Showing posts with label GEDmatch. Show all posts
Showing posts with label GEDmatch. Show all posts

Sunday, 19 July 2020

Major privacy breach at GEDmatch

There has been a major privacy breach at GEDmatch, the third-party genetic genealogy website which has become well known in the last two years because of its use by law enforcement agencies in the US to solve cold cases. A member of the Genetic Genealogy Ireland Facebook group posted a message at lunchtime today (13.38 pm UK time) to advise that the site had been compromised and that people were receiving what appeared to be fake matches with suspicious e-mail addresses.(This Facebook post has now been deleted.) Some users were reporting that they were receiving unusually large numbers of  new matches, all sharing unexpectedly high amounts of DNA which would normally indicate a very close relationship. In another group, one user reported receiving over 3000 matches, all of which shared over 700 cM. A match in this range would normally indicate a very close relationship such as a first cousin or closer.

Later on this afternoon (14.54 pm UK time) a user posted in the Genetic Genealogy Tips and Techniques group on Facebook that all his kits on GEDmatch were now publicly accessible and all marked as available to the police. This included not just standard kits but also phased kits and Lazarus kits,which are by default always marked as research kits and are not normally available for matching. I checked my own account at GEDmatch and found that all my kits had been changed without my consent to allow police access. This included two phased research kits which were never intended to be made public. I initially found that I was unable to change the settings on any of the kits. The site was up and down for a short while this afternoon before I was finally able to log in and restore my preferred access settings.

Since then GEDmatch has been offline with a message that the site is down for maintenance.
Many other people have also reported that their kits have been affected and that the settings have been changed to allow police access without their consent. Graham Coop shared on Twitter this afternoon a screenshot of his accounts showing how they had all been changed to allow police access..


It therefore appears that the entire database has been changed to make all kits available for police access. This also means that the law enforcement kits, which are normally uploaded as research kits so that they do not appear in match lists, have been compromised. Anyone logging onto the website during this period would have seen those kits and might have been able to save a screenshot with the kit numbers. Allowing unauthorised access to law enforcement kits could potentially have serious consequences and could compromise an investigation.

This is clearly a matter of great concern. There are well over 1.2 million profiles on GEDmatch but only around 200,000 or so kits had opted to make their profiles available for law enforcement matching. This means that the DNA profiles and e-mail addresses of probably around a million people have been exposed, including all the law enforcement kits. It is unlikely anyone would have been able to do anything with the matches during the period when the website was compromised because so many spurious matches were being produced. It is the exposure of the e-mail addresses and kit numbers which is likely to be of the most concern.

According to a report on the Tech in the City website the original privacy settings were restored before the site was taken down though I'm not clear what time this happened as I'm not clear what timezone the author is reporting from.

As GEDmatch operates in the European Union and has many EU customers, they are obliged to comply with the EU's General Data Protection Regulation (GDPR). Because of the serious nature of this breach it seems likely that they will have to report the matter to the appropriate regulatory authority in the EU. I don't know which authority they have registered with but the Information Commissioner's Office in the UK has information on how such data breaches should be reported. If a company or organisation has not protected the security of its customers than an enforcement action can be take and the company can be fined.

GEDmatch have since advised that they are aware of the issues and are responding. According to a post in the GEDmatch User Group on Facebook GEDmatch are "doing research right now to confirm what is happening. They are leaving the site down until they can clearly confirm what is going on." They are expected to make a formal statement later. It appears that this was an inadvertent update that went wrong. There appears to be no evidence that the site was hacked.

In the meantime it is pointless to speculate about what might have happened and we will need to await until further information is available. I will update this page if I receive any further news.

Update
Just after publishing this blog post I discovered (22.51 pm UK time) that GEDmatch is back up and running and my kits all have the correct access levels.

23.09 pm The following message has been posted on the GEDmatch Facebook page.

Update 21 July 2020
GEDmatch have announced on their Facebook page that they experienced a security breach on Sunday which was orchestrated through a sophisticated attack on one of their servers via an existing user account. The site was functioning briefly yesterday but reports started coming in late last night that people were once again receiving lots of unexpectedly high matches with a low SNP overlap in their match lists. I was able to briefly log into my account at 1.00 am night and found that the kit I checked had lots of matches with users with words like "imputed" and "partial" in the names. My highest match was at the first cousin level with a user from the Chinese company Gese DNA. The site has now been taken down and GEDmatch are working with a cybersecurity company to implement new security measures. Here is a screenshot of the message from GEDmatch. I've removed the contact details from the post but these are are available in the full version of the message in the Facebook group. 


It is good that GEDmatch are being transparent about the problems and this may turn out for the best in the long run if the security of the database is improved. The site was down for at least three hours and although they say that no data was downloaded in that time it would have been possible to take screenshots of match lists from many different accounts. Once you have a kit number you then essentially have access to that individual's account. It is also a cascading effect because you can click on all the matches of the matches as well. This essentially means that all the kit numbers have been compromised because no one will know which kits were affected. All the kit numbers will need to be changed. Ideally it would be better if GEDmatch did not reveal kit numbers in the match lists. It will be interesting to see what happens but I rather suspect the site will be down for a long time.

