{"id":230,"date":"2024-08-07T11:51:00","date_gmt":"2024-08-07T11:51:00","guid":{"rendered":"https:\/\/absolutelynothing.io\/?p=230"},"modified":"2024-08-21T12:16:01","modified_gmt":"2024-08-21T12:16:01","slug":"i-just-took-a-dna-test-turns-outmy-data-was-leaked","status":"publish","type":"post","link":"https:\/\/absolutelynothing.io\/?p=230","title":{"rendered":"I Just Took a DNA test, Turns Out\u2026My Data was Leaked"},"content":{"rendered":"\n<p><em>Diane here, COO and the least technical member of our group! I\u2019ll occasionally take control of our blog to give y\u2019all a break from hearing from Kyle. My posts will focus more on things happening in mainstream media or whatever I find interesting, relevant, or scandalous. Enjoy!<\/em>&nbsp;\ud83d\udda4<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p>Hi readers! I\u2019m back and this week we are going to talk about another alarming data leak. While all data leaks are concerning because personally identifiable information (otherwise known as PII; think email address, name, address, credit card information, etc.) is made available to bad actors, there are some data leaks that expose, what I believe, to be even more sensitive information\u2026and this is what happened in 2023.<\/p>\n\n\n\n<p>Unless you have been living under a rock, you\u2019ve probably heard about companies where with a simple cheek swab you can send them your DNA and find out your <a href=\"https:\/\/www.ancestry.com\/dna\/\">ancestry<\/a> or find out more about your <a href=\"https:\/\/www.23andme.com\/\">health<\/a> through your genetics. Heck, you can even do <a href=\"https:\/\/shop.embarkvet.com\/products\/embark-dog-dna-test-kit?srsltid=AfmBOormqkG5xdydtysmJuJ-SR6ER0P6etZNi4-RPpL-C5VHzVJTIDEX\">DNA testing for your dog<\/a> (we don\u2019t need a DNA test to know our <a href=\"https:\/\/absolutelynothing.io\/?page_id=133#:~:text=Remy%20Bear%2C%20Chief%20Barking%20Officer\">Chief Barking Officer<\/a> is 90% queen and 10% cookie monster). I can totally understand the allure of tracing your ancestry and of learning more about your genetics to help inform your medical care, but I would also caution y\u2019all to do your due diligence prior to giving companies your literal DNA because as we have learned from previous data leaks, no data is truly 100% secure.<\/p>\n\n\n\n<p>Let\u2019s take a look at what happened to 23andMe\u2026<\/p>\n\n\n\n<p>In late 2023, a hacker stole the data of 6.9 million users of 23andMe, about half of the company\u2019s total users. The investigation revealed the hacker was able to [brute-force](<a href=\"https:\/\/www.fortinet.com\/resources\/cyberglossary\/brute-force-attack#:~:text=A%20brute%20force%20attack%20is,and%20organizations\">https:\/\/www.fortinet.com\/resources\/cyberglossary\/brute-force-attack#:~:text=A brute force attack is,and organizations<\/a>&#8216;%20systems%20and%20networks.) users\u2019 passwords (basically using trial and error) by using passwords available online from other data leaks (#donotreusepasswords). 23andMe reported to <a href=\"https:\/\/techcrunch.com\/2023\/12\/04\/23andme-confirms-hackers-stole-ancestry-data-on-6-9-million-users\/\">TechCrunch<\/a>, the data leaked was from users who opted-in to the company\u2019s DNA Relatives feature and included the \u201cperson\u2019s name, birth year, relationship labels, the percentage of DNA shared with relatives, ancestry reports and self-reported location\u201d as well as uploaded photos. Other data was access using the Family Tree feature.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"959\" height=\"935\" src=\"https:\/\/absolutelynothing.io\/wp-content\/uploads\/2024\/08\/Screenshot-2024-08-05-at-2.40.31\u202fPM.png\" alt=\"\" class=\"wp-image-231\" srcset=\"https:\/\/absolutelynothing.io\/wp-content\/uploads\/2024\/08\/Screenshot-2024-08-05-at-2.40.31\u202fPM.png 959w, https:\/\/absolutelynothing.io\/wp-content\/uploads\/2024\/08\/Screenshot-2024-08-05-at-2.40.31\u202fPM-300x292.png 300w, https:\/\/absolutelynothing.io\/wp-content\/uploads\/2024\/08\/Screenshot-2024-08-05-at-2.40.31\u202fPM-768x749.png 768w\" sizes=\"auto, (max-width: 959px) 100vw, 959px\" \/><figcaption class=\"wp-element-caption\">How strong is your password? Check out this graph to see how long it would take a hacker to brute force your password.<\/figcaption><\/figure>\n\n\n\n<p>The hacker, who goes by Golem (probably ripped from Gollum of \u201cLord of the Rings\u201d), posted on an online forum used by cybercriminals the Personally Identifiable Information of more than 1 million users with Jewish ancestry. The data included their full names, home addresses, and birth dates. <a href=\"https:\/\/www.nytimes.com\/2024\/01\/26\/business\/23andme-hack-data.html\">According to The New York Times<\/a>, after a request was made by forum poster, Golem leaked the profile information of 100,000 Chinese customers.<\/p>\n\n\n\n<p>2<a href=\"https:\/\/blog.23andme.com\/articles\/addressing-data-security-concerns\">3andMe subsequently notified their users<\/a>, required them to change their passwords, and required new customers to setup two-step verification when creating accounts. There is also currently a lawsuit making it\u2019s way through the court systems. The class action lawsuit accuses 23andMe of \u201cfailing to protect the privacy of customers whose personal information was exposed last year in a data breach that&nbsp;affected nearly seven million profiles\u201d and \u201cfailing to notify customers with Chinese and Ashkenazi Jewish heritage that they appeared to have been specifically targeted, or that their personal genetic information had been compiled into \u2018specially curated lists\u2019 that were shared and sold on the dark web\u201d.