23andMe DNA data hack, Bruce Schneier & John Greally, M.D.
In this episode
Watch #cybersecurity #hacking expert Bruce Schneier @schneierblog & #genetics #DNA expert John Greally, M.D. @greally discuss the #23andMe DNA data #hack consequences, how & why it happened, who did it, & how to protect yourself. For more information about the interview guests go to http://Schneier.com & https://www.einsteinmed.edu/faculty/4156/john-greally/
Thanks for tuning in to Episode #28 of The Doctor Podcast Show. I'm Doctor Robert Seiker, your host, and today we're going to be discussing a very important topic. As you may have heard in the news, about three months ago in October there was a break in into the 23andMe computer system where the DNA of about 14 million people is held. Now I'm an ophthalmologist, A physician, but many of my patients always ask me for advice, referral to other doctors, other medical advice. And many of my patients were concerned about this hack because they had donated their DNA to 23andMe and they were concerned that there might be some issues and problems with this in the future.
And I really couldn't answer them and tell them what to do about it and what happened and why it happened and whether they should be concerned or not. So I decided to check some media and websites, but I really couldn't learn too much about it. And that point I realized I need to talk to some experts. So I decided to contact experts who are on the program with me today. And we have Bruce Schneider, who is one of the world's leading experts on cybersecurity and hacking and also on cryptography. And Bruce has written many books on these subjects.
He's been a New York Times bestselling author, and he has a book out now called A Hacker's Mind, which talks about the subject. So Bruce is an excellent expert on this topic, but we also need an expert on DNA and genetics. So I invited Doctor John Greeley. Doctor Greeley is a professor of Pediatrics and genetics and is an Epigenomics expert as well. And ADNA expert. And he's a professor at the Albert Einstein College of Medicine here in New York City. So between Bruce and John, we we should be able to figure out what happened here, why it happened and what the short and long term consequences are.
I'd like to start with you John, for a moment. If you could just explain to us what DNA is and most people know, but maybe there are some people out there who still not familiar with it and explain how people gave their DNA to 23andMe. Thanks for having me on, Robert, and I'm looking forward to this, to learning from Bruce about what his perspective is on this hack as well. So every week when I see patients in my clinic at Montefiore in the Bronx, I have to do exactly this kind of explanation of what is DNA and why is it something that is relevant to people's lives and especially their health.
So in at its most fundamental, it's a sequence of ACG and T that is patterned in a way that allows us to create genes that produce every protein in our bodies and allow us to form the way that we are and importantly, have variation from person to person. We have about 4 million places in our 3 billion base per genome where there's some variability to distinguish the three of us. Now when you have that variability, that most of it is going to give rise to things like differences in height and hair color and things like that, but some of it can also give rise to risks of disease.
The other thing that of course 23andMe has been able to do by looking at these sequences is to tell you what population on planet Earth do you most resemble. And that's that's why a lot of people would have bought these, these kits in the first place. I have to confess, I was an early adopter of 23andMe in the era of when they were offering genetic testing before they were shut down by the Federal Trade Commission. And I wanted to see what was it like when the when the test results were pointed at me as a physician because then I'd have a little bit more insight into what my patients were going through.
So I found that I basically didn't have any of the the genetic changes that they were associating with disease. I found it an interesting process to to think through what the implications would have been for me if I had found something. And I discovered that my ancestry is 100% from the West of Ireland, which was no shock whatsoever. Right, right. We can tell from from what you're saying. So that's very interesting. That's how they got the DNA people just donated and I I understand they can donate their saliva and their saliva contains DNA material.
Is that right? Yeah, if you, if you were to put saliva under a microscope as well as seeing a lot of little microorganisms, you'd see cells. So these cells are in part the cells that come from the inside of your cheek, the the lining of your your mouth. But most of the cells are actually from blood and it has to do with the fact that around your teeth you have a little bit of inflammation all the time and those cells end up populating your saliva. So it's a mixture of two different cell types, but each of them has exactly the DNA that is part of your entire body.
So it's it's as good a source of DNA in most respects as getting a sample of blood. So now once you send that to 23andMe, they have your entire DNA code, right? They do and they don't. So they have your sample of DNA, Oh, sorry, your sample of saliva that they extract to make your sample of DNA. And what they can then do is anything that they want. But what they've done in order to have a cost effective test that they can sell at a profit is they don't look at all of the three billion base pairs.
They look at a subset of the of the places where which are variable in the genome. So it's I'm not sure what exactly they do, but it's it's probably of the order of a couple of million of these base pairs. So it's a tiny sampling of the genome, but it's enough to tell you about ancestry. It's enough to tell you about some of the diseases that they now look for. Again, having been stopped looking at it for a number of years, it's and it's enough to to link to things like preferences for for whether you think cilantro tastes like soap or something delicious.
So Dave, it's some quirky stuff in there as well as the ancestry things and the disease relevant changes. Interesting. So Bruce, from what I've read in the media and and on the web is that somehow somebody stole passwords to the 23andMe site. Normally my understanding is to get into the site and look at your information there you need a username and a password. And according to the media and 23andMe, a few 1000 passwords were stolen. And then somebody was able to get into their websites and into their computer system and into their database.
