FTC accuses DNA testing company of lying about dumping samples
- Reference: 1687375815
- News link: https://www.theregister.co.uk/2023/06/21/dna_testing_company_ftc_complaint/
- Source link:
To make matters worse, the FTC also alleged in a consent order made public last week that the company didn't secure the information properly, and further, that it changed its privacy policy retroactively without properly notifying or getting consent from people whose data the company had already collected – people who had signed a different, earlier version of the policy.
Under the proposed settlement, Vitagene/1Health.io will have to sharpen its data protection practices and put into place procedures to keep them sharp, as well as a pay a fine. The company has neither admitted nor denied any of the allegations.
[1]
"Companies that try to change the rules of the game by re-writing their privacy policy are on notice," said Samuel Levine, director of the FTC's Bureau of Consumer Protection. "The FTC Act prohibits companies from unilaterally applying material privacy policy changes to previously collected data."
[2]
[3]
The company asks users to spit into a tube and uses the customer's genetic data, in combination with a health quiz, to check if a user has, or may soon have, certain health conditions. After a user buys a product package from that costs between $29 and $259, the company gives them a report about their health, wellness, and ancestry.
According to the [4]order [PDF], the company, which the FTC said also trades as Vitagene, "identifies salient genotype data, pertinent questionnaire answers, and, based on the genotype data and questionnaire answers, the level of risk for having or developing certain health conditions, such as high LDL cholesterol, high triglycerides, obesity, or blood clots."
[5]
The document, which proposes a settlement of $75,000 and to extract a promise from the company to police its data protection, claims that Vitagene did not securely store consumers' health reports and raw genotype data.
100 points to whoever guesses what comes next. The order goes on to claim it was all bunged in Amazon S3 buckets, and that the containers' access controls were conspicuous by their absence.
In all fairness, misconfigurations of Amazon's cloud buckets are common, even after AWS introduced a new set of controls in [6]2018 to set "blanket policies" blocking public access to cloud storage from being enabled that you can apply to your S3 buckets via access control lists.
[7]Hijacked S3 buckets used in attacks on npm packages
[8]Lantum S3 bucket leak is prescription for chaos for thousands of UK doctors
[9]Another security calamity for Capita: An unsecured AWS bucket
[10]Amazon slaps automatic encryption on S3 data
Bloomberg [11]reported on the leak back in 2019, saying the company had left people's health records publicly accessible for years.
Vitagene told the newswire at the time that the files dated from when the company was in beta testing and affected a small fraction of its customer base.
[12]
The FTC's recent order goes on to detail another count from the proposed complaint alleging Vitagene posted revised privacy policies on its websites in April and December 2020 that described "materially expanded practices for the company's sharing of consumers' sensitive health and genetic information with third parties." According to the commission, this included the information of consumers who purchased products and services from the company before April 2020 — "without taking any additional steps to notify consumers or obtain consumers' consent."
The FTC said the proposed order contained "provisions" to address Vitagene's conduct and prevent it from "engaging in the same or similar acts or practices in the future."
Mehdi Maghsoodnia, CEO of 1Health, told The Register in a statement: "In July 2019, we were for the first alerted to the fact that a small number of customer files had been inadvertently stored in a publicly accessible location. There is no evidence these customer files were improperly accessed.
"In response, the FTC launched an investigation which has now dragged on for nearly four years. This is a case of extraordinary government overreach. Ultimately, we disagree with many of the FTC's conclusions. But we look forward to finally putting this matter behind us." ®
Get our [13]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZJNy-hIqrvBbRSrG230JmQAAAAo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZJNy-hIqrvBbRSrG230JmQAAAAo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZJNy-hIqrvBbRSrG230JmQAAAAo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.ftc.gov/system/files/ftc_gov/pdf/decision_and_order.pdf
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZJNy-hIqrvBbRSrG230JmQAAAAo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2018/11/16/aws_s3_bucket_security/
[7] https://www.theregister.com/2023/06/19/npm_s3_buckets_malware/
[8] https://www.theregister.com/2023/06/12/lantum_s3_bucket_leak/
[9] https://www.theregister.com/2023/05/17/another_security_calamity_for_capita/
[10] https://www.theregister.com/2023/01/06/amazon_s3_encryption/
[11] https://www.bloomberg.com/news/articles/2019-07-09/dna-testing-service-exposed-thousands-of-customer-records-online
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZJNy-hIqrvBbRSrG230JmQAAAAo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[13] https://whitepapers.theregister.com/
"health, wellness, and ancestry" right...
wellness - (us English) what a conman says to you before he sells you magic beans, or kale, depending on the decade.
ancestry - What you can't accurately determine with a single person DNA test alone, along with ethnicity and genealogy. Within a generation or two you can look at heredity, but it's only accurate if the people you are testing against are also tested and compared in the same date set.
As for heath, there are a host of things this testing MIGHT tell you, but for $250 you could get a full series from an actual medical medical test company covered by actual privacy laws, and control what happens with the data afterwords.
The great thing is all it takes is one idiot relative to start handing these out at Christmas and the whole families medical privacy is gone permanently. You will forever be reliant on the ethical and legal behavior of US insurance carriers, advertisers and, of course, law enforcement. That last won will even shoot down the innocent man has nothing to hide bit by being criminally incompetent and willing to jail someone for decades based on a partial dna match, from a degraded sample, even when the person has never been to the state where the crime was committed.
These fly-by-night DNA companies should have already been shut down.
$75,000 settlement! Oh no, how can they possibly afford that?
I sincerely wish governments would start imposing *meaningful* fines and penalties on companies for stuff like this. $75k is pocket lint, even for a "smaller" biotech company like this. Assuming the settlement goes as described here, the company will probably buy the lawyer responsible for it a brand new mansion as thanks for all the profits saved.
Interpreting the official response:
"a small number of customer files" == "Have you seen TREE(3)? Now *that*'s a large number!"
"There is no evidence these customer files were improperly accessed." == "They were publicly accessible! Any access was, by definition, proper!"