Further update 21 July 2020
5.00 pm 
From the GEDmatch Facebook page: "GEDmatch will remain offline for 2 to 3 days as we further enhance security protocols. Thank you for your patience. We apologize for the inconvenience this has caused."

Update 22 July 2020
MyHeritage advised late last night of a security alert involving a malicious phishing attempt that was possible related to the GEDmatch breach. For full details see the MyHeritage blog post:


The further reading section of this blog post has been updated to include an informative blog post from Leah Larkin explaining why we were seeing the mystery matches at GEDmatch sharing unusually high amounts of DNA. I have also included an official statement from Verogen which was published on their blog on 20th July, a further blog post from Leah Larkin which includes a timeline of the events and an article from Peter Aldhous of Buzzfeed News..
 
An e-mail has been sent out by Verogen to all GEDmatch users informing them of the breach. My e-mail arrived at 8.40 am. It may take time for a bulk e-mail to reach all 1.2 million or more users. If you haven't received the e-mail check your spam folder. I've copied the text below in case you haven't received it.

Dear GEDmatch member,

On the morning of July 19, GEDmatch experienced a security breach orchestrated through a sophisticated attack on one of our servers via an existing user account. We became aware of the situation a short time later and immediately took the site down. As a result of this breach, all user permissions were reset, making all profiles visible to all users. This was the case for approximately 3 hours. During this time, users who did not opt-in for law enforcement matching were available for law enforcement matching, and, conversely, all law enforcement profiles were made visible to GEDmatch users.

On Monday, July 20, as we continued to investigate the incident and work on a permanent solution to safeguard against threats of this nature, we discovered that the site was still vulnerable and made the decision to take the site down until such time that we can be absolutely sure that user data is protected against potential attacks. It was later confirmed that GEDmatch was the target of a second breach in which all user permissions were set to opt-out of law enforcement matching.

We can assure you that your DNA information was not compromised, as GEDmatch does not store raw DNA files on the site. When you upload your data, the information is encoded, and the raw file deleted. This is one of the ways we protect our users’ most sensitive information.

Further, we are working with a leading cybersecurity firm to conduct a comprehensive forensic review and help us implement the best possible security measures. We expect the site will be up within the next day or two.

We have reported the unauthorized access to the appropriate authorities and continue to work toward identifying the individuals responsible for this criminal act.

Today, we were informed that MyHeritage customers who are also GEDmatch users were the target of a phishing scam. Please remember to exercise caution when opening emails and clicking links. Never provide sensitive information via email. If an email seems suspicious, contact the company in question directly through the phone number or email address listed on their website, not via a reply to the suspicious email. You can reach GEDmatch at  xxxx or xxxxx [email address and telephone number removed]. At this time, we have no evidence to suggest the phishing scam is a result of the GEDmatch security breach this week. We are continuing to investigate the incident.

Please be assured that we take these matters very seriously. Our Number 1 responsibility is to protect the data of our users. We know we have not lived up to this responsibility this week, and we are working hard to regain your trust. We apologize for the concern and frustration this situation has caused.

Sincerely,

Brett Williams
CEO, Verogen Inc.

For a French translation of this e-mail see the post in the Facebook group France ADN - Généalogie Génétique (ISOGG).

Update 25th July 2020
There is a notice on the GEDmatch Facebook suggesting that the site will be back online today though at 11.35 am UK time the site was still down.

The site was restored in the afternoon of 25th July and no further issues have been reported to date.

Tuesday, 17 December 2019

An update on EU kits at GEDmatch and a message from Curtis Rogers

We learnt last week that GEDmatch has been acquired by the forensics company Verogen. I now have some further information about the handling of European Union users at GEDmatch. When the sale first went through only a small number of EU users were presented with a consent form in order to access the website. We thought at the time that the form was only being shown to those who had an identifiable e-mail address in the EU. I did not have to re-consent when I first tried to log onto GEDmatch, presumably because my e-mail address had a .com suffix and not a .co.uk suffix. That all changed some time last week, and Verogen are now identifying EU users by their IP address. As a result I found that I had to re-consent to use the site. Below are screenshots of the data transfer form which all EU users are now required to sign.


Having signed the form you are then presented with this screen.


You are then given the option to decide on a kit by basis which kits you would like to transfer to Verogen, which kits you would like to delete and which kits you would like to decide about later.

Many people have been reporting that they've lost a lot of matches at GEDmatch and that some of their kits have disappeared. Genetic genealogist Paul Watkins contacted Verogen and he has given me permission to share the contents of the reply he received which explains what has been happening:
While we did have issues with Kits “disappearing” this week from UK users, the main reason that matches are looking like they disappear is that people who are subject to European General Data Privacy Regulations (GDPR) have been pulled out of the database temporarily, as we are legally required to obtain consent to transfer control of users data to Verogen.