And then using that information they are able to extract about 7 million people's DNA information in addition to their private other information. Does that sound plausible, Bruce? Oh, of course it's plausible. I mean the the details are a little bit off but a lot we don't know. First I want to take issue with the when you said that people donated their DNA, this is not a charity. This is you're not donating your used clothing. That's a business that you send your DNA sample to. They analyze it and send you an information about it.
And as a business, they promise to keep that information private. And that's, that's that's what they do. And so, yes, near as we can tell, and I'm going to say near as we can tell because data's fuzzy here, I'm sure the company's going to be sued. So lawyers looking over everything said, there are SEC filings, there were initial announcements. Some of it didn't make sense. There are later ones. So a lot of caveats. So it looks like hackers got into 23andMe probably last fall using something called credential stuffing.
And what this is, is using the username and password that you use for something else that was otherwise compromised. So I'm going to make this up. You have a username and password and you're using it on this gaming site, and that gaming site was hacked and the hackers published all the usernames and passwords. This happens all the time. And what clever hackers do is take those new passwords and try them elsewhere. So they'll go to a bank and try all of these names and passwords that were hacked from this gaming site.
Because maybe some of them are going to work. And some hackers did that with 23andMe and surprise, about 14,000 worked. So that's 14,000 people who are compromised. And exactly what was compromised, there are differing reports, DNA information probably, but your username, maybe your address, I don't know, maybe your credit card data, some demographic stuff you put in, whatever is in your account. Now 23andMe has a feature where you can publish your information to your relatives. And the neat thing about DNA is it tells you who's related to who.
And a lot of people use this for genealogical research. So in the spirit of genealogical research, 23andMe allows people to tag figure out who their relatives are using the DNA. Right now that information is going to be in your account, so if someone hacks your account, they'll hack that information. So now there's an additional 1.4 million I saw somewhere else, 5.5 million I saw somewhere you said, you know, seven point or something. I mean the numbers are kind of unclear, but it blows up enormously when relatives taken into account.
So that's basically what happened. Right. But the question is, if let's say you've got 7000 passwords that work that you've stolen from some other site, you've stolen hundreds of thousands of other usernames and passwords, don't you have to sit there and put all of those into the 23andMe system to see you do but? Luckily you have a computer, so you can push a button, take a nap, and the computer does all the work for you. Remember, all this is automated, so when I say that we try the passwords, we don't actually sit and type them in.
That would be boring like everybody else. Hackers use computers to repeat boring, repetitive tasks. And this credential stuffing is not a new tactic. This is very common. Usually you'll see it against banks, Bitcoin wallets. I mean, lots of places you can get money having it done against a site where you just get data, you know, that's more pranky than it is criminal, because what are you going to do with this data? Right now, when I log into some of my websites, occasionally if I log in from a different location, it'll say, oh, you're not from your original computer.
We need to do 2 factor authentication, other things. So shouldn't 23andMe's computers notice that somebody is putting in thousands, 10s of thousands, maybe hundreds of thousands of passwords in a very rapid pace? Doesn't that imply that there's a hack going on? I assume they're not doing it from thousands of computers. There's probably just a few computers. So it's all coming from just a limited number of IP addresses. Shouldn't that be caught? And now you're pointing out why we're blaming 23andMe and not the victims.
And 23 me actually released a statement saying, like, not our fault, the users, we use their passwords, so who on them? But as you point out, we have lots of good techniques to prevent credential stuffing. And lots of sites either mandate to factor authentication. Or as you pointed out, if you log in from a new computer, the site recognizes it and says, wait a second, it's a new computer, I'm going to send you a text message. I'm going to do something else, demand some more information. And that's to prevent these sorts of attacks.
And the fact that 23 Enemy didn't have that in place, I mean that's going to be the reason why they are fine. There are lawsuits. That's what they did wrong. Well. They either we want. Users to choose new passwords for everything they do. Right. But you don't always get that. But maybe either they didn't have it in place or could the hackers have? Possibly change the computer programming to trick 23andMe to not realize. No, they didn't. 23andMe didn't have it in place. We know that. Well, once you log in, shouldn't there be some sort of safety feature that prevents you from getting into all the other data and information they have about people who donate?
You could do that mean 23 me didn't and and and you know if you have a bank account you'll notice that's true, right? There's some things you can do on the website, some things you can't require digital authentication or you know, maybe some other controls. I mean I can wire $1000 to you without a problem. If I don't wire $50,000 or some you know, site in Eastern Europe, they're going to be with some more checks. 23 to me didn't have any of that in place, so when the hackers got in, they got everything.
You're pretty sure that the safety features weren't disabled by the hacker. The hackers didn't hack the the the network, so that wasn't the way the hack worked, right? So the only way the hackers got in 23 Andme was through the passwords. They had no ability to change what the network did, and if they did that they wouldn't need to do password stuffing. So yes, where we are sure that that's not the way the hack worked in this case. Other cases your hypothesis might be correct. In this case it wasn't.
