Okay but like, I'm not planning on committing a crime and nothing I do now is considered criminal, but let's play out the worst case scenario and a fascist government comes to power and something I do now is considered criminal and they can place me doing it with this DNA that as the author describes can narrow down if it was me pretty easily.
You can tell me I'm paranoid or something, but I can also just not give them my DNA for no effort and be all the more better off if something like this happens OR if I do commit a crime under current laws I haven't given up the ghost immediately.
This feels like short term little gain for catastrophic effects in the worst case scenario.
The author also makes this like a weird dichotomy with online tracking, I ALSO care about being tracked on the internet and my personal privacy is pretty important to me in general.
I want all of my privacy, or better worded I want privacy to be my choice such as here on HN where I use my real name intentionally. :)
alistairSH · 3h ago
It's not a "weird" dichotomy, it's a straight-up false dichotomy.
DNA is just one facet of all the data being actively collected by SuperMegaCorp and/or governments (or probably worst of all, both at the same time and in cooperation with each other).
ianbutler · 3h ago
Sure could have used stronger language here, I agree
jacquesm · 3h ago
> let's play out the worst case scenario and a fascist government comes to power
That's borderline no longer a hypothetical.
sampo · 2h ago
> and they can place me doing it with this DNA
Probably easier to place you with your cell phone location data, or surveillance cameras and face recognition.
johnisgood · 3h ago
> Okay but like, I'm not planning on committing a crime and nothing I do now is considered criminal
I genuinely don't know and would like to know: are you being sarcastic? I'm asking because to me it seems like you are, but please correct me if I'm wrong.
ianbutler · 3h ago
No I'm disarming a common quip from people immediately and effectively.
johnisgood · 2h ago
[REDACTED]
worik · 2h ago
I agree
And it is not the state (criminality) that is the biggest risk IMO. The classifying of people into "sheep and goats" is more likely to come from private power. Governments are dangerous, yes. But there are many fewer democratic checks and balances over private power
yura · 2h ago
You're literally restating the same point that the original poster has already made in his comment. You're agreeing with him.
Seems like you just read the first phrase of his comment and immediately went into an adversarial "are you being sarcastic?" loop. Because the point you made is what came immediately after the part you quoted in his original comment:
> [...] but let's play out the worst case scenario and a fascist government comes to power and something I do now is considered criminal and they can place me doing it with this DNA that as the author describes can narrow down if it was me pretty easily.
johnisgood · 2h ago
No, I read his full comment, but I have a problem with "I'm not planning on committing a crime and nothing I do now is considered criminal" which is commonplace these days to say. I laid it out as to what.
So, as for the rest of his comments, such as: "The author also makes this like a weird dichotomy with online tracking, I ALSO care about being tracked on the internet and my personal privacy is pretty important to me in general.", I agree.
I edited my comment as it was deeply misunderstood, and I am not interested in having it derailed even further. Maybe another time.
tetris11 · 3h ago
> That’s a tiny percentage: about 0.02% of your genome. So no, they don’t have your genome, but they do have a small sample of it.
What kind of reasoning is that? Fine, they're not doing whole genome sequencing on you (yet), but having a detailed chip profile of several million informative SNPs absolutely can and will be used to profile you.
Very quickly and easily I might add.
Classical linkage analysis has been used quite effectively to profile people since the 80s using only a handful of (polymorphic) markers, because the power of the analysis is driven more by the number of related members than by the number of markers of an individual.
23&Me has a customer base of more than 10 million people(!!)
exe34 · 3h ago
They don't have all your personal information, they just have your name and address.
compiler-guy · 3h ago
Which makes it trivial to buy a database and correlate everything.
inetknght · 3h ago
> The fact is that if you’re worried about privacy, you should be far, far more concerned about all the data that various companies are hoovering up
I worked in DNA analysis for 6 years.
You should absolutely be worried about the data that various companies are hoovering up. Your DNA is part of it.
codingdave · 4h ago
> The fact is that if you’re worried about privacy, you should be far, far more concerned about all the data that various companies are hoovering up about you based on your online activity.
Maybe it is just meant to emphasize that there are things they themselves believe to be worse. But yeah, this fallacy is extremely common. I love rationalwiki.org.
markx2 · 3h ago
Data about me and what I click is one issue.
Data that can be used against my children is another.
My late wife had MS. It took her. Insurance companies would love that data to load against anything my kids do.
There are other issues but the fact is that companies will use DNA and every other data point they can to maximise what they take and minimise with loaded terms what they might, just might, maybe, pay out.
It's not about the now.