Unfortunately, in addition, to known EU users, there are also many users that we do not know their location (we use the IP address of the user when they login to determine the country of origin). This group contains a mix of users from different countries (EU, US, and ex-US users). However, because there is most certainly EU users in this unknown location group, the legal ramification of violating European GDPR is severe, and this has forced us to pull these people out of the database until they log in and consent. 
Users from the EU and those with an unknown location are logging back in, and we expect that these matches will repopulate over time. We are also reaching out proactively to these users to ask them to log in to confirm their location and accept the new terms of service.
The issue of disappearing kits appears to have been resolved and the following notice now appears when you log into GEDmatch.
Meanwhile it has been reported in the official GEDmatch Facebook group that Curtis Rogers will be sending out an e-mail to all GEDmatch users. I've copied the text of the e-mail below for reference:
A MESSAGE FROM GEDMATCH FOUNDER CURTIS ROGERS. THIS MESSAGE WILL BE EMAILED TO ALL USERS. 
To GEDmatch users, 
As you may know, on December 9 we shared the news that GEDmatch has been purchased by Verogen, Inc., a forensic genomics company whose focus is human ID. This sale took place only because I know it is a big step forward for GEDmatch, its users, and the genetic genealogical community. Since the announcement, there has been speculation about a number of things, much of it unfounded. 
There has been concern that law enforcement will have greater access to GEDmatch user information. The opposite is true. Verogen has firmly and repeatedly stated that it will fight all unauthorized law enforcement use and any warrants that may be issued. This is a stronger position than GEDmatch was previously able to implement. 
There has been concern that Verogen will eliminate GEDmatch free tools and raise Tier 1 rates. In fact, Verogen has made it clear that the free tools will remain, and there are no immediate plans to raise Tier 1 rates. 
It has been reported on social media that there is a mass exodus of kits from the GEDmatch database. There has been a temporary drop in the database size only because privacy policies in place in the various countries where our users reside require citizens to specifically approve the transfer of their data to Verogen. As users grant permission, that data will again be visible on the site. We are proactively reaching out to these users to encourage them to consent to the transfer. 
The sale to Verogen will be a tremendous benefit to genealogists. Verogen has pledged to continue the GEDmatch philosophy of providing free services. It recognizes that all information belongs to the users who have placed it on GEDmatch, that this information may be removed by the users at any time, and that strong privacy protections need to be in place. It is to Verogen’s advantage to build the consumer database, meaning more and better matches for users. Verogen recognizes that law enforcement use of genetic genealogy is here to stay and is in a better position to prevent abuses and protect privacy than GEDmatch ever could have done on its own. 
Bottom line: I am thrilled that the ideal company has purchased GEDmatch. The baby I created will now mature for the benefit of all involved. If anyone has any doubts, I may be reached at [email address redacted]. I will do my best to personally respond to all concerns. 
Curtis Rogers
GEDmatch
It will take time for GEDmatch to settle back down after the sale but I would urge everyone to give the new owners the benefit of the doubt and to see how it all works out in the months to come.

Tuesday, 10 December 2019

GEDmatch has been acquired by the forensic genomics company Verogen

GEDmatch has been acquired by the forensic genomics company Verogen. The acquisition was announced today in a press release from Verogen.
SAN DIEGO, CA (December 9, 2019) — GEDmatch, a pioneer in consumer genealogy, today announced that it has joined with forensic genomics firm Verogen, Inc. in a move that allows the company to ensure ongoing privacy protections and enhance the customer experience for users of its website. 
“I am confident that we have found an ideal partner for GEDmatch,” said founder Curtis Rogers. “Verogen understands our philosophy and shares the vision of GEDmatch, which has always been about using science to connect people,” Rogers said. “Verogen is able to support our growth while staying true to our roots.” 
GEDmatch allows users to upload genetic profiles created by other genealogy sites in order to expand the search for familial links. GEDmatch’s database currently has more than 1.3 million customer profiles and is gaining as many as 1,000 new users every day. 
In the coming months, GEDmatch users will begin to see improvements to the website, such as an enhanced homepage that offers increased functionality, Verogen CEO Brett Williams said. Verogen will also bolster the GEDmatch platform, resulting in increased stability and optimal searchability. These back-end changes won’t disrupt the experience for users and, in fact, will make searching the database easier, Williams said. 
GEDmatch’s terms of service will not change, with respect to the use, purposes of processing, and disclosures of user data, Williams confirmed. The website gives users a choice to opt-in to allow law enforcement to search uploaded files as a tool to solve violent crimes. Among the successes of this technology is work by public safety officials who used GEDMatch to apprehend accused Golden State Killer Joseph DeAngelo, a notorious serial killer who terrorized California and evaded police for decades until his arrest in 2018. 
As many as 70 violent crimes have been solved as a result of genealogy searches. “Never before have we as a society had the opportunity to serve as a molecular eyewitness, enabling law enforcement to solve violent crimes efficiently and with certainty,” Williams said. 
“Still, our users have the absolute right to choose whether they want to share their information with law enforcement by opting in,” Williams said. “We are steadfast in our commitment to protecting users’ privacy and will fight any future attempts to access data of those who have not opted in.” 
Added Rogers: “Our number one priority is our customers. We are and always have been a genealogy site whose goal is to help people find answers they’re looking for about themselves and their families. As we grow, we want to enhance the customer experience by making the site more user-friendly and by ensuring data is protected. Verogen can help us do that.” 
Under terms of the deal, Rogers will retain a key role focused on the primary mission of GEDmatch, which is to provide tools to help amateur and professional researchers and genealogists. 
GEDmatch customers who have questions about the partnership or how their privacy is protected are encouraged to contact customer service at gedmatch@verogen.com
If you have an account on GEDmatch you will now see a notice when you log in to the website informing you of the need to sign up to the new Terms of Service and Privacy Policy which have been introduced "in view of recent events in the genealogical community".
The revised Terms of Service clarify that GEDmatch is now operated by Verogen "following the acquisition by Verogen of the GEDmatch website".