It was kind of basic stuff here. All right. So, John, going back to you, so now there's this stolen DNA information that's matched with other private information. What can these hackers do with this material? To be honest with you, not too much you you have to try and think of what could you do that'd be harmful. What would you pay them to avoid doing to you? So there will be some things like you actually you you have a disease risk that you've chosen not to have reported back to you. If that was part of the file that that the hackers were able to get into, they could potentially start use that in some way or tell, say that you're they're going to sell, send it to your employer or something like that.
Now we do have some laws in the United States as regards the harmful use of genetic information. There's a law called a federal law called a gena gena. The genetic information on discrimination and what it does is 2 things very specifically. One is it doesn't allow any discrimination against you in the workplace. And the second is that it doesn't allow you to be discriminated against in terms of your health insurance. What it doesn't do and what what would be great to be able to expand it to do is other spaces are not protected, like your your school, your your college, things like that.
There there are other places that it would be usefully expanded to. And then there are other types of insurance. There's life insurance, long term care and disability insurance. They're not covered by Gina. So if if there was something embarrassing about your health that could be disclosed from this information, then this could be used against you in some of these more vulnerable areas that you have one of the. Types of insurance are are not covered. In other words, potentially the hackers could threaten to leak your DNA information and disease predisposition to an insurance company, which might then either increase your premiums or deny you insurance.
Did that happen? Absolutely. It's a it's a real possibility and I would be very concerned myself if that was if I was vulnerable to that. There is also you know they'll have information about family relationships. They they may they may talk about releasing embarrassing information to your family. They may talk about how there's something about you've got a half brother, did you know that budget. Do you want them to know that you're that you're related to them Family relationships. They're also quite private and you don't know the circumstances.
Maybe the two half brothers know each other very well. Although I know somebody who did a 23andMe test with his brother and the result said so this is your half brother and he had no idea. So 23andMe can reveal things that are dead, disturb your sense of self in in terms of your identity and that can also expand over to ancestry. So if somebody is very proudly a member of some ethnic group and it's very important in terms of their membership of that community and they find that actually half their DNA is not from that community and they they relate that to their their membership of the community, which is their DNA, doesn't make you who you are in terms of your community relations.
This is a big issue with our indigenous friends. So you can, but you can misinterpret it and it can damage yourself sense of self. So there are many ways that the information could be used against you. But one of the things that has come up when I deal with patients and people from vulnerable communities is there's this assumption that says that there was information in DNA that can be used to kill you, that they'll find vulnerabilities for. There's some chemical or drug or something that could be used to wipe not not only you, but other members of your ethnic group or or or race these.
You know, there there have been movies with this kind of a plot. So people have fears. So it's not so much important whether it's a fear is realistic or not. The importance is whether people have the fears to start with. And so when you have sensitive information like 23andMe have, and people have fears about this, the misuse of this kind of information, it's not up to 23andMe or me as a physician or a health system or whoever else holds these data to define what the patient should be worried about.
It's up to us to respond to even the least rational of fears because that's how we're responsible in our relationship with the individual who's either getting care from us. We're buying our service. Right. A couple of my patients voiced to me that they're concerned about paternity issues. For example, they could approach somebody and say, you know, we've got your daughter's DNA and your DNA turns out there's not a good match. How much will you pay us to not tell your daughter or the rest of your family?
Could that be done? Oh, absolutely. And that's exactly the kind of example of familial relationships that are potentially areas of embarrassment. Right now, Bruce, what about some people are concerned that the police or other government security agencies might get a hold of this DNA and possibly use it against the person. Is that reasonable fear? It's reasonable, has nothing to do with this hack, but of course it's reasonable. The police are mining these DNA databases 23andMe answer g.com. Other companies are readily share information with the police and that's used to solve crimes.
And it's kind of interesting because it's DNA, it's not necessarily the criminals who send their DNA, it's often a relative. So there are bunches of crimes solved because, you know, 3 second cousins pop up in the DNA database and the police triangulate. Who's the common relative among these three people? Or it is a first cousin of this person. So the police will call this person and say we think your first cousin is a serial killer. And the first cousin says, Oh yeah, it's the crazy one nobody associated with anymore.
Must be him. Here's his last known address. Right. Lots of things like this to happen. Nothing to do with the hack, but yes, and people are rightly concerned that their privacy is being violated even if they are not using the system because some of their relatives are. Now, what's happening in this hack case is that the the hackers have tried to sell the data on the dark web. Have they succeeded? Hard to tell. Probably not. My guess this is not very valuable. A company would never buy this. An insurance company is not going to buy stolen data and use it to deny people's medical insurance.
That is an enormous criminal violation. People will go to jail for that, and they know it. They have enough ways to make money screwing you over without having to be blatantly illegal. So that's not going to happen, right? The police aren't going to go after this data. They have lots of legal ways to get your DNA data if they want it like warrants, and even just asking these companies because they just hand them over. So, you know, my guess is this is more of a prank than anything else. I think the hackers tried it because you know, why not?
It's easy to try. They got in, they got lucky. They got how much of data They're trying to sell it. I don't think there's going to be a buyer because, well, you know there is Blackmail attempts, blackmails, hard, you know it. It's not a a crime. You just do with a computer and then and get away with it. It requires interactions and yes, you can use Bitcoin to get your ransom and that's safer than trying to get a suitcase full of $100 bills from somebody at a parking lot. But you know, there's still risk there.