It's about the later.
johnisgood · 3h ago
Oh man, I have MS and I have immobility and incontinence issues at 30. Based on the location of lesions, I have a high risk for four-limb paralysis. It scares the hell out of me, and my quality of life is out the window already anyways. Life was hard before, it is much harder now.
JohnFen · 4h ago
I wonder why he cares whether or not people delete their DNA?
I asked them to delete mine (although I'm not optimistic that they did so), and I'm glad that I did for two reasons. First, I don't think they dealt with me transparently and honestly from the start and second, whether or not that data is directly a risk to me, it's yet more data about me that's out there in the world and can be combined with other data to make a potent risk.
The less data about me that exists in any database, even trivial or apparently innocuous data, the better.
psyklic · 3h ago
This is like saying if you have nothing to hide, you should consent to police searches. What is found only provides more possibly coincidental evidence to use against you (just as DNA provides evidence about your potential health).
stanfordkid · 3h ago
This a bone headed article… umm we can’t extract anything from it about your health (*now)… so might as well just spread it everywhere?
Like he doesn’t even go into the fact that it could be used by law enforcement wrongfully etc: e.g Unregulated Chinese crime detection startup buys the data, you happen to be in China and get arrested bc they used inadequate algorithms that wrongfully accused you.
There is absolutely nothing convincing here.
sholladay · 1h ago
The author might not be aware of this, but DNA databases from companies like 23andMe are already being used for mass surveillance and police work. They don’t need the entire gene sequence, they already have enough to identify you and invade your privacy more than you might think, especially in combination with other data and the data of other people.
The Golden State Killer was caught because a distant relative submitted a DNA sample to one of these services. Thus, when the police submitted a DNA test report from the unknown killer to GEDmatch, it came back with some useful hits, which they were able to narrow down to just one person.
Maybe you support the outcome in that particular case, but what happens when it’s your sibling that committed a crime, or they are a political dissident, or they practice the “wrong” religion?
And remember that your DNA is one of the few pieces of personal information that is permanent and cannot be changed.
You know genomes. But you don't seem to understand how big corporations operate and what the risks to your privacy are when your DNA and/or significant fractions thereof start floating around. It takes ~33 bits to uniquely identify a human. This is 'gods own GUID' and it has far, far more than 33 bits, even in the most limited case.
montgomery_r · 2h ago
Salzberg states several times that one should browse in 'private' or 'incognito' mode to stop 3rd party tracking. This is false.
Incognito mode stops data such as web history and cookies being stored on the computer you are using - it is good (enough) for obscuring what sites you have visited from other people who may have access to your computer. (It may not defeat a deep forensic search, it might save you from family embarrassment).
Incognito mode does not hide any data at all from your ISP, your DNS server, or the web servers you visit - it does not do anything to defeat 3rd party tracking.
An error of this magnitude does make me wonder whether any of his other propositions are true at all.
JohnFen · 2h ago
Good catch!
It's almost as if being an expert in one thing doesn't give you any expertise in a completely unrelated thing.
fitblipper · 1h ago
This is the tired excuses:
If you've got nothing to hide then you shouldn't want privacy
And
If you already lack privacy in some places you should just give up on having any.
The first is stupid. If there exists capacity to keep things private, why would I NOT want to have privacy? What is in it for me to let arbitrary others see everything I do and am?
The second so strange to hear. It is an argument for turning the slippery slope of privacy erosion that you try to resist into a waterslide that you should enthusiasticly throw yourself down.
maratc · 3h ago
> That’s a tiny percentage: about 0.02% of your genome. So no, they don’t have your genome, but they do have a small sample of it.
IIRC, 99 percent of the rest is shared by all humans, 95 precent is shared by humans and apes, and some 80 (?) percent is shared by humans and drosophila flies? That's likely the important 0.02%.
compiler-guy · 2h ago
Even if we accept the author’s contention that the downside risk is very low (and plenty of other comments explain why that is a bad idea), they make no case at all for the benefits. If there is no benefit to keeping it, then there is no downside to deleting it.
aroch · 3h ago
> However–and here’s the rub–some 25 years after the human genome was sequenced, and despite huge efforts to link genes and disease, there are almost no SNPs that tell you anything consequential about your health. If you have a genetic disease, you almost certainly already know about it, and if you don’t know, then the 23andMe data just isn’t going to reveal anything.
For someone who “knows genomes”, this is a brain dead take on microarrays. Lots of the content on arrays _is_ directly tied to a phenotype because there’s limited space so we directly test variants that are known to cause problems!
Is he really claiming that BRCA1/2 variants don’t increase risk of breast cancer in a meaningful way? Or that there aren’t tons of people who are XXY who don’t know even though it’s the hidden cause of many infertility problems?