Some European Union users are being asked to fill in an extra consent form before they can access their one-to-many matches. However, despite being in the EU, I have not had to fill in this form. There is speculation that the form is only being shown to those who have e-mail addresses that can be readily identified as being from EU countries.


At the end of the new site policy you are given three options: to accept the new terms of service, to reject the policy and delete your kit or to decide later. You will not be able to enter the site unless you accept the new terms of service.
To see the differences between the old and new privacy policies at GEDmatch see this saved link from DiffChecker.

It will be interesting to see how this all plays out. With the investment from Verogen we are likely to see improved functionality at GEDmatch, a better user interface and improved security measures. However, Verogen will also need to recoup their costs. Will genealogists be put off from using a genealogy database that is owned by a forensics company? I've already seen lots of comments from genealogists on Twitter and Facebook who have indicated that they will now be deleting their kits from GEDmatch. Will Verogen be able to attract enough paying subscribers to the Tier 1 tools to make a profit? Will Verogen introduce new subscription features? Will they charge law enforcement agencies for access to the database? How will Verogen react if they are served with a subpoena or search warrant for access to kits which have not opted in?

GEDmatch is now one of three genetic genealogy databases that can be used by law enforcement agencies. Gene By Gene, the parent company of FamilyTreeDNA, has its own lab where it provides forensic testing. They allow law enforcement agencies access to their genetic genealogy databases but charge a substantial fee to cover the costs of registering the users and processing the paperwork. Controversially, FTDNA now automatically opt in all their customers to law enforcement matching regardless of where they live. Few people read through all the terms and conditions when signing up for a genealogy test and so they will not have given fully informed consent to have their data shared with law enforcement. EU customers were automatically opted out of law enforcement matching prior to March 2019, but customers in all other countries were opted in.

DNA Solves is a new website set up by David Mittelman of Othram. Mittelman was previously the Chief Scientific Officer at Gene by Gene. DNA Solves has not yet been officially launched but is intended as a law enforcement-only database. Few details are currently available about how the site will operate.

It remains to be seen how this will all work out. Time will tell.

Update 10 December 2019
Verogen have sent out the following e-mail to their customers.
To Our Valued Customers:

We are pleased to share news that has far-reaching benefits for our company, our customers, and our scientific and law enforcement partners. Today, Verogen announced its acquisition of GEDmatch, an online genetic genealogy service that has been central to law enforcement solving over 70 cold cases in the U.S.

What this means for you

On a day-to-day basis it is business as usual. Verogen will continue to provide NGS instrumentation, software, reagents and consumables to a global customer base for forensic and biometric based human identification. Meanwhile, we will bring significant technical and scientific resources to build a more expansive GEDmatch platform that will exhibit increased security and ease of use. In the coming months, we will engage you in a conversation about the future of genetic genealogy, and how Verogen will enable the operational forensic laboratory to participate in the exciting revolution.

For more information, you can read the full press release here. 

The Verogen story continues…

Verogen was spun out from Illumina in August 2017 and is the only company solely focused on providing NGS instrumentation, software, reagents and consumables for forensic and biometric based human identification.

Verogen is building an NGS-based forensic ecosystem that is focused on a single platform multi-application strategy with common workflows between the applications. We are developing a compact but powerful range of applications that work in combination to improve and extend forensic analysis of biological traces that will enhance your ability to obtain an individual’s identification.

Today we offer solutions that utilize genomic and mitochondrial DNA that address the most common challenges for casework and missing persons sample analysis. Soon, we will be rolling out new applications as part of our “single platform multi-application strategy” that will enhance and expand your ability to provide a comprehensive human ID.
Update 10th December 2019
The following message to GEDmatch users has been posted by Curtis Rogers. It is visible when you log into your GEDmatch. The full message can also be seen here: https://www.gedmatch.com/curt_msg.htm


Update 11 December 2019
There is now a new Facebook page for the new GEDmatch:

https://www.facebook.com/officialGEDmatch

Update 18 December 2019
See my blog post An update on EU kits at GEDmatch and a message from Curtis Rogers

