{"id":13874,"date":"2018-11-20T08:10:13","date_gmt":"2018-11-20T16:10:13","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2018\/11\/20\/news-7641\/"},"modified":"2018-11-20T08:10:13","modified_gmt":"2018-11-20T16:10:13","slug":"news-7641","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2018\/11\/20\/news-7641\/","title":{"rendered":"What DNA testing kit companies are really doing with your data"},"content":{"rendered":"<p><strong>Credit to Author: Wendy Zamora| Date: Tue, 20 Nov 2018 15:00:00 +0000<\/strong><\/p>\n<p>Sarah* hovered over the mailbox, envelope in hand. She knew as soon as she mailed off her DNA sample, there\u2019d be no turning back. She ran through the information she looked up on 23andMe\u2019s website one more time: the privacy policy, the research parameters, the option to learn about potential health risks, the warning that the findings could have a dramatic impact on her life.<\/p>\n<p>She paused, instinctively retracting her arm from the mailbox opening. Would she live to regret this choice? What could she learn about her family, herself that she may not want to know? How safe did she really feel giving her genetic information away to be studied, shared with others, or even experimented with?<\/p>\n<p>Thinking back to her sign-up experience, Sarah suddenly worried about the massive amount of personally identifiable information she already handed over to the company. With a background in IT, she knew what a juicy target hers and other customers\u2019 data would be for a potential hacker. Realistically, how safe was her data from a potential breach? She tried to recall the specifics of the EULA, but the wall of legalese text melted before her memory.<\/p>\n<p>Pivoting on her heel, Sarah began to turn away from the mailbox when she remembered just why she wanted to sign up for genetic testing in the first place. She was compelled to learn about her own health history after finding out she had a rare genetic disorder,Ehlers-Danlos syndrome, and wanted to present her DNA for the purpose of further research. In addition, she was on a mission to find her mother\u2019s father. She had a vague idea of who he was, but no clue how to track him down, and believed DNA testing could lead her in the right direction.<\/p>\n<p>Sarah closed her eyes and pictured her mother\u2019s face when she told her she found her dad. With renewed conviction, she dropped the envelope in the mailbox. It was done.<\/p>\n<p>*<em>Not her real name. Subject asked that her name be changed to protect her anonymity.<\/em><\/p>\n<h3>An informed decision<\/h3>\n<p>What if Sarah were you? Would you be inclined to test your DNA to find out about your heritage, your potential health risks, or discover long lost family members? Would you want to submit a sample of genetic material for the purpose of testing and research? Would you care to have a trove of personal data stored in a large database alongside millions of other customers? And would you worry about what could be done with that data and genetic sample, both legally and illegally?<\/p>\n<p>Perhaps your curiosity is powerful enough to sign up without thinking through the consequences. But this would be a dire mistake. Sarah spent a long time weighing the pros and cons of her situation, and ultimately made an informed decision about what to do with her data. But even she was missing parts of the puzzle before taking the plunge. DNA testing is so commonplace now that we\u2019re blindly participating without truly understanding the implications.<\/p>\n<p>And there are many. From privacy concerns to law enforcement controversies to life insurance accessibility to employment discrimination, red flags abound. And yet, this fledgling industry shows no signs of stopping. As of 2017, an estimated <a href=\"https:\/\/www.technologyreview.com\/s\/610233\/2017-was-the-year-consumer-dna-testing-blew-up\/\" target=\"_blank\" rel=\"noopener\">12 million people<\/a> have had their DNA analyzed through at-home genealogy tests. Want to venture a guess at how many of those read through the <a href=\"https:\/\/www.23andme.com\/about\/privacy\/\" target=\"_blank\" rel=\"noopener\">21-page privacy policy<\/a> to understand exactly how their data is being used, shared, and protected?<\/p>\n<p>Nowadays, security and privacy cannot be assumed. Between hacks of major social media companies and underhanded sharing of data with third parties, there are ways that companies are both negligent of the dangers of storing data without following best security practices and complicit in the dissemination of data to those willing to pay\u2014whether that\u2019s in the name of research or not.<\/p>\n<p>So I decided to dig into exactly what these at-home DNA testing kit companies are doing to protect their customers\u2019 most precious data, since you can\u2019t get much more personally identifiable than a DNA sample. How seriously are these organizations taking the security of their data? What is being done to secure these massive databases of DNA and other PII? How transparent are these companies with their customers about what\u2019s being done with their data?