So in this case, the privacy violation is more personal. What might happen here is after the criminals realize not getting any money from it, they'll just dump the data and now it becomes available to everybody to look at. And right there are those potential embarrassments John mentioned. If you have a disease that you don't want to talk about, it could show up in the data. You know, it kind of reminds me of when I remember when Ashley Madison was hacked. That was the the illicit affair website and the data was just posted and then everyone would like looked up their partner.
And I'm sure there were lots of very heated discussions in families all over the world after that. I mean, this is that kind of thing, but not nearly as as gross. Right. So your best guess is this is some prankster, Maybe some young kids. I think they call. It's hard to figure out how to make good money here. You know, I yeah. I see. That's pretty interesting. Now I read in in some media and some websites that apparently the hackers claimed they had information about Jewish people, a huge accumulation of DNA from from Jewish people.
And also they had information about British royalty for some reason. I don't know how that fits in or why they would disclose that. Any Any ideas there, John, about why they'd be interested in DNA from Jewish Ashkenazi people or DNA from British royalty, the king? Royalty DNA is probably worth money. The tabloids will pay for that. Ashkenazi Jews, I'm not quite sure as it's valuable. Why is? You know why is British royalty DNA valuable? Because the British tabloids love to publish Chelsea's articles about their royalty, John being close to their British Isles than I am, you can talk about the tabloids.
Yeah, John, tell us. I would like to stress at this point that Ireland is a separate jurisdiction and we got our independence from our colonial power some time ago. But everything that Bruce is saying is correct, what they call the red tops over there because they they the name of the newspapers and it read salacious, doesn't even begin to describe them. They've been hacking phones. It was as well a publicized case of Harry, I think was 1 the fellow whose phone was hacked. They'll publish anything.
They're they're it's pretty vile. But getting back to the Ashkenazi Jewish focus, that appeared to be the case in the 23andMe hack. Obviously I'm I'm concerned about one thing, which is that there could be an element of anti-Semitism involved and it was a selective hack. But what I wonder is based on what Bruce was saying about this idea that if you can get into one person's account, you can then start to capture more individuals. The ability to call relatives is going to differ from ethnic group to ethnic group.
And some, some ethnic groups are more interrelated. The Ashkenazi Jewish individuals, Irish people, people from Puerto Rico, some religious groups within the United States like the Amish and so on. So this is actually surprisingly common. But if you have people who are Ashkenazi Jewish, they've gone in there to to test their DNA and they end up being the easiest ones to disseminate For more information, then it could have inadvertently ended up enriching for Ashkenazi Jewish individuals. But of course you you do worry that they that there is some element of malevolence towards Jewish people, which would be kind of disgusting.
So now that we've talked about this, what can people do to protect themselves? I've read that 23andMe decided to use two factor authentication after this happened. Is that sufficient protection? Is is that going to work or are there ways that that can be hacked as well? You know, lots of these companies get hacked all sorts of ways. This was kind of a kindergarten hack. So you know, a basic security measure will will defend against it. And not just 23 Andme. Some of their competitors also have upped their game here.
But you know, companies have been hacked directly, not through the users, but through the networks. In the end, there's nothing you can do. When you use any company where you give them your data, whether it is a you know, DNA testing company or a genealogical database or your e-mail provider or your cell phone company, you are trusting that company. Period. Full stop. There's nothing you can do to protect yourself on their network. I mean this basic hygiene right? Use to back authentication when you can.
Don't reuse your passwords. This is like the lesson for users here. And use a password manager, by the way. So you'll remember your good passwords, right? Your browser will remember passwords, your phone remember your passwords, choose passwords you can't remember. But that's really in the noise, you know, The way these companies work is there's no real rules. They can do what they want, and they're going to have lousy security because it's cheaper. So all you can do is trust them, and you have no reason to trust them.
It's no fun, but that's the way we live. So you're saying it's more and yeah, go ahead. John, I'd add just to that Robert, because I think that there's another element to this which is I would say that 23andMe would have a disincentive to make it look like the privacy of your DNA is a big deal for them to to say that you need to have two factor authentication because you're actually sharing pretty private information with us. Then people may think twice about whether they're going to buy this kiss in in in a in a pharmacy and and reveal this information to a a, a company.
What I think is going to trend over the next several years is a tendency towards more concern about sharing your genomic information in particular as opposed to people becoming more blase about it. And the reason that I think that it's going to become a pressing issue is because what you're able to do with 23andMe for a very small subset of your DNA sequence is now going to be possible for your entire genome, the 3 billion base pairs. Because the cost of sequencing each of our human genomes right now has come down to $100.
So if you're at the end of the year and your health savings account has got a few 100 bucks left in it and that's enough to pay for the reagents and you know the sort of processing of your of your information and you have a choice whether you're going to get your your DNA sequenced or get a new pair of glasses and they're kind of the same price point to that point you're going to have. You're going to want to know two things when when you make that decision. One is, is there some benefit to me to have my DNA sequence reported back to me in some way?