Further reading

Wednesday, 6 November 2019

Search warrant granted for access to GEDmatch database

A troubling story has been published in the New York Times about a security breach at GEDmatch. Detective Michael Fields from the Orlando Police Department was able to obtain a search warrant which allowed him to over-ride the privacy settings of individual customers at GEDmatch and search for matches in the entire database rather than in the subset of the database which had opted in to law enforcement matching. Fields had previously been able to use GEDmatch in collaboration with Parabon Nanolabs to identify a suspect in the 2001 murder of Christine Franke. He was disappointed when GEDmatch changed their terms of service in May this year which resulted in all users being required to actively opt in to law enforcement matching. This change effectively reset the number of profiles available for law enforcement matching to zero, including many people who had transferred their results to GEDmatch specifically to help with law enforcement cases. Since then a steady trickle of people have opted back in to law enforcement matching but, according to the New York Times article, just 185,000 of GEDmatch's 1.3 million users have done so at the present time. The cold case which resulted in the search warrant relates to a serial rapist who assaulted a number of women several decades ago, though the full details have not been made public. The New York Times reports as follows:
In July, he [Fields] asked a judge in the Ninth Judicial Circuit Court of Florida to approve a warrant that would let him override the privacy settings of GEDmatch’s users and search the site’s full database of 1.2 million users. After Judge Patricia Strowbridge agreed, Detective Fields said in an interview, the site complied within 24 hours. He said that some leads had emerged, but that he had yet to make an arrest. He declined to share the warrant or say how it was worded. 
Detective Fields described his methods at the International Association of Chiefs of Police conference in Chicago last week. Logan Koepke, a policy analyst at Upturn, a nonprofit in Washington that studies how technology affects social issues, was in the audience. After the talk, “multiple other detectives and officers approached him asking for a copy of the warrant,” Mr. Koepke said.
It is difficult to comment on this case without having the full facts available. As this is an active investigation it is not possible to get a copy of the search warrant to find out why the police thought it necessary to over-ride the consents and we don't know the grounds on which the judge granted the warrant. GEDmatch could potentially have resisted the warrant but they are unlikely to have the resources to fight a lengthy legal battle. They are also likely to be sworn to confidentiality so they would not be able to discuss the case and would not have been in a position to warn their users. But if GEDmatch were sworn to confidentiality I wonder why Detective Fields was boasting about his actions at a police conference.

However, the use of a search warrant in this case does provide cause for concern as it potentially sets a precedent. What is to stop the police issuing search warrants to search for matches at the other testing companies? Would these companies be able to defy the warrant and refuse access? It is also troubling from an international perspective. An American judge has made a unilateral decision which affects the privacy and rights of all of GEDmatch's many international users who do not have any legal or governmental representation in the US. Granting access to the opted out profiles of international customers is not only a disproportionate measure, as their family trees are much less likely to be used to solve the crime, but it is also a gross over-reach by the judge who has passed a judgement which affects individuals who live in countries which are outside her jurisdiction.

If you think you might have been affected I suggest that you write to the Orlando Police Department to find out if your name is included in the match lists they are using. If you are an EU citizen you should be protected by the General Data Protection Regulation (GDPR) and you will have the right to have your information removed. If the police refuse to do so you should complain to your data protection regulator in the EU. If you are in the UK you should write to the Information Commissioner's Office. If you are in Ireland you should write to the Data Protection Commission. The ICO have a handy template on their website which you can use if you wish to submit a complaint. I have now written to the Orlando Police Department and I await their response with interest.

If you feel strongly about this judgement you might also like to write to Judge Patricia Strowbridge. She can be contacted via her judicial assistant. I have sent her an e-mail because I think it's important that she understands the international implications of her decision though I am not expecting a response.

Update 7th  November 2019
I have received the following response from Judge Strowbridge's office:

"Judge Strowbridge’s office is in receipt of the email you sent yesterday, November 6, 2019. Unfortunately, the Florida Code of Judicial Conduct strictly prohibits judges from commenting on any pending cases. As such, Judge Strowbridge is unable to respond to your email."

Update 13th November 2019
Someone was able to get a redacted version of the GEDmatch search warrant and they've shared it on Twitter. You can access it here:

https://twitter.com/rot13x2/status/1194325134653435904

I will comment on this in due course.

Update 18th November 2019
Leah Larkin published an analysis of the GEDmatch search warrant.

Further reading
Related blog posts

Sunday, 3 November 2019

Genotype extraction and false relative attacks: potential security risks at third-party genetic genealogy sites

Hot on the heels of a paper published the other week by Michael "Doc" Edge and Graham Coop on the possibility of attacks on genetic privacy via uploads to genealogy databases comes another paper by an independent team of researchers warning of another potential security risk.

The latest paper is written by Peter Ney, Luis Ceze and Tadayoshi Kohno, three researchers at the Paul G. Allen School of Computer Science & Engineering at the University of Washington. They caution about the risks of genotype theft and falsified genetic relations in the GEDmatch database.

I do not feel qualified to comment on the security risks they have identified so I will provide some links and let you make your own judgement.

The authors have provided some FAQs which provide a good starting point:

https://dnasec.cs.washington.edu/genetic-genealogy/

If you want read the full paper you can find it here:

The possible implications are also discussed in this article by Antonio Regalado in MIT Technology Review:


See also this report in the University of Washington News:


GEDmatch were given advance notice of the publication of the paper to allow them time to implement any necessary fixes. I understand that GEDmatch currently have measures in place that would thwart the method described in this paper but, understandably, they are not sharing the specifics. Further measures are also being investigated.

Note that this loophole affects GEDmatch only. The method won't work at AncestryDNA, 23andMe, FamilyTreeDNA, MyHeritage and Living DNA.