<\/p>\n<p>There\u2019s a lot to unpack with commercial DNA testing\u2014often pages and pages of documents to sift through regarding privacy, security, and design. It can be mind-numbingly difficult to process, which is why so many customers just breeze through agreements and click \u201cOkay\u201d without really thinking about what they\u2019re purchasing.<\/p>\n<p>But this isn\u2019t some app on your phone or software on your computer. It\u2019s data that could be potentially life-changing. Data that, if misinterpreted, could send people into an emotional tailspin, or worse, a false sense of security. And it\u2019s data that, in the wrong hands, could be used for devastating purposes.<\/p>\n<p>In an effort to better educate users about the pros and cons of participating in at-home DNA testing, I\u2019m going to peel back the layers so customers can see for themselves, as clearly as possible, the areas of concern, as well as the benefits of using this technology. That way, users can make informed choices about their DNA and related data, information that we believe should not be taken or given away lightly.<\/p>\n<p>That way, when it\u2019s your turn to stand in front of the mailbox, you won\u2019t be second-guessing your decision.<\/p>\n<h3>Area of concern: life insurance<\/h3>\n<p>Only a few years ago in the United States, health insurance companies could deny applicants coverage based on pre-existing conditions. While this is thankfully no longer the case, life insurance companies can be more selective about who they cover and how much they charge.<\/p>\n<p>According to the American Counsel for Life Insurers (ACLI), a life insurance company may ask an applicant for any relevant information about his health\u2014and that includes the results of a genetic test, if one was taken. Any indication of health risk could factor into the price tag of coverage here in the United States.<\/p>\n<p>Of course, there\u2019s nothing that forces an individual to disclose that information when applying for life insurance. But the industry relies on honest communication from its customers in order to effectively price policies.<\/p>\n<p>\u201cThe basis of sound underwriting has always been the sharing of information between the applicant and the insurer\u2014and that remains today,\u201d said Dr. Robert Gleeson, consultant for the ACLI. \u201cIt only makes sense for companies to know what the applicant knows. There must be a level playing field.\u201d<\/p>\n<p>The ACLI believes that the introduction of genetic testing can actually help life insurers better determine risk classification, enabling them to offer overall lower premiums for consumers. However, the fact remains: If a patience receives a diagnosis or if genetic testing reveals a high risk for a particular disease, their insurance premiums go up.<\/p>\n<p><a href=\"https:\/\/theconversation.com\/australians-can-be-denied-life-insurance-based-on-genetic-test-results-and-there-is-little-protection-81335\" target=\"_blank\" rel=\"noopener\">In Australia<\/a>, any genetic results deemed a health risk can result in not only increased premiums but denial of coverage altogether. And if you thought Australians could get away with a little white lie of omission when applying for life insurance, they are bound by law to disclose any known genetic test results, including those from at-home DNA testing kits.<\/p>\n<h3>Area of concern: employment<\/h3>\n<p>Going back as far as 1964 to <a href=\"https:\/\/www.eeoc.gov\/laws\/statutes\/titlevii.cfm\" target=\"_blank\" rel=\"noopener\">Title VII<\/a> of the Civil Rights Act, employers cannot discriminate based on race, color, religion, sex, or nationality. Workers with disabilities or other health conditions are protected by the Americans with Disabilities Act, the Rehab Act, and the Family and Medical Leave Act (FMLA).<\/p>\n<p>But these regulations only apply to employees or candidates with a demonstrated health condition or disability. What if genetic tests reveal the <em>potential <\/em>for disability or health concern? For that, we have GINA.<\/p>\n<p>The <a href=\"https:\/\/www.eeoc.gov\/laws\/types\/genetic.cfm\" target=\"_blank\" rel=\"noopener\">Genetic Information Nondiscrimination Act<\/a> (GINA) prohibits the use of genetic information in making employment decisions.<\/p>\n<p>&#8220;Genetic information is protected under GINA, and cannot be considered unless it relates to a legitimate safety-sensitive job function,&#8221; said John Jernigan, People and Culture Operations Director at Malwarebytes.<\/p>\n<p>So that\u2019s what the law says. What happens in reality might be a different story. Unfortunately, it\u2019s popular practice for individuals to share their genetic results online, especially on social media. In fact, 23andMe has even sponsored celebrities unveiling and sharing their results. Surely no one will see videos of stars like Mayim Bialik sharing their 23andMe results live and follow suit.<\/p>\n<p><iframe  src='https:\/\/www.youtube.com\/embed\/RPLuAc_ZkvI?version=3&#038;rel=1&#038;fs=1&#038;autohide=2&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;wmode=transparent' width=\"100%\" height=\"420\" frameborder=\"0\" ><\/iframe> <\/p>\n<p>The hiring process is incredibly subjective. It would be almost impossible to point the finger at any employer and say, \u201cYou didn\u2019t hire me because of the screenshot I shared on Facebook of my 23andMe results!