And honestly the the likes of 23andMe is not providing much of A benefit from from the information. It's it's mostly a benefit to 23andMe as opposed to the consumer of their product. But the other thing that's going to become a big deal is these sort of stories are just going to become more and more prevalent where they've been. There's been misuse of people's genomic information and there are going to be some real tragedies where people will have, you know, had real damage to them because of these kinds of hacks and losing control over their privacy.
So I think that what's going to happen over the next several years is that we are going to see a tendency towards people looking at their genomic information in the same the way they should. It's like a naked picture of yourself. You wouldn't share a naked picture of yourself with some random people out in California who say that they're going to you know tell you about your ancestry from from you know, a naked picture of yourself. It's it's the same kind of information when you're when you're sharing your genomics sequence And as people begin to realize that we we will ask for more from people who are doing our testing whether it's commercial entities like 23andMe or our healthcare systems.
And that's completely fair. People should own their own information and when they share their information it should be respected. And if it's not respected, we should have legislative recourse in place so that people are forced to do to do the right thing, as opposed to shutting the door after the horse is bolted, which has just happened with 23andMe. Right. Great points. And I was just going to ask you, I read yesterday that the Mayo Clinic is doing a partnership with a startup AI company to evaluate genomic information that they have.
And apparently they have 100,000 people who've given their DNA to the Mayo Clinic. I I foresee something bad happening there as well, especially if they're sharing it with a startup AI company. How do people protect themselves from that? Yeah, this is, this is only one example of quite a few population scale studies that are that are being performed around the country. There's a large study in Utah in through Intermountain Health System, there's a study of the veterans, the Melan Veterans program.
There's the All of Us program which is being run by the National Institutes of Health and then there are individual hospital systems like Geisinger in Pennsylvania, Mount Sinai here in New York. And the idea is if you can get a lot of people's information, you can link it to health system information, you can make it get insights and that's really, really valuable. And some of these programs, I think the All of Us program in particular is quite careful about the the protection of people's privacy and dignity.
But the I agree with you that it has to be done in a very responsible way. The incentives for people who are in like an AI company or the even the academics in an institution are that you want people to just give their information and kind of trust you to use it the right way. Whereas and if you have any sort of restrictions on that, on that sharing of the information, it's going to cramp your style, it's going to reduce your ability to make discoveries. So the people who are inherently involved with these kinds of biobanks are kind of conflicted.
And so just to put it into a slightly different perspective, and I'm sorry, Bruce, I'm trying to to hog the conversation here. I'll shut up after this. We have been approached in the Bronx on numerous occasions to buy companies who would like to sequence the the people of the Bronx. The people of the Bronx are enormously valuable to these kinds of companies because of the diversity of the genomes of the Bronx. The Bronx is incredibly diverse. 91% of people in the Bronx are not Northern European white in their genetic ancestry, so that means there's more space for discovery.
But the what we have to have in the Bronx because of the fact that people are naturally suspicious that things could be used against them, is a a a different kind of a data sharing model in which it's absolutely clear that there will be no risk to privacy and dignity. So that's where you have to go from trust to control. Trust is somebody says, I believe that this Irish lad is going to be, you know, careful about my DNA sequence. And I live here in the Bronx and he works at Montefiore and that's all good.
But there's uncertainty there because I could be, I could be a jerk and I'm just hiding it really well. But if you give people control where you can't, you can't use that information. It doesn't leave the server. You know, it has all the protections that Bruce would be expert in so that you people can't get in there easily, then control Trump's trust every time. We have to have a model that allows people to have that control over, as I say, what would be the equivalent of a picture of them naked.
We have to be careful with these sensitivities. That's the kind of standard thing we talk about in security, privacy all the time that people need control of over their data. That is not just trust me with it, it's it's I have control over how it's used. And what's interesting, what John's talking about is the difference between a university study, a medical hospital study, right, a research study and a for profit corporation like mining your DNA and trying to figure out how to make money off it.
You'll be there'll be different incentives there to give users, patients more control, more trust. I would be much more comfortable giving the Mayo Clinic my DNA than I would be giving 23andMe my DNA because the Mayo Clinic is is subject to a whole lot of medical privacy rules that 23andMe is not because they're not a healthcare provider, they're an information system. So I think John was really on the right track about trust and control, but I wanna you know, bring that that profit motive versus research motive into play here.
Right. So trust and control is great, but then the person has to also verify you. You heard? No way to verify. No way to verify. You mean I will never be able to verify how John treats my medical data? But I can't go into his computer system. I can't go into his network. You're not going to let me order this stuff and like, I'm someone who knows how to do it. The average patient has no idea. In the end, you have to trust. Just like, you know, you go into a restaurant, you know, maybe, maybe you look at like the health code sticker on the door.
But generally you have to trust society works that way in everything. Right. So that brings me to my next question. I think, Bruce, in the year 2000, you wrote somewhere that if McDonald's was giving out free hamburgers for your DNA sample, there would be a line around the block of people giving their DNA to McDonald's for a free hamburger. So are are we giving away our private information and DNA and data too easily and? All the time. And in fact, in Brazil a couple of weeks ago there was a report that they would get either McDonald's or burger.
