Online services that allow users to upload their genetic information to help research genealogy and find lost relatives may be vulnerable to a sort of genetic hacking, according to a paper published today in eLife by two geneticists at the University of California, Davis.

Online services such as GEDMatch, MyHeritage and FamilyTreeDNA have increasingly become popular places for people to upload their genetic information and research their genealogy. But Graham Coop and Michael Edge warn that someone with expertise in genetics and computing could design and upload DNA sequences that extract far more from these databases than some lost cousins. It may be possible for an attacker to pull out the genetic information of most people in a database or to identify people with specific genetic traits.

"People are giving up more information than they think they are," when they upload to these publicly accessible sites, Coop said. And unlike credit card information, you can't just cancel your old genome and get a new one. The problems do not affect for-profit DNA sequencing companies such as 23andMe, Coop added. You have to submit your DNA as a saliva sample to get access to their genetic data. The public databases, however, allow anyone to upload DNA sequences and search for other users with matching sequences.

Search Antibodies
Search Now Use our Antibody Search Tool to find the right antibody for your research. Filter
by Type, Application, Reactivity, Host, Clonality, Conjugate/Tag, and Isotype.

These sites work by using software to compare DNA sequences uploaded by users with sequences already in their database. Your genome is a mosaic of pieces inherited from your ancestors. Bigger pieces, or tiles in the mosaic, come from recent ancestors. As generations pass, matching sequences get chopped into smaller pieces. So if you share large chunks of DNA sequence with someone else, it's likely you share a recent ancestor.

Coop and Edge found three approaches to attacking these databases. They call these methods IBS (identical by sequence) tiling, IBS probing, and IBS baiting.

In IBS tiling, an attacker uploads several genomes found in public research databases and keeps track of which ones match with other genomes in the database, and where. If they can find enough matching tiles, they can put together most of someone's genome.

IBS probing can be used to hunt for people who carry a specific genetic variant. To do this, the attacker creates a fake genome with a DNA sequence that isn't likely to match anyone, except for one small section that will match the gene of interest. Matches from the database are likely to be people with this genetic variant.

Finally, IBS baiting relies on tricking one class of algorithms used to identify relatives. (Not all databases use this type of algorithm, though). Coop and Edge calculate that with as few as 100 uploaded DNA sequences, an attacker could use this method to obtain most of the genomic information in a database.

All three attacks could be carried out by someone with knowledge of genetics and computing, such as a graduate student or serious hobbyist, but "the good news is that it's quite preventable," Edge said. Coop and Edge's paper sets out a series of steps direct-to-consumer genetics services could take to block these attacks. While they have already shared the information with the leading services, they have had a 'varied' response, Coop noted.