\u201d It could be entirely possible that the candidate was discriminated against, but in court, any he said\/she said arguments will benefit the employer and not the employee.<\/p>\n<p>Our advice: steer clear of sharing the results, especially any screenshots, on social media. You never know how someone could use that information against you.<\/p>\n<h3>Area of concern: personally identifiable information (PII)<\/h3>\n<p>Consumer DNA tests are clearly best known for collecting and analyzing DNA. However just as important\u2014arguably more so to their bottom line\u2014is the personally identifiable information they collect from their customers at various points in their relationship. Organizations are absorbing as much as they can about their customers in the name of research, yes, but also in the name of profit.<\/p>\n<p>What exactly do these companies ask for? Besides the actual DNA sample, they collect and store content from the moment of registration, including your name, credit card, address, email, username and password, and payment methods. But that\u2019s just the tip of the iceberg.<\/p>\n<p>Along with the genetic and registration data, 23andMe also curates self-reported content through a hulking, 45-minute long survey delivered to its customers. This includes asking about disease conditions, medical and family history, personal traits, and ethnicity. 23andMe also tracks your web behavior via cookies, and stores your IP address, browser preference, and which pages you click on. Finally, any data you produce or share on its website, such as text, music, audio, video, images, and messages to other members, belongs to 23andMe. Getting uncomfortable yet? These are hugely attractive targets for cybercriminals.<\/p>\n<div id=\"attachment_26380\" style=\"width: 610px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"26380\" data-permalink=\"https:\/\/blog.malwarebytes.com\/101\/2018\/11\/dna-testing-kit-companies-really-data\/attachment\/questionnaire\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/questionnaire.png\" data-orig-size=\"2448,1360\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"questionnaire\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/questionnaire-300x167.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/questionnaire-600x333.png\" class=\"size-large wp-image-26380\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/questionnaire-600x333.png\" alt=\"\" width=\"600\" height=\"333\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/questionnaire-600x333.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/questionnaire-300x167.png 300w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/p>\n<p class=\"wp-caption-text\">Survey questions gather loads of sensitive PII.<\/p>\n<\/div>\n<p>Oh, but there\u2019s more. Companies such as Ancestry or Helix have ways to keep their customers consistently involved with their data on their sites. They\u2019ll send customers a message saying, \u201cYou disclosed to us you had allergies. We\u2019re doing this study on allergies\u2014can you answer these questions?\u201d And thus even more information is gathered.<\/p>\n<p>Taking a closer look at the companies&#8217; EULAs, you\u2019ll discover that PII can also be gathered from social media, including any likes, tweets, pins, or follow links, as well as any profile information from Facebook if you use it to log into their web portals.<\/p>\n<p>But the information-gathering doesn\u2019t stop there. Ancestry and others will also search public and historical records, such as newspaper mentions, birth, death, and marriage records related to you. In addition, Ancestry cites a frustratingly vague \u201cinformation collected from third parties\u201d bullet point in their privacy policy. Make of that what you will.<\/p>\n<p>Speaking of third parties, many of them will get a good glimpse of who you are thanks to policies that allow for commercial DNA testing companies to market new products offers from business partners, including producing targeted ads personalized to users based on their interests. And finally, according to the privacy policy shared among many of these sites, DNA testing companies can and do sell your aggregate information to third parties \u201cin order to perform business development, initiate research, send you marketing emails, and improve our services.\u201d<\/p>\n<div id=\"attachment_26383\" style=\"width: 610px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"26383\" data-permalink=\"https:\/\/blog.malwarebytes.com\/101\/2018\/11\/dna-testing-kit-companies-really-data\/attachment\/emails-2\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/emails.png\" data-orig-size=\"2168,1214\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"emails\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/emails-300x168.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/emails-600x336.png\" class=\"size-large wp-image-26383\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/emails-600x336.png\" alt=\"\" width=\"600\" height=\"336\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/emails-600x336.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/emails-300x168.