Update 4th November 2019
This research was also covered in New Scientist. You need a subscription to access the full article but here are some quotes from the end of the article:
"The study identifies a “clear risk” to the GEDmatch database, according to Graham Coop at the University of California, Davis, who wasn’t involved in the work. “I do worry that [GEDmatch are] not taking these concerns seriously enough. They have over a million people’s genetic data and they have placed these data at risk, which is incredibly concerning.” 
The risks could be easily solved by limiting genetic data uploads to DNA test results that are authenticated or digitally signed, says Ney. Better checks on uploads to detect anomalies, and restrictions on one-to-one comparison searches would help too, he says. His team alerted GEDmatch to the vulnerabilities before publishing and took measures to avoid exposing anyone’s identity. 
Curtis Rogers at GEDmatch says: “We are concerned about security and appreciate they have pointed out vulnerabilities.” He says the site has made several changes to address the vulnerability and is working on others, but didn’t specify what measures.
The article can be found here:

 https://www.newscientist.com/article/2221972-privacy-attack-on-dna-website-reveals-93-per-cent-of-a-persons-data/

Tuesday, 22 October 2019

Attacks on genetic privacy via uploads to genealogical databases

Update 7th January 2020
This paper has now been published in the peer-reviewed open access journal eLIFE. You can read it here.  In the same journal there is also a good commentary article by Shai Carmi "Genealogy: the challenges of maintaining genetic privacy" which you can read here

A new preprint has just been published by Michael "Doc" Edge and Graham Coop from the University of California Davis about some potential security risks in genetic genealogy databases. The paper is concerned with genealogy databases which accept uploads (ie, GEDmatch, FamilyTreeDNA, Living DNA and MyHeritage DNA). AncestryDNA and 23andMe do not accept uploads so they are not affected. Not all of the techniques described in the paper would necessarily work at all the companies. The companies were all given early sight of the paper so they have had the opportunity to make any adjustments. I understand that GEDmatch have already taken some unspecified measures and are considering more. The authors have provided a few suggestions on possible solutions for dealing with the risks they have highlighted and improving security such as using cryptographic signatures on DNA data files.

The authors have written some FAQs about their paper and if you want to understand what it is all about I recommend reading these FAQs first.

If you want to read the full paper it can be found here.

UC Davis have issued a press release which can be found here.

Leah Larkin has written an excellent blog post about the paper explaining the concepts in easy-to-understand terms.

Blaine Bettinger has shared his thoughts in this blog post.

I will update this post with further links if I find any other useful commentaries on the subject.

Update 18th December 2019
An updated copy of the preprint was uploaded to BiorXiv on 18th December and can be seen here.

Monday, 21 May 2018

Updates to the Terms of Service and Privacy Policy at GEDmatch

In the light of the revelations that the citizen science website GEDmatch was being used by law enforcement to identify victims of crime and suspects in murder investigations, the site owners have now updated the Terms of Service and Privacy Policy. When you log into your GEDmatch account you will now receive the following message:
The new Terms of Service and Privacy Policy can be seen here. (You do not need to be a GEDmatch user to access the link.)

It is of note that GEDmatch have now clarified that "DNA obtained and authorized by law enforcement" can be uploaded for two very specific uses to: "(1) identify a perpetrator of a violent crime against another individual; or (2) identify remains of a deceased individual".


There is also a new section which explicitly spells out the potential uses of your DNA results including the fact that your DNA could be used for "Familial searching by third parties such as law enforcement agencies to identify the perpetrator of a crime, or to identify remains."

The user is presented with three options: (1) to accept the new terms and conditions; (2) to reject the new policy and delete their account; (3) to decide later.

Preliminary thoughts
When the news first broke that GEDmatch had been used to identify a murder victim known as the Buckskin Girl, I expressed concerns about the use of GEDmatch for this purpose without the explicit informed consent of the users. The use of GEDmatch in the identification of a suspect in the Golden State Killer case exacerbated those concerns. I am therefore very pleased that GEDmatch have taken prompt action to update their site policy. The revised policy is also a commendable example of transparency, and a welcome use of plain, simple and direct language.

If you'd asked me two months ago what would happen if it was revealed that GEDmatch had been used by the police in a murder investigation I would have predicted that large numbers of people would have withdrawn their data and that GEDmatch would have been pressurised to restrict access to law enforcement. I couldn't have been more wrong. While views have been mixed there has been a positive reaction from many members of the genetic genealogy community who are happy that their DNA has potentially been used to catch a killer.

GEDmatch have made a bold and brave move in legitimising the use of their site for law enforcement searches in specific circumstances. I think they are being genuinely altruistic and want to have GEDmatch used to bring closure to the affected families. They are to be commended for this decision.