I forget which one. They give away free hamburgers for face scans. Yeah, no, this face scan was going to tell you if you look drunk or not. So there was a whole little game going on. They were collecting face scans for hamburgers. So what I said, the year 2000 actually came true this year. You know, we give away some very private data all the time, right? I mean, this is a portable surveillance device. This knows where I am at all times, knows when I wake up, when I go to sleep. We all have one.
It knows who I sleep with, right? Knows who I talk to, knows what I say, right. You know. Yes, modern computer society involves us giving away our privacy again and again. And you know, I am not an EU citizen, so I the European Data Protection Act does not apply to me. And this data is used by private corporations in all sorts of ways. There's a vibrant data broker industry in the United States. That data is bought and sold and combined and used in ways that you have no idea. Because we do not have adequate privacy protections.
So this is much bigger than ancestry data than than your DNA. Now it's actually things that potentially more immediately intimate. But yes, that's that's the way society works today. So the next question is, if we're giving it away for a hamburger, maybe people should get compensated for giving their DNA. Instead of 23andMe charging you money to take your DNA sample, if 23andMe and Ancestry and the other sites are using that data for profit making, why should the individual who's donated that data get a piece of the action?
In other words, can I copyright my DNA? It's my DNA. If you make a dollar off of it, I get 20%. You know, so lots of people talk about people should be paid for their data. Now, currently the debate is paid for by the AI companies or the AIS are training on all of our data. Maybe they should pay us for it. My general problem with property regimes for your personal data is they don't work. I tend to fall in a rights regime. So you know, you are not allowed to be in a medical environment here. You're not allowed to sell your kidney, right?
There is no commerce in human organs. We have decided as society that that is something that is not subject to property rules. There are rights involved, right? There are fundamental human rights. I think data, your personal data is more about rights than property. And this is this is the way the EU falls as well. I mean, the EU law looks at your rights to your data. So it's not like your DNA is like, you know, a book that you can sell. It is part of you, you know, in a similar way your kidney is part of you and that you have rights to it.
But there, there's a difference. If if you give away your kidney, that requires major surgery, which there's risks for, and that that's an issue. Giving away your DNA is 0 risk. About selling, giving it away, right. So through there. But there is risk. We've talked about the risk, right? You can decide that property regimes for data is the way to go. And their persuasive arguments on the Internet that you can read their persuasive arguments that that rights is a better regime. I fall on rights. I think if it's property, it'll be abused and you will not get the protections you want and the the price will drop to 0.
You'll get, you won't get, you don't get 20%, you'll get $0.20, which is basically right. You'll get a hamburger. You won't get a continuing revenue stream because the data is valuable in aggregate, It's not valuable individually. If you think about things John was talking about, the value of DNA data really is the research, the discoveries, putting it all together, learning things. Having said that there is a couple of yeah, I was going to say there are a couple of paradigms actually that that address this idea of sharing in profit.
Because if if there have been some discoveries made that have been very positive in terms of coming up with new therapeutic approaches for certain common diseases. They're one of the biggest early national scale studies of the population's DNA was in Iceland a population of about 300,000 people. And I have no idea how how people do things in Iceland. They've they've a huge number of people in bands. They've a huge number of people who are creative. It seems like it must be the same people over and over again, because I can't imagine how 300,000 people have such such an influence.
But when some very enterprising geneticists said, Iceland is great for keeping genealogical records and there's a lot of interrelatedness of of people there. And so there was a great opportunity to make some discoveries about genetics of of common diseases. So at the early stage of trying to persuade the politicians and the people that this was, that this was potentially beneficial to them to participate. I'm trying to remember the name of the drug company, but I think it was Hoffman, the Roche, which doesn't exist anymore.
It's been through acquisitions who said that if drugs were discovered based on findings in the Icelandic people, they would be made available to the Icelandic people for free. So that very quickly disappeared as a promise as they set up the actual biobank and started to do the genetic studies. But it was part of the agreement that was being put in front of the Icelandic people. If you Fast forward to the modern day, the people who really impressed me as regards thinking through these issues because of a lot of past and ongoing injustices that they've suffered is our indigenous colleagues there.
There's a group of individuals who have, you know, degrees and have PhD degrees and other scientists and other representatives were involved with this initiative called the Native Bio Data Consortium and they are very clear. If you want to work with a specific tribal group, tribal nation, you don't go and talk to, you know, just random person X from that population. You first of all talk to the tribal elders. You explain what it is that you want to do and everything that will be upside and downside about it, and then with their their permission you can go.
And with the permission of the tribal elders you can go and approach the individuals from from the from the nation. But what they want is to be involved in genetics research, but not exploited by it. And if there is profit made from it, they very sensibly want to be made part of the the what would be due to them for having created the essential intellectual property that allowed the discoveries to be made in the first place. So it's actually a reasonable question for people to say if you discover something with on me and 200,000 other people that use sequenced up in the Bronx, shouldn't I get something from that?
And it could be as simple as if you live in one of the 25 zip codes in the Bronx, we will give you this medicine for free or at cost or something like that. There are ways of doing this. There's ways to compensate people. I think we have to work that out in the future. Related to this subject is EMR or electronic Medical records or EHR electronic health records. You've probably read there have been numerous hacks of hospitals, major medical centers and networks and it's increasing all the time. And there's ransoms being paid millions of dollars.