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/emails-900x506.png 900w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/emails-400x225.png 400w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/p>\n<p class=\"wp-caption-text\">That&#8217;s a lot of marketing emails.<\/p>\n<\/div>\n<p>One such partner who benefits from the sharing of aggregate information is <a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/xwkaz3\/23andme-sold-access-to-your-dna-library-to-big-pharma-but-you-can-opt-out\" target=\"_blank\" rel=\"noopener\">Big Pharma<\/a>: at-home DNA testing kits profit by selling user data to pharmaceutical companies for development of new drugs. For some, this might constitute crossing the line; for others, it represents being able to help researchers and those suffering from disease with their data.<\/p>\n<p>\u201cYou have to trust all their affiliates, all their employees, all the people that could purchase the company,\u201d said Sarah, our IT girl who elected to participate in 23andMe\u2019s research. \u201cIt\u2019s better to take the mindset that there\u2019s potential that any time this could be seen and accessed by anyone. You should always be willing to accept that risk.\u201d<\/p>\n<p>Sadly, there\u2019s already more than enough reason to assume any of this information could be stolen\u2014because it has.<\/p>\n<p>In June 2018, <a href=\"o%09https:\/www.reuters.com\/article\/us-myheritage-privacy\/security-breach-at-myheritage-website-leaks-details-of-over-92-million-users-idUSKCN1J1308\" target=\"_blank\" rel=\"noopener\">MyHeritage announced<\/a> that the data of over 92 million users was leaked from the company\u2019s website in October the previous year. Emails and hashed passwords were stolen\u2014thankfully, the DNA and other data of customers was safe. Prior to that, the emails and passwords of 300,000 users from Ancestry.com were stolen back in 2015.<\/p>\n<p>But as these databases grow and more information is gathered on individuals, the mark only becomes juicier for threat actors. \u201cThey want to create as broad a profile of the target as possible, not just of the individual but of their associates,\u201d said security expert and founder of <a href=\"https:\/\/haveibeenpwned.com\/\" target=\"_blank\" rel=\"noopener\">Have I Been Pwned<\/a> Troy Hunt, who tipped off Ancestry about their breach. \u201cIf I know who someone\u2019s mother, father, sister, and descendants might be, imagine how convincing a phishing email I could create. Imagine how I could fool your bank.\u201d<\/p>\n<p>Cybercriminals can weaponize data not only to resell to third parties but for blackmail and extortion purposes. Through breaching this data, criminals could dangle coveted genetic, health, and ancestral discoveries in front of their victims. <em>You\u2019ve got a sibling\u2014send money here and we\u2019ll show you who. You\u2019re pre-dispositioned to a disease, but we won&#8217;t tell you which one until you send Bitcoin here.<\/em> Years later, the Ashley Madison breach is still being exploited in this way.<\/p>\n<h3>Doing it right: data stored safely and separately<\/h3>\n<p>With so much sensitive data being collected by DNA testing companies, especially content related to health, one would hope these organizations pay special attention to securing it. In this area, I was pleasantly surprised to learn that several of the top consumer DNA tests banded together to create a robust security policy that aims to protect user data according to best practices.<\/p>\n<p>And what are those practices? For starters, DNA testing kit companies store user PII and genetic data in physically separating computing environments, and encrypt the data at rest and in transit. PII is assigned a randomized customer identification number for identification and customer support services, and genetic information is only identified using a barcode system.<\/p>\n<p>Security is baked into the design of the systems that gather, store, and disseminate data, including explicit security reviews in the software development lifecycle, quality assurance testing, and operational deployment. Security controls are also audited on a regular basis.<\/p>\n<p>Access to the data is restricted to authorized personnel, based on job function and role, in order to reduce the likelihood of malicious insiders compromising or leaking the data. In addition, robust authentication controls, such as <a href=\"https:\/\/blog.malwarebytes.com\/101\/2018\/09\/two-factor-authentication-2fa-secure-seems\/\" target=\"_blank\" rel=\"noopener\">multi-factor authentication<\/a> and single sign-on, prohibit data flowing in and out like the tides.<\/p>\n<p>For additional safety measures, consumer DNA testing companies conduct penetration testing and offer a bug bounty program to shore up vulnerabilities in their web application. Even more care has been taken with security training and awareness programs for employees, and incident management and response plans were developed with guidance from the National Institute of Standards and Technology (NIST).<\/p>\n<p>In the words of the great John Hammond: They spared no expense.<\/p>\n<p>When Hunt made the call to Ancestry about the breach, he recalls that they responded quickly and professionally, unlike other organizations he&#8217;s contacted about data leaks and breaches.