing on imaginary future scenarios and focus on the actual real problems you have already. Because they don’t exist elsewhere and it’s got nothing to do with DNA information.

Hahaha did I strike a nerve? Probably guilt. You know you should care more about privacy but you can't give up the convenience.

No, I’m just tired of seeing your ill thought out comments on this site.

All it would take is one shitty government to mandate you have to have dna on file and your entire safety is gone.

Focus on having a better government, that will actually protect your citizens, not this fear mongering.

It's ok, I'm sure just screaming "America bad" will totally mask those guilty feelings.

I’m sure pretending you don’t already have it worse will make you feel smug about not knowing about your dna.

Your problems are purely political, they don’t exist elsewhere. Get used to that.

2 more...
2 more...
2 more...
2 more...
2 more...
2 more...
2 more...
2 more...

Considering the rise of fascism everywhere? What could possibility go wrong?

Mass data harvesting, inevitable data breach - oh look, you have genetic markers for some degenerative condition, and for some reason you're now suddenly getting booted off your insurance and refused coverage.

2 more...
2 more...

Worst that could happen is that you get denied insurance coverage or pay a bigger premium than you should. Or get caught easier if you decide to succumb to a life of crime. Or in the future they might be able to figure out if you have predisposition towards addictive behaviors and market gambling and stuff to you.

So hopefully nothing too bad, but personally I'd still feel iffy about a private corporation owning the rights to my DNA.

Worst that could happen is that you get denied insurance coverage

If you end up getting a serious illness or cancer or something like that, you might reevaluate how big of a problem this is.

I was being facetious. Obviously it's a huge problem.

I don't have health insurance and the world already advertises addictive shit to me and everyone else.

I'm not too worried about it.

I wish you the best of luck when your health insurance rejects your life saving operation because, "you were informed of your genetic predisposition to x and did not take preventative actions for n years."

while you're dealing with your own mortality, you'll also be coming to terms with your own ignorance that put you in that situation.

but don't worry, you're young, you'll live forever.

I have universal healthcare.

Have fun when your private health insurance fucks you over for whatever bullshit reason it picks and you can’t afford to fight it even though you’re in the right?

2 more...

People are morons for doing these things and expecting any privacy.

23andMe has a “request data deletion” feature. I don’t know if it actually works, but it’s worth a try if you’re worried about it.

Yep, I had my data deleted. They told me so, but I don't for a second believe it.

They don't actually delete anything. They will throw the physical samples away but retain your entire identified genetic code.

https://news.ycombinator.com/item?id=17611256

There's a better source out there but I can't find it atm. They hide behind an obscure FDA rule. Something about retaining genetic data for 20 years no matter what or something.

i was really close to using this service.

then they got hacked. so i waited.

now this makes me glad that i waited.

Nope. I wasn’t that fucking stupid. So…. Not me.

Except half a dozen of your relatives did, so you might as well have at this point.

Anyone who used these DNA analysis services were idiots to begin with.

There was no way in hell that valuable genetic data would ever stay private with no commercial or police access.

Sadly my grandpa did it before dying so some of my information is in there.

Nope, I never did

But you can’t control what your family does.

Honestly terrifying. Once that info is out there, who knows what could happen.

Will insurance use it to see if you're pre-disposed to something and charge more?

Will a fascist group use it to find groups they think are undesirable? What if there's a genetic component or predisposition to being gay/trans?

Will future terrorists or governments use it to engineer a virus that only affects a group of people? Assasinate an enemy and their entire family?

There's a podcast sequel to Orphan Black that uses the plot from your last point, and it is excellent

There's a podcast sequel to Orphan Black

Squeals like a little girl and heads to AntennaPod app

Edit: EEE it actually stars Tatiana Maslany herself! 🥰

It's honestly so freaking good. I really wish they'd make another season, but I don't see it happening now that they've done Echos (which I haven't seen yet, no spoilers!). My only complaint is the first season doesn't have Felix's voice actor, but season 2 does, and it's fantastic.

You should probably just assume that your genetic information is already or will be out there at some point. If you want to protect against how it could be used against you, my suggestion would be to change your last name from a genetically-based one to one chosen by you. It isn’t foolproof since the name change is public record, but it creates a firewall that makes it harder.

That's why I changed my legal name to "Marijuana Plant Johnson"

Too unique for a name database. Just change your last name to Nguyen or Chan. Throw off the scent.

I'm not a fan of being paranoid.

Yes because people who are paranoid schizophrenia were all such a fan of it. Wonderful prognosis of how mental health works.

I was never worried about this because I’m from Eastern Kentucky.

They have my dna, but good luck finding me.