What I've noticed is that more and more of the different hospitals are now network together. So when I go to the hospital and look up one of my patients, I also see information from numerous other hospitals that that patient has been in and other doctors offices. My concern is there is, is that if these network systems are hacked, then not only will they get DNA data but other personal medical data. And it's concerning that there are more and more hacks. Bruce, what do you think is going on there?
Why are there more hacks? And are we protecting our medical data? Sufficiently, yeah. Hospitals are a prime target of ransomware. Couple of reasons. They tend to have outdated IT and they don't have the newest stuff because they're often underfunded. The department and a lot of the random equipment at a hospital that's computer networked doesn't get updated. So they tend to be pretty vulnerable. So they are they are a target they're they're tend to be a juicy target. Also, municipalities also seem to be a juicy target for the same reasons.
So there's nothing about hospital data, it's just that they are more vulnerable. A ransomware is is peculiar in that for the most part nothing is stolen. The data is locked up. And so a bunch of years ago, criminals realized that the most that the the the person to whom the data is most valuable to is the person you stole it from, right? So rather than sell your data, they lock it up and then ransom it back to you. And that is far more profitable to figure out a buyer. It's like nobody wants to buy a hospital's data.
The hospital certainly wants it back. That has changed because as an incentive to get victims to pay the ransom, the data is stolen. So there's a threat we're going to publish it in addition to the the threat that you can't get it back. So we're we're seeing that kind of double threat happening and bunch of companies have had their data released by after refusing to pay a ransom. Jeff Bezos famously was hacked, his data was stolen, he refused to pay a ransom, it was published. So, so that does happen.
So nothing special about medical data here, it's just that the networks are more vulnerable. And you know, so two things that make this crime possible, one is the the fact that this ransom cellulator back to the victim. And two is cryptocurrencies that allow ransoms to be paid over the network without going through the banking system, which basically doesn't allow for this kind of transaction to happen. We get paid in Bitcoin, which can't be traced or it's very difficult to be. More complicated than that, but basically Bitcoin can't be interdicted easily.
That's the point, right? If you are a Russian criminal gang, right, good luck getting getting a merchant account on Visa. It's not going to happen, but you can get a Bitcoin account pretty easily. So you mentioned that hospital networks or maybe are not up to date in their software and hardware and that's why they're targets. What what should they do about that? Are banks better protected or what kind of? Better protected banks tend to be because like they have the money and they know the money is valuable and if they lose the money they they see it right.
If you lose the data, it's hard to translate into money, so it's a little more abstract. Banks tend to be very, you know, precise in their analysis. If it costs $0.10 to protect $0.05, they're not going to spend it, right. If it costs $0.05 to protect $0.10, they'll do it in a second. So banks have a much more fine grained risk analysis metrics because they're dealing with money, That's yeah. So hospitals and medical centers need to hire the companies that are. Protecting them. No need to. But you know, like, I don't know if you're like on the board of the hospital and you could buy a new heart lung machine, you can buy some cybersecurity.
What are you going to spend money on? Right. You tend to spend money on the things that further your mission. Infrastructure, hygiene, that kind of stuff is easy to cut if budgets are tight. And that's what happens. It should also be mentioned though Robert, that the hospitals have a liability if they expose data for 20 minutes and even if nothing happens to the data you get a fine because the the there. There are regulations in place that say that you do not allow this to happen in the 1st place I'm in.
Favor of those regulations. Absolutely, Yeah. So that that's the internal incentive more than anything else that that allows that prompts hospitals to do whatever they can right now because there's a a genuine risk that these substantial fine could be levied against you. And these are these are not $10,000 fines. These are like multi $1,000,000 fines for having allowed your EHR to become exposed to the wide world for for 20 minutes. It has happened to health systems that I know about. So it it may not be that, you know, you may want to have your heart lung machine because you can generate revenue.
But also, if you think that you're going to violate federal standards for protecting patient information and you think that your system is leaky at all, there is some pretty strong robust feedback mechanism for that as well. Right. But nonetheless, the hacks are happening more frequently and the ransom money is, is going up. So obviously they're not protecting it. Well, my concern is that all these hospitals are connecting to each other now. So all you have to do is to break into one of them and you've got 10 hospitals that you can lock down or steal data from.
And that kind of thing happens all the time not just in hospitals but in in many sorts of networks that yes, as we interconnect vulnerabilities in one and this happened in intheancestry.com case, the, I'm sorry, the 23andMe, they had a a partnership with another another company I can I can look up which one and it was from MyHeritage. So there was some leakage between those two companies. So that kind of stuff happens all the time. Right now I've read recently there are a bunch of lawsuits that are happening.
After the packs come the lawsuits. That is a inevitable thing now, and that also is something that convinces companies to do better, right? If there are class action lawsuits, there are big penalties. What we want, right, is companies to spend the money on prevention, right, to do the work beforehand to up their security. So these things don't happen. And the way you make that happen in our market economy is you raise the costs of getting it wrong, right. So John mentioned that there are fines. These are probably related to HIPAA or other healthcare regulations that require patient privacy.