<\/p>\n<p>&#8220;There\u2019s always a range of ways organizations tend to deal with this. In some cases, they really don\u2019t want to know. They put up the shutters and stick their head in the sand. In some cases, they deny it, even if the data is right there in front of them.&#8221;<\/p>\n<p>Thankfully, that does not seem to be the case for the major DNA testing businesses.<\/p>\n<h3>Area of concern: law enforcement<\/h3>\n<p>At-home DNA testing kit companies are a little vague about when and under which conditions they would hand over your information to law enforcement, using terms such as \u201cunder certain circumstances\u201d and \u201cwe have to comply with valid requests\u201d without defining the circumstances or indicating what would be considered \u201cvalid.\u201d However, they do provide this <a href=\"https:\/\/www.23andme.com\/transparency-report\/\">transparency report<\/a> that details government requests for data and how they have responded.<\/p>\n<p>Yet, news broke earlier this year that DNA from 23andMe was used to <a href=\"http:\/\/time.com\/5299394\/golden-state-killer-dna\/\" target=\"_blank\" rel=\"noopener\">find the Golden State Killer<\/a>, and it gave consumers collective pause. While putting a serial killer behind bars is worthy cause, the killer was found because a relative of his had participated in 23andMe&#8217;s test, and the DNA was a close enough match to DNA found at the original 1970&#8217;s crime scenes that they were able to pin him down.<\/p>\n<p>This opens up a can of worms about the impact of commercially-generated genetic data being available to law enforcement or other government bodies. How else could this data be used or even abused by police, investigators, or legislatures? The success of the Golden State Killer arrest could lead to re-opening other high-profile cold cases, or eventually turning to the consumer DNA databases every time there&#8217;s DNA evidence found at the scene of a crime.<\/p>\n<p>Because so many individuals have now signed up for commercial DNA tests, odds are <a href=\"o%09https:\/arstechnica.com\/science\/2018\/10\/chances-dna-can-be-used-to-find-your-family-60-percent-and-rising\">60 percent and rising<\/a> that, if you live in the US and are of European descent, you can be identified by information that your relatives have made public. In fact, law enforcement soon may not need a family member to have submitted DNA in order to find matches. According to a <a href=\"https:\/\/www.scientificamerican.com\/article\/how-to-identify-almost-anyone-in-a-consumer-gene-database\/\">study published in <em>Science<\/em><\/a>, that figure will soon rise to 100 percent as consumer DNA databases reach critical mass.<\/p>\n<p>What\u2019s the big deal if DNA is used to capture criminals, though? Putting on my tinfoil hat for a second, I imagine a <em>Minority-Report<\/em>-esque scenario of stopping future crimes or misinterpreting DNA and imprisoning the wrong person. While those scenarios are a little far-fetched, I didn\u2019t have to look too hard for real-life instances of abuse.<\/p>\n<p>In July 2018, Vice reported that <a href=\"https:\/\/news.vice.com\/amp\/en_ca\/article\/wjkxmy\/canada-is-using-ancestry-dna-websites-to-help-it-deport-people\">Canada\u2019s border agency was using data from Ancestry.com and Familytreedna.com<\/a> to establish nationalities of migrants and deport those it found suspect. In an era of high tensions on race, nationality, and immigration, it\u2019s not hard to see how genetic data could be used against an individual or family for any number of civil or human rights violations.<\/p>\n<h3>Area of concern: accuracy of testing results<\/h3>\n<p>While this doesn\u2019t technically fall under the guise of cybersecurity, the accuracy of test results is of concern because these companies are doling out incredibly sensitive information that has the potential to levy dramatic change on peoples\u2019 lives. A <a href=\"https:\/\/www.nature.com\/articles\/gim201838\" target=\"_blank\" rel=\"noopener\">March 2018 study in <em>Nature<\/em><\/a> found that 40 percent of results from at-home DNA testing kits were false positives, meaning someone was deemed \u201cat risk\u201d for a category that later turned out to be benign. That statistic is validated by the fact that test results from different consumer testing companies\u00a0<a href=\"https:\/\/www.seattletimes.com\/seattle-news\/reporters-dna-ancestry-tests-caught-me-off-guard\/\" target=\"_blank\" rel=\"noopener\">can vary dramatically<\/a>.<\/p>\n<p>The relative inaccuracy of the test results is compounded by the fact that there\u2019s a lot of room to misinterpret them. Whether it\u2019s learning you\u2019re high risk for Alzheimer\u2019s or discovering that your father is not really your father, health and ancestry data can be consumed without context, and with no doctor or genetic counselor on hand to soften the blow.<\/p>\n<p>In fact, consumer DNA testing companies are rather reticent to send their users to genetic counselors\u2014it\u2019s essentially antithetical to their mission, which is to make genetic data more accessible to their customers.