However, we now have a very interesting situation. GEDmatch is a citizen science website that was initially set up to provide DNA and genealogy tools to help adoptees who were searching for their biological parents. At present all the police DNA databases use autosomal STR (short tandem repeat) markers, and up to 24 such markers are currently used. Although the number of markers used is very small, they are specially chosen for their variability, and there are very low odds that two people would have an identical DNA fingerprint. Autosomal STRs can be used for familial searches but are only effective for identifying very close relationships. The standard tests used for genetic genealogy use a different type of marker known as a SNP (single nucleotide polymorphism). Upwards of 600,000 autosomal SNPs are tested on a microarray chip. Results can be compared in a database using the amount of DNA shared and the length of the shared segments to make predictions about relationships. Predictions can be made with reasonable confidence in combination with genealogical records for relationships up to about the second cousin level. Predictions are more difficult for more distant relationships because of the random nature of DNA inheritance and the limitations of family tree research. As far as I'm aware, there is no police force in the world which has its own autosomal SNP database for familial searches. Bizarrely, as Sarah Zhang has pointed out GEDmatch.com has become "the de facto DNA and genealogy database for all of law enforcement". Given that probably around 80% of GEDmatch users are in the US, it is likely that, in the short term at least, it will only be the American police using GEDmatch in this way, though that situation could change as the consumer genetic testing market continues to grow internationally.

There are still many issues to be addressed going forwards. I have many questions but no answers:
  • Can privacy policies on websites be legally enforced?
  • What oversight will there be of these searches to ensure that the police use these powers responsibly?
  • Will there be an ethics committee or some other supervisory body which will scrutinise applications for such searches?  In the UK oversight is provided by the Biometrics Commissioner and Forensic Science Regulator. Do similar bodies exist in America and in other countries?
  • What measures will be taken to ensure that searches are proportionate and that large numbers of innocent third and forth cousins identified from a crime scene sample are not brought into the police dragnet? In America this could mean that your cousin will be stalked by armed police in an attempt to get a discarded item to obtain a DNA sample.
  • Which genealogists are qualified to perform such searches and how can the police verify whether a genealogist has the necessary skills and will behave in an ethical way?
  • How will people feel if their DNA is used to falsely incriminate an innocent person? There have already been recorded cases of well meaning volunteer search angels misidentifying the biological parents of adoptees. The stakes are much higher in criminal investigations, and especially in US states which still have the death penalty.
  • Is there a case for the police to upgrade their own databases so that they use autosomal SNPs instead of STRs?
All these issues will be discussed in the months and years to come, and it will be interesting to see what happens. For now I think it's important that everyone gets their voice heard. What do you think?

Monday, 30 April 2018

GEDmatch, Ysearch and the Golden State Killer

This is a rough and ready compilation of useful links in the Golden State Killer case which I am updating and re-organising on a regular basis as further information becomes available. Suggestions for additional links are welcome.
The coastline of the Golden State of California taken from a viewpoint near Bixby Bridge in June 2017.
There have been a lot of debates in the various genetic genealogy Facebook groups in the last few days about the implications for genealogy following the revelation that GEDmatch was used to narrow down the search for suspects in the hunt for a rapist and serial killer in California known as the Golden State Killer.

I've shared my views in this article for MIT Technology Review:

The brave new world of genetic genealogy

See also my short interview with Rosemary Collins of Who Do You Think You Are? Magazine

What are the risks of using DNA websites in criminal investigations?

I've provided below a compilation of the most useful links for further reading.

Articles by and interviews with genealogists

The moral maze of DNA testing by Philip Grass

Genealogy and the golden state killer by Leah Larkin, The DNA Geek

A comparison of GEDmatch and the FBI's CODIS database by Leah Larkin, The DNA Geek

The bull in the DNA china shop by Judy Russell, The Legal Genealogist

Dilemma: was it wrong to catch killer with DNA by Peter Calver, Lost Cousins newsletter

My fourth cousins, the Golden State Killer, and the Fourth Amendment by Laurie Pratt, Three Branch Tree

DNA Security: my thoughts in the wake of the Golden State Killer development by Brianne Kirkpatrick, Watershed DNA

A genealogical tragedy of the commons by Jacqui Stevens

How to find a killer using DNA and genealogy by Kitty Cooper

The Golden State Killer and DNA by Roberta Estes, DNAeXplained

The price of sharing  by Judy Russell, The Legal Genealogist

The secrets in your spit: using genetic genealogy to solve cold cases by Paul Woodbury, LegacyTree Genealogists

Extreme Genes Podcast interview with Paul Woodbury of Legacy Tree Genealogists Paul expresses concerns about the use of GEDmatch in cold cases

Extreme Genes interview with CeCe Moore CeCe explains the methodology she used to identify a suspect in a cold case murder and discusses the ethics of using GEDmatch to solve crimes

Meet the woman investigating cold case murders from her couch Megyn Kelly from USA Today interviews CeCe Moore

Exclusive: the woman behind the scenes who helped capture the Golden State Killer by Matthias Gafni, The Mercury News

She helped cracked the Golden State Killer case. Here's what she's going to do next by Heather Murphy, The New York Times

Articles by academics

The ethics of catching criminals using their family's DNA. Editorial. Nature.

How lucky was the genetic investigation into the Golden State Killer? by Graham Coop and Doc Edge, The Coop Lab.