This is just such a bad take it is hard to take anything said here seriously
alistairSH · 3h ago
Is he really claiming that BRCA1/2 variants don’t increase risk of breast cancer...
Even worse, if insurance companies had their way, they'd use the family matriarch's BRCA1/2 variant to set the rates for all her descendants. Massive DNA profiling doesn't just impact the "owner" of the DNA - it impacts anybody in their family tree who might have similar genes.
sorokod · 3h ago
What is the benefit of leaving your data with 23andMe?
epistasis · 4h ago
I love Steven Salzburg, but he's missing the main point here:
23andMe could have been sold to someone that is not based in California which would result in a loss of many protections currently there, such as being able to have the data be deleted.
Sure, the data is not that valuable. Nobody really cares that is doing serious decision making based on good science or following the law.
I think he also ignores a new risk that's developing: bad tests. Current polygenic risk scores are all the rage, but they are very close to junk science, and if not created and applied very very carefully, far more carefully than most machine learning models, they will be junk.
So even if there's nothing in your DNA that could be used to discriminate against you, bad application of the technology could harm (or benefit) you, completely randomly. All because some pointy haired boss demanded that a bad model gets built and applied, whether or not the engineers knew what they were doing or gave proper warning to management.
This isn't just health care, it could be admissions to a private school, or the application for an apartment or NYC housing co-op, or whatever.
That's a serious risk, that some junk company uses the data in completely inappropriate ways, once the data is out in the wild.
Why not delete? There's zero benefit to the consumer to keep the data in 23andMe, at least for this consumer. Others that want to connect with 5th cousins might think differently of course.
But the point is that it's a personal decision and we all have different values and wants.
loteck · 3h ago
This commentary attempts to reassure people about staying with 23 and me, but ultimately ends up concluding that there's virtually nothing useful to be gleaned from the data created from the 23 and me process.
Author dismissed privacy concerns in the same way we see others downplay it: you already are giving up your privacy in other parts of your life, why not give it up here, too? Total nonsense, IMO.
The conclusion I came to from this, that I don't believe the author intended, is that you should delete your data from this company because it is pointless.
EndsOfnversion · 2h ago
What a useful and timely reminder to delete your data from 23andmes website. Thank you.
karaterobot · 3h ago
> The fact is that if you’re worried about privacy, you should be far, far more concerned about all the data that various companies are hoovering up about you based on your online activity.
This tired canard makes me mad. It's not either/or. Be concerned about anyone who is collecting data on you and selling it without your consent.
And in my mind, the reason to delete your data from 23AndMe isn't to protect PII, it's to take an a salable asset away from a company that promised they wouldn't sell it in the first place, then changed their mind.
wat10000 · 3h ago
"What’s fascinating–and a lot of fun, for some–is that by comparing these scattered landmarks, called SNPs or “snips,” you can get a very accurate picture of how closely related two people are."
This directly contradicts the claim that these samples reveal nothing about your health or disease risk. Maybe it doesn't reveal anything in isolation, but if you know some medical history about some of my relatives and you have their DNA info, then that gives you some significant info about me too.
seydor · 3h ago
you can download your data before deletion so this is not useful advice. you can use your data elsewhere if you care about the other stuff
worik · 2h ago
Incredibly unconvincing
The arguments boil down to "we're all fucked so letting 23&me fuck us more is no big deal"
> ...this is only a problem because of our disastrous insurance-based, for-profit healthcare system in the U.S.
That is the reality for the subjects of the USA. So it is a problem
>...far more concerned about all the data that various companies are hoovering up about you based on your online activity
No. I take active measures against sneaky surveillance (my browsers cannot be tracked as far as I can tell) and I use my real name lots of places. I am in control. If my siblings, parents, children submit "their" private data to these evil data horders, I am not in control
Deleting your, and yours, data from 23&me will be closing the stable door, I am unconvinced that these sorts of people will actually delete anything (they will remove it from your view and control) but it has performative value
Delete the data!
FollowingTheDao · 3h ago
I run my genome twice through 23 and me, the V4 and V5 chip.
They’re doing this I found a mutation parentheses (not a polymorphism) in my CVS enzyme that was causing my family to have heart attacks before they were 50.
And I currently diagnosed two people just looking at their genetics one with celiac and the other one with 21 hydroxy deficiency. Just let them impress your doctor for test in proving it was right.
What makes me sad about this is that it’s such a valuable resource that no one’s going to have access to because of corporations and greed. Personalized medicine is the only way to cure diseases and the only way to find out what’s going on in your body.
constantcrying · 3h ago
>The fact is that if you’re worried about privacy, you should be far, far more concerned about all the data that various companies are hoovering up about you based on your online activity.