<\/p>\n<p>Brianne Kirkpatrick, a genetic counselor and ancestry expert with the National Society for Genetic Counselors (NSGC), said that 23andMe once had a fairly prominent link on their website for finding genetic counselors to help users understand their results. That link is now either buried or gone. In addition, she mentioned that a one of her clients had to call 23andMe three times until they finally agreed to recommend Kirkpatrick&#8217;s counseling services.<\/p>\n<p>\u201cThe biggest drawback is people believing that they understand the results when maybe they don\u2019t,\u201d she said. \u201cFor example, people don\u2019t understand that the BRCA1 and BRCA2 testing these companies provide is really only helpful if you\u2019re Ashkenazi Jew. In the fine print, it says they look at three variants out of thousands, and these three are only for this population. But people rush to make a conclusion because at a high level it looks like they should be either relieved or worried. It\u2019s complex information, which is why genetic counselors exist in the first place.\u201d<\/p>\n<div id=\"attachment_26381\" style=\"width: 610px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"26381\" data-permalink=\"https:\/\/blog.malwarebytes.com\/101\/2018\/11\/dna-testing-kit-companies-really-data\/attachment\/genetic_risk\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/genetic_risk.png\" data-orig-size=\"1664,1076\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"genetic_risk\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/genetic_risk-300x194.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/genetic_risk-600x388.png\" class=\"size-large wp-image-26381\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/genetic_risk-600x388.png\" alt=\"\" width=\"600\" height=\"388\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/genetic_risk-600x388.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/genetic_risk-300x194.png 300w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/p>\n<p class=\"wp-caption-text\">But what&#8217;s the symbology?<\/p>\n<\/div>\n<p>The data becomes even more messy when you move beyond users of European descent. People of color, especially those of Asian or African descent, <a href=\"https:\/\/qz.com\/765879\/23andme-has-a-race-problem-when-it-comes-to-ancestry-reports-for-non-whites\/\" target=\"_blank\" rel=\"noopener\">have had a particularly hard go of it<\/a> because they are underrepresented in many companies\u2019 data sets. Often, black, Hispanic, or Asian users receive reports that list parts of their heritage as \u201clow confidence\u201d because their DNA doesn\u2019t sufficiently match the company\u2019s points of reference.<\/p>\n<p>DNA testing companies not only offer sometimes incomplete, inaccurate information that\u2019s easy to misunderstand to their customers, they also provide the raw data output that can be downloaded and then sent to <a href=\"https:\/\/www.reddit.com\/r\/23andme\/comments\/81zyjp\/list_of_sites_for_raw_data\/\" target=\"_blank\" rel=\"noopener\">third party websites<\/a> for even more evaluation. But those sites have not been as historically well-protected as the major consumer DNA testing companies. Once again, the security and privacy of genetic data goes fluttering away into the ether when users upload it, unencrypted and unprotected, to third-party platforms.<\/p>\n<h3>Doing it right: privacy policy<\/h3>\n<p>As an emerging industry, there\u2019s little in the way of regulation or public policy when it comes to consumer genetic testing. Laboratory testing is bound by Medicare and Medicaid clauses, and commercial companies are regulated by the FDA, but DNA testing companies are a little of both, with the added complexity of operating online. The <a href=\"https:\/\/iapp.org\/news\/a\/how-gdpr-changes-the-rules-for-research\/\" target=\"_blank\" rel=\"noopener\">General Data Protection Regulation (GDPR)<\/a> launched in May 2018 requires companies to publicly disclose whether they\u2019ve experienced a cyberattack, and imposes heavy fines for those who are not in compliance. But GDPR only applies to companies doing business in Europe.<\/p>\n<p>As far as legal precedent is concerned, the 1990 California Supreme Court case <a href=\"https:\/\/en.wikipedia.org\/wiki\/Moore_v._Regents_of_the_University_of_California\" target=\"_blank\" rel=\"noopener\">Moore vs. Regents of the University of California<\/a> found that individuals no longer have claim over their genetic data once they relinquish it for medical testing or other forms of study. So if Ancestry sells your DNA to a pharmaceutical company that then uses your cells to find the cure for cancer, you won\u2019t see a dime of compensation. Bummer.<\/p>\n<p>Despite the many opportunities for data to be stolen, abused, misunderstood, and sold to the highest bidder, the law simply hasn\u2019t caught up to our technology. So the teams developing security and privacy policies for DNA testing companies are doing pioneering work, embracing security best practices and transparency at every turn. This is the right thing to do.<\/p>\n<p>Almost two years ago, founders at Helix started working with privacy experts in order to understand all the key pieces they would need to safeguard\u2014and they recognized that there was a need to form a formal coalition to enhance collaboration across the industry.