<\/p>\n\n\n\n<p>According to the National Institutes of Health (NIH), there are <a href=\"https:\/\/medlineplus.gov\/genetics\/understanding\/dtcgenetictesting\/dtcrisksbenefits\/\">little regulations or oversight for direct-to-consumer genetic testing companies<\/a>, unlike the companies that work directly with health care professionals. This lack of oversight and regulations includes what they can and can\u2019t do with your data and how they can (or don\u2019t) protect your data. Most of these companies have detailed information on their practices which can help you answer the following questions which are outlined by the NIH as being helpful to <a href=\"https:\/\/medlineplus.gov\/genetics\/understanding\/dtcgenetictesting\/dtcprivacy\/\">\u201cassess a company\u2019s privacy practices\u201d<\/a>\u2026<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>What does the company do with your sample once it has completed the analysis? Will the sample be stored, shared, sold, or destroyed?<\/li>\n\n\n\n<li>Once you take the test, who owns your genetic data?<\/li>\n\n\n\n<li>How does the company safeguard your genetic data and other personal information that you provide? Is it stored in a database that is protected from unauthorized access? What happens if the database is hacked or otherwise compromised?<\/li>\n\n\n\n<li>Can you delete your results from the company\u2019s database if you wish?<\/li>\n\n\n\n<li>Does the company use your information for internal research, advertising, or other secondary purposes?<\/li>\n\n\n\n<li>Will the company share your genetic data or sell it to pharmaceutical or biotechnology companies, academic institutions, or nonprofit organizations? If so, will the shared data include other information that could identify you (such as your name or date of birth)? For what purposes will your data be used? Will you be informed when your data are shared or sold?<\/li>\n\n\n\n<li>If you do not want your genetic data shared, sold, or used for research, can you opt out? What happens if you agree to share your information but want to opt out later?<\/li>\n\n\n\n<li>Will you be notified in the future if the company changes its privacy policies?<\/li>\n\n\n\n<li>What would happen to your sample and your genetic information if the company is sold or goes out of business?<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p>So if you, like Lizzo, want to take a DNA test to find out you\u2019re 100% that b*tch, make sure to read the privacy policy and any other policy available thoroughly, visit the FAQ page, send your questions to the company, and make sure to use a strong password.<\/p>\n\n\n\n<p>And if the thought of cybercriminals having your data and your DNA (or really anyone other than the intended) makes your skin crawl, or if you have begun to think about just how much of your data is out there and are getting the ick, you have found yourself in the right place! <strong>Here at AbsolutelyNothing, we believe digital citizens, such as yourself, should have control over their data and the first step is to become more aware and education about data privacy and privacy policies.<\/strong> Our team is so very close to releasing our first products which are going to help you pinpoint what kind of data companies are collecting and make sense of the legalese in privacy policies, terms, and agreements. If you are excited about what we are doing at AbsolutelyNothing, go ahead and <a href=\"https:\/\/buymeacoffee.com\/absolutelynothing\">let us know<\/a> &#8211; we are a small and scrappy team so every dollar counts.<\/p>\n\n\n\n<p>Until next time digital citizens,<\/p>\n\n\n\n<p>Diane<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Diane here, COO and the least technical member of our group! I\u2019ll occasionally take control of our blog to give y\u2019all a break from hearing from Kyle. My posts will focus more on things happening in mainstream media or whatever I find interesting, relevant, or scandalous. Enjoy!&nbsp;\ud83d\udda4 Hi readers! I\u2019m back and this week we [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[25],"class_list":["post-230","post","type-post","status-publish","format-standard","hentry","category-uncategorized","tag-2024-08"],"_links":{"self":[{"href":"https:\/\/absolutelynothing.io\/index.php?rest_route=\/wp\/v2\/posts\/230","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/absolutelynothing.io\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/absolutelynothing.io\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/absolutelynothing.io\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/absolutelynothing.io\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=230"}],"version-history":[{"count":1,"href":"https:\/\/absolutelynothing.io\/index.php?rest_route=\/wp\/v2\/posts\/230\/revisions"}],"predecessor-version":[{"id":232,"href":"https:\/\/absolutelynothing.io\/index.php?rest_route=\/wp\/v2\/posts\/230\/revisions\/232"}],"wp:attachment":[{"href":"https:\/\/absolutelynothing.io\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=230"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/absolutelynothing.io\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=230"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/absolutelynothing.io\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=230"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}