The risk for privacy is not that one piece of your data is out there, but that companies can recreate a very sophisticated model of you by aggregating many pieces.
The idea that one small breach of privacy is equivalent to the vast amounts of informations 23andme has getting correlated with hundreds of other small pieces, is absurd.
It is a total lie that you should not be concerned about your privacy, because total privacy is impossible. The author also does not understand incognito mode.
namuol · 3h ago
I’m sorry, but the whataboutism argument being made about online data trackers and brokers being “the real bad guys” totally misses the point that insurers are extremely thirsty for data like this, which is a very different buyer than, say, a political campaign fund or marketing agency. But like, both are mutually concerning, too.
You can tell me I'm paranoid or something, but I can also just not give them my DNA for no effort and be all the more better off if something like this happens OR if I do commit a crime under current laws I haven't given up the ghost immediately.
This feels like short term little gain for catastrophic effects in the worst case scenario.
The author also makes this like a weird dichotomy with online tracking, I ALSO care about being tracked on the internet and my personal privacy is pretty important to me in general.
I want all of my privacy, or better worded I want privacy to be my choice such as here on HN where I use my real name intentionally. :)
DNA is just one facet of all the data being actively collected by SuperMegaCorp and/or governments (or probably worst of all, both at the same time and in cooperation with each other).
That's borderline no longer a hypothetical.
Probably easier to place you with your cell phone location data, or surveillance cameras and face recognition.
I genuinely don't know and would like to know: are you being sarcastic? I'm asking because to me it seems like you are, but please correct me if I'm wrong.
And it is not the state (criminality) that is the biggest risk IMO. The classifying of people into "sheep and goats" is more likely to come from private power. Governments are dangerous, yes. But there are many fewer democratic checks and balances over private power
Seems like you just read the first phrase of his comment and immediately went into an adversarial "are you being sarcastic?" loop. Because the point you made is what came immediately after the part you quoted in his original comment:
> [...] but let's play out the worst case scenario and a fascist government comes to power and something I do now is considered criminal and they can place me doing it with this DNA that as the author describes can narrow down if it was me pretty easily.
So, as for the rest of his comments, such as: "The author also makes this like a weird dichotomy with online tracking, I ALSO care about being tracked on the internet and my personal privacy is pretty important to me in general.", I agree.
I edited my comment as it was deeply misunderstood, and I am not interested in having it derailed even further. Maybe another time.
What kind of reasoning is that? Fine, they're not doing whole genome sequencing on you (yet), but having a detailed chip profile of several million informative SNPs absolutely can and will be used to profile you.
Very quickly and easily I might add.
Classical linkage analysis has been used quite effectively to profile people since the 80s using only a handful of (polymorphic) markers, because the power of the analysis is driven more by the number of related members than by the number of markers of an individual.
23&Me has a customer base of more than 10 million people(!!)
I worked in DNA analysis for 6 years.
You should absolutely be worried about the data that various companies are hoovering up. Your DNA is part of it.
https://rationalwiki.org/wiki/Not_as_bad_as
Data that can be used against my children is another.
My late wife had MS. It took her. Insurance companies would love that data to load against anything my kids do.
There are other issues but the fact is that companies will use DNA and every other data point they can to maximise what they take and minimise with loaded terms what they might, just might, maybe, pay out.
It's not about the now.
It's about the later.
I asked them to delete mine (although I'm not optimistic that they did so), and I'm glad that I did for two reasons. First, I don't think they dealt with me transparently and honestly from the start and second, whether or not that data is directly a risk to me, it's yet more data about me that's out there in the world and can be combined with other data to make a potent risk.
The less data about me that exists in any database, even trivial or apparently innocuous data, the better.
Like he doesn’t even go into the fact that it could be used by law enforcement wrongfully etc: e.g Unregulated Chinese crime detection startup buys the data, you happen to be in China and get arrested bc they used inadequate algorithms that wrongfully accused you.
There is absolutely nothing convincing here.
The Golden State Killer was caught because a distant relative submitted a DNA sample to one of these services. Thus, when the police submitted a DNA test report from the unknown killer to GEDmatch, it came back with some useful hits, which they were able to narrow down to just one person.
Maybe you support the outcome in that particular case, but what happens when it’s your sibling that committed a crime, or they are a political dissident, or they practice the “wrong” religion?
And remember that your DNA is one of the few pieces of personal information that is permanent and cannot be changed.
https://www.science.org/content/article/we-will-find-you-dna...
https://en.wikipedia.org/wiki/Joseph_James_DeAngelo
It's almost as if being an expert in one thing doesn't give you any expertise in a completely unrelated thing.