<\/p>\n<p>Through the Future of Privacy forum, they developed an independent think tank focused on creating public policy that leaders in the industry could follow. They teamed up with representatives from 23andMe, Ancestry, and others to create <a href=\"https:\/\/www.23andme.com\/about\/privacy\/\" target=\"_blank\" rel=\"noopener\">a set of standards<\/a> that primarily hammered on the importance of transparency and clear communication with consumers.<\/p>\n<p>\u201cIt is something that we are very passionate about,\u201d said Misha Rashkin, Senior Genetic Counselor at Helix, and an active member of developing the shared privacy policy. \u201cWe\u2019ve spent our careers explaining genetics to people, so there\u2019s a years-long held belief that transparent, appropriate education\u2014meaning developing policy at an approachable reading level\u2014has got to be a cornerstone of people interacting with their DNA.\u201d<\/p>\n<p>While the privacy coalition strived for easy-to-understand language, the fact remains that their privacy policy is a 21-page document that most people are going to ignore. Rashkin and other team members were aware, so they built more touch points for customers to drill into the data and provide consent, including in-product notifications, emails, blog posts, and infographics delivered to customers as they continued to interact with their data on the platform.<\/p>\n<div id=\"attachment_26382\" style=\"width: 610px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"26382\" data-permalink=\"https:\/\/blog.malwarebytes.com\/101\/2018\/11\/dna-testing-kit-companies-really-data\/attachment\/mid-atlantic-settlers\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/mid-atlantic-settlers.png\" data-orig-size=\"2802,1366\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"mid-atlantic settlers\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/mid-atlantic-settlers-300x146.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/mid-atlantic-settlers-600x293.png\" class=\"wp-image-26382 size-large\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/mid-atlantic-settlers-600x293.png\" alt=\"\" width=\"600\" height=\"293\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/mid-atlantic-settlers-600x293.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/mid-atlantic-settlers-300x146.png 300w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/p>\n<p class=\"wp-caption-text\">Maps, diagrams, charts, and other visuals help users better understand their data.<\/p>\n<\/div>\n<p>After Rashkin and company finalized and published their privacy policy, they turned it into a checklist that partners could use to determine baseline security and privacy standards, and what companies need to do to be compliant. But the work won\u2019t stop there.<\/p>\n<p>\u201cThis is just the beginning,\u201d said Elissa Levin Senior Director of Clinical Affairs and Policy at Helix, and a founding member of the privacy policy coalition. \u201cAs the industry evolves, we are planning on continuing to work on these standards and progress them. And then we&#8217;re actually going out to educate policy makers and regulators and the public in general. We want to help them determine what these policies are and differentiate who are the good players and who are the not-so-good players.\u201d<\/p>\n<h3>Biggest area of concern: the unknown<\/h3>\n<p>We just don&#8217;t know what we don&#8217;t know when it comes to technology. When Mark Zuckerberg invented Facebook, he merely wanted an easy way to look at pretty college girls. I don&#8217;t think it entered his wildest dreams that his company&#8217;s platform could be used to directly interfere with a presidential election, or lead to the genocide of citizens in Myanmar. But because of a lack of foresight and an inability to move quickly to right the ship, we&#8217;re now all <a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/09\/millions-of-accounts-affected-in-latest-facebook-hack\/\" target=\"_blank\" rel=\"noopener\">mired in the mud<\/a>.<\/p>\n<p>Right now, cybercriminals aren&#8217;t searching for DNA on the black market, but that doesn&#8217;t mean they won&#8217;t. Cybercrime often follows the path of least resistance\u2014what takes the least amount of effort for the biggest payoff? That&#8217;s why social engineering attacks still vastly outnumber traditional malware infection vectors.<\/p>\n<p>Because of that, cybercriminals likely believe it&#8217;s not worth jumping through hoops to try and break serious encryption for a product (genetic data) that&#8217;s not in demand\u2014yet. But as biometrics and fingerprinting and other biological modes of authentication become more popular, I imagine it&#8217;s only a matter of time before the wagons start circling.<\/p>\n<p>And yet\u2014does it even matter? Even with all of the red flags exposed, millions of customers have taken the leap of faith because their curiosity overpowers their fear, or the immediate gratification is more satisfying than the nebulous, vague \u201cwhat ifs\u201d that we in the security community haven\u2019t solved for. With so much data publicly available, do people even care about privacy anymore?