Those are good. That raises the cost of getting it wrong. Other way to do that is to class action lawsuits and it raises the cost of getting it wrong, right.
So what should people take from those patients and the general public? Should they be giving their DNA and other information to companies that are not medical centers or hospitals? Should they wait a while till this is cleared up in the future? If you've got a phone in your pocket, you already being spied on way more intimately than anything else you can do, you know, 23andMe is kind of in the noise. It's it's a special kind of privacy that isn't available right by your your cell phone surveillance master, because it's really about you.
It it it tells you things that you might not want to know, as John pointed out, or that you don't know. And that will be true for your entire life. It's not like someone's stealing your password that you can change what can be done with it, right? You know in 10 years will be different and what can be done today, right? John mentioned the science fiction dystopia of a a like a disease targeted to your genome that will only kill you. That is science fiction today. Will it be science fiction in 50 years?
Who knows I? Think that's coming. A lot of things. About your DNA that make it special. But there's a lot of cool things about knowing your DNA that make it special. I'm a privacy person. I cannot tell people how to make this trade off. And just like I would never tell you not to have a smartphone, I will never tell you not to use one of these companies, right? The trade-offs are way bigger than security.
John, what do you think people should do now to protect themselves maximally if if there is such a possibility? We should ask for more from the people who are working with our genomic information. I think that the idea of having a one off consent, A1 off agreement with a company or with the health system or whatever it might be and it's a yes or no consent and it's quite difficult to revoke if you change your mind. That model is not serving us well right now. So what we should have is consent, which is dynamic and granular.
So dynamic means that over time you can change your mind, you can opt into things, you can opt out of things. And granular means that your genome can be used in many, many different ways for many different kinds of biological questions. But some of them you may not want people studying your genome because you're sensitive about something or you have a fear about something. So that's where granularity comes in, especially if if the information is going to be returned to you. So you may be terrified of cancer and you just do not want to know your cancer risk.
You may have an uncle who at the age of 42 had a massive heart attack and you definitely want to know your cardiovascular disease risk. You may be, you know one of these young brash dudes who says, hey show me everything because you know they're they're kind of knuckleheads and you know adorable in their naivety and. Or you may be somebody who's from one of the patient populations that I that I work with in the Bronx and they're they're just suspicious because of centuries of racism and and abuse.
So the analogy I use is if you walk into a busy restaurant and you you look at what everybody's eating, I only know 2 two people have exactly the same meal. So why should we have something which is as sensitive as genomic information and the privacy issues around that and everybody having a different feel for it. And why should we try and have one menu for everybody? We we need to have something which which allows people that extra sense of control over what what is being their DNA is being used for.
And if we make it that for everybody who's in this business of of using people's DNA that the respect for privacy and dignity of people's information is first and foremost and that can be imposed by the the potential for massive fines reputational loss all these other issues. You can force people to to do the right thing and that we should ask for that as well as as consumers, as citizens that that these kinds of protections are put in place to to help us and our families. So John's 100% right and not just DNA data, but that could be true for your financial data, your your calling records, everything and and we can do that.
As a security person, I can build what John wants. Question is you know how do we get it and the market's not going to do it. John's right. It's regulation. It's massive fines. It's it's going to be the government saying to these companies you must give people granular control over their data. So Bruce, you just said you could do it. So in other words, if if you had access to. The tech is not hard. The technology is the technology. This is not something hard to do. But it's expensive. The economic will to do it is the hard part.
So, Bruce, you you held up your phone there and you said you're being surveilled. As one of the world's top cybersecurity experts. Why do you have a smartphone? Because of having a Saudi, because you can't live as a citizen in the 21st century of that one, 'cause, you know, yeah, I mean, I could not have a smartphone, not be on zoom with you, you know, not live in a home with with power. I can do all those things. It's no fun. So we all make trade-offs. I mean, I hate Pokémon Go, for heaven's sakes.
That is a game that spies on you. So we're all doing our best and making our trade-offs, and there are no absolutes. And I'll remind you, Robert, that I did admit that I used 23andMe myself, so you know, you can be informed and still make these decisions. Right. I didn't want to ask you if anybody's gotten in touch with you and tried to blackmail you.
It's it's probably that I. Don't need passwords in all of his sites. That was actually true, but the the my DNA is actually pretty boring looking from my own assessment of it, because I did. I did download the raw data and look at it and I found that there is evidence that many generations back my parents must have had a common ancestor. And that's actually not uncommon when you when you look at people from Ireland. I mentioned other other groups earlier who are a bit more related. So I went home and I told my parents about about that and that was an interesting conversation.
So like unlike everybody else, he downloads the raw data because he actually has a degree in looking at the raw data. Right and. It was still boring. Interesting. Any closing comments on this or related topics? I thought we closed it pretty well. Yeah, I think we covered this very well. I think the public watching this will learn a lot, be educated about it, and take precautions as much as they can to prevent this from adversely affecting them. I want to thank both of you for taking the time. I know you have very busy schedules.
I want to thank you for coming on the Doctor podcast program. I really appreciate your time. Thanks for having. Us. All right. Take care. Bye, bye.