The first is stupid. If there exists capacity to keep things private, why would I NOT want to have privacy? What is in it for me to let arbitrary others see everything I do and am?
The second so strange to hear. It is an argument for turning the slippery slope of privacy erosion that you try to resist into a waterslide that you should enthusiasticly throw yourself down.
IIRC, 99 percent of the rest is shared by all humans, 95 precent is shared by humans and apes, and some 80 (?) percent is shared by humans and drosophila flies? That's likely the important 0.02%.
For someone who “knows genomes”, this is a brain dead take on microarrays. Lots of the content on arrays _is_ directly tied to a phenotype because there’s limited space so we directly test variants that are known to cause problems!
Is he really claiming that BRCA1/2 variants don’t increase risk of breast cancer in a meaningful way? Or that there aren’t tons of people who are XXY who don’t know even though it’s the hidden cause of many infertility problems?
This is just such a bad take it is hard to take anything said here seriously
Even worse, if insurance companies had their way, they'd use the family matriarch's BRCA1/2 variant to set the rates for all her descendants. Massive DNA profiling doesn't just impact the "owner" of the DNA - it impacts anybody in their family tree who might have similar genes.
23andMe could have been sold to someone that is not based in California which would result in a loss of many protections currently there, such as being able to have the data be deleted.
Sure, the data is not that valuable. Nobody really cares that is doing serious decision making based on good science or following the law.
I think he also ignores a new risk that's developing: bad tests. Current polygenic risk scores are all the rage, but they are very close to junk science, and if not created and applied very very carefully, far more carefully than most machine learning models, they will be junk.
So even if there's nothing in your DNA that could be used to discriminate against you, bad application of the technology could harm (or benefit) you, completely randomly. All because some pointy haired boss demanded that a bad model gets built and applied, whether or not the engineers knew what they were doing or gave proper warning to management.
This isn't just health care, it could be admissions to a private school, or the application for an apartment or NYC housing co-op, or whatever.
That's a serious risk, that some junk company uses the data in completely inappropriate ways, once the data is out in the wild.
Why not delete? There's zero benefit to the consumer to keep the data in 23andMe, at least for this consumer. Others that want to connect with 5th cousins might think differently of course.
But the point is that it's a personal decision and we all have different values and wants.
Author dismissed privacy concerns in the same way we see others downplay it: you already are giving up your privacy in other parts of your life, why not give it up here, too? Total nonsense, IMO.
The conclusion I came to from this, that I don't believe the author intended, is that you should delete your data from this company because it is pointless.
This tired canard makes me mad. It's not either/or. Be concerned about anyone who is collecting data on you and selling it without your consent.
And in my mind, the reason to delete your data from 23AndMe isn't to protect PII, it's to take an a salable asset away from a company that promised they wouldn't sell it in the first place, then changed their mind.
This directly contradicts the claim that these samples reveal nothing about your health or disease risk. Maybe it doesn't reveal anything in isolation, but if you know some medical history about some of my relatives and you have their DNA info, then that gives you some significant info about me too.
The arguments boil down to "we're all fucked so letting 23&me fuck us more is no big deal"
> ...this is only a problem because of our disastrous insurance-based, for-profit healthcare system in the U.S.
That is the reality for the subjects of the USA. So it is a problem
>...far more concerned about all the data that various companies are hoovering up about you based on your online activity
No. I take active measures against sneaky surveillance (my browsers cannot be tracked as far as I can tell) and I use my real name lots of places. I am in control. If my siblings, parents, children submit "their" private data to these evil data horders, I am not in control
Deleting your, and yours, data from 23&me will be closing the stable door, I am unconvinced that these sorts of people will actually delete anything (they will remove it from your view and control) but it has performative value
Delete the data!
They’re doing this I found a mutation parentheses (not a polymorphism) in my CVS enzyme that was causing my family to have heart attacks before they were 50.
And I currently diagnosed two people just looking at their genetics one with celiac and the other one with 21 hydroxy deficiency. Just let them impress your doctor for test in proving it was right.
What makes me sad about this is that it’s such a valuable resource that no one’s going to have access to because of corporations and greed. Personalized medicine is the only way to cure diseases and the only way to find out what’s going on in your body.
The risk for privacy is not that one piece of your data is out there, but that companies can recreate a very sophisticated model of you by aggregating many pieces.
The idea that one small breach of privacy is equivalent to the vast amounts of informations 23andme has getting correlated with hundreds of other small pieces, is absurd.
It is a total lie that you should not be concerned about your privacy, because total privacy is impossible. The author also does not understand incognito mode.