<\/p>\n<p>\u201cThere are changing sentiments about personal data among generations,\u201d said Hunt. \u201cThere\u2019s this entire generation who has grown up sharing their whole world online. This is their new social norm. We\u2019re normalizing the collection of this information. I think if we were to say it\u2019s a bad thing, we\u2019d be projecting our more privacy-conscience viewpoints on them.\u201d<\/p>\n<p>Others believe that, regardless of personal feelings on privacy, this technology isn&#8217;t going away, so we\u2014security experts, consumers, policy makers, and genetic testers alike\u2014need to address its complex security and privacy issues head on.<\/p>\n<p>&#8220;Privacy is such a personal matter. And while there may be trends, that doesn\u2019t necessarily speak to an entire generation. There are people who are more open and there are people who are more concerned,&#8221; said Levin.\u00a0 &#8220;Whether someone is concerned or not, we are going to set these standards and abide by these practices because we think it\u2019s important to protect people, even if they don\u2019t think it\u2019s critical.\u00a0Fundamentally, it does come down to being transparent and helping people be aware of the risk to at least mitigate surprises.&#8221;<\/p>\n<p>Indeed, whether privacy is personally important to you or not, understanding which data is being collected from where and how companies benefit from using your data makes you a more well-informed consumer.<\/p>\n<p>Don\u2019t just check that box. Look deeper, ask questions, and do some self-reflection about what\u2019s important to you. Because right now, if someone steals your data, you might have to change a few passwords or cancel a couple credit cards. You might even be embroiled in <a href=\"https:\/\/blog.malwarebytes.com\/101\/2017\/09\/equifax-aftermath-how-to-protect-against-identity-theft\/\" target=\"_blank\" rel=\"noopener\">identity theft hell<\/a>. But we have no idea what the consequences will be if someone steals your genetic code.<\/p>\n<p>Laws change and society changes. What\u2019s legal and sanctioned now may not be in the future. But that data is going to be around a long time. And you cannot change your DNA.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/101\/2018\/11\/dna-testing-kit-companies-really-data\/\">What DNA testing kit companies are really doing with your data<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/101\/2018\/11\/dna-testing-kit-companies-really-data\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Wendy Zamora| Date: Tue, 20 Nov 2018 15:00:00 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/101\/2018\/11\/dna-testing-kit-companies-really-data\/' title='What DNA testing kit companies are really doing with your data'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/shutterstock_464368688.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>Consumer DNA testing kits were a top holiday present last season, and are expected to be big sellers again. But should you think twice before hitting the buy button? What&#8217;s really happening with all your genetic data? We take a deep dive into all the areas of concern\u2014plus what the testing companies are getting right\u2014when it comes to the security of your DNA and the privacy of your sensitive personal information.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/101\/\" rel=\"category tag\">101<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/data-storage\/\" rel=\"tag\">data storage<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/dna\/\" rel=\"tag\">dna<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/genetic-data\/\" rel=\"tag\">genetic data<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/genetic-info\/\" rel=\"tag\">genetic info<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/gina\/\" rel=\"tag\">GINA<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/pii\/\" rel=\"tag\">PII<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/privacy\/\" rel=\"tag\">privacy<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/privacy-policy\/\" rel=\"tag\">privacy policy<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/101\/2018\/11\/dna-testing-kit-companies-really-data\/' title='What DNA testing kit companies are really doing with your data'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/101\/2018\/11\/dna-testing-kit-companies-really-data\/\">What DNA testing kit companies are really doing with your data<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[10519,12066,13650,20209,20210,20211,19131,5897,18883],"class_list":["post-13874","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-10519","tag-data-storage","tag-dna","tag-genetic-data","tag-genetic-info","tag-gina","tag-pii","tag-privacy","tag-privacy-policy"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/13874","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=13874"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/13874\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=13874"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=13874"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=13874"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}