Is your genome really your own? The public and forensic value of DNA by Nathan Scudder and Denise McNevin, The Conversation

A chat with the geneticist who predicted how the state may have tracked down the Golden State Killer Jon Cohen interviews Yaniv Erlich for Science

Is it ethical to use genealogy data to solve crimes? (£) by Benjamin E. Berkman, Wynter K. Miller and Christine Grady, Annals of Internal Medicine. 

Experts outline ethics issues with use of genealogy to solve crimes by Carolyn Crist, Reuters. A commentary on the above paper by Berkman et al. Reuters Health News.

Genealogy databases and the future of criminal investigation by Natalie Ram, Christi J. Guerrini and
Amy L. McGuire. Science Magazine. See also the interview with Natalie Ram and Amy L McGuire on Science Friday.

Re-identification of genomic data using long range familial searches (preprint) by Yaniv Erlich, Tal Shor, Shai Carmi and Itsik Pe'er. BioRxiv

Perspective: Sociogenetic risks — ancestry DNA testing, third-party identity, and protection of privacy by Thomas May. New England Journal of Medicine

Crowdsourced and crowdfunded: the future of forensic DNA by Nathan Scudder, Australian Journal of Forensic Sciences.

Forensic genealogy: some serious concerns by Denise Syndercombe Court, Forensic Science International Genetics 

The Golden State Killer investigation and the nascent field of forensic genealogy by Chris Phillips, Forensic Science International Genetics

Should police detectives have total access to public genetic databases? by Stephanie Fullerton and Rori Rohlfs, Leapsmag

Newspaper and magazine articles

DNA databases: biology stripped bare by Karlin Lillington, Irish Times

The creepy, dark side of DNA databases by Vera Eidelman of the American Civil Liberties Union writing in The Washington Post

Tentative thoughts on the use of genealogy sites to solve crimes by Orin Kerr, Reason

DNA website had unwitting role in Golden State manhunt by Kirsten Brown, Bloomberg News. Interesting background information on the people behind GEDmatch.

How a tiny website became the police's go-to genealogy database by Sarah Zhang, The Atlantic

DNA detectives are searching for killers in your family tree by Kirsten Brown, Bloomberg

Cold cases heat up as law enforcement uses genetics to solve past crimes by Diana Fine Maron, Scientific American

The unlikely crime-fighter cracking decades old murders. A genealogist? by Justin Jouvenal, Washington Post

Police can now track killers using relatives' DNA - but should they? by Chelsea Whyte, New Scientist

Background on the Golden State Killer case

For further information on the case I suggest reading the following article on NPR.

In hunt for Golden State Killer, investigators uploaded his DNA to genealogy site

Make sure too that you watch the interview with Paul Holes, the investigator involved with this case which is included on the above link.

There is an additional interview with Paul Holes providing further details in a New York Times podcast on 4th May 2018:

https://www.nytimes.com/2018/05/04/podcasts/the-daily/golden-state-killer-dna.html

This article explains how GEDmatch was used:

Here’s the ‘open-source’ genealogy DNA website that helped crack the Golden State Killer case

The US TV programme ABC 20/20 aired a special edition To Catch A Killer on 4th May on the DeAngelo case:

How DNA from family members helped solve the Golden State Killer case 

In this ABC 20/20 Extra segment CeCe Moore provides an excellent explanation of the methodology used by genetic genealogists in unknown parentage cases. This technique was used in the Golden State Killer case:

How investigators built a genetic genealogy leading to Golden State Killer arrest

The 20/20 Extra segment is also available on Twitter

https://twitter.com/ABC2020/status/992591964272021504

This article from the Washington Post has a good overview of the genealogical research that was done in this case:

To find alleged Golden State Killer, investigators first found his great-great-great grandparents

This is a good article by Sarah Zhang in The Atlantic covering some of the ethical issues:

How a genealogy website led to the alleged Golden State Killer

Some members of the genetic genealogy community are cited in the New York Times article which also discusses some of the ethical concerns:

The Golden State Killer is tracked through a thicket of DNA, and experts shudder

The search warrant information was released on 1st June 2018. See pages 49 and 50 for the details of how the police obtained surreptitious DNA samples (apparently perfectly legally) from DeAngelo's car door handle and from a tissue taken from his dustbin (trash can):

http://www.sacbee.com/latest-news/article212377094.html

Ysearch
The public Y-DNA database Ysearch was also used in the Golden State Killer investigation and that search resulted in an innocent person in an Oregon nursing home being ensnared into the investigation. See the report on the Associated Press website:

Serial killer search led to wrong man in 2017

It has since been revealed that the police took out a sub poena to access the customer's account at Family Tree DNA:

A DNA testing company was forced to reveal a customer’s identity for the Golden State Killer case. It turned out to be a false lead

The daughter of the man in the Oregon nursing home has spoken out to say that her father was happy  he was able to help with the investigation:

Daughter says local man whose DNA was tested in Golden State Killer case would do it again

Ysearch has previously been used in two other cases which resulted in the false incrimination of an innocent person.

A New Orleans filmmaker by the name of Michael Usry was falsely implicated in the 1996 murder of Angie Dodge as a result of a weak match found in the then public Sorenson Molecular Genealogy Foundation Y-DNA database. The police were told that a 34/35 Y-STR match indicated that it was "very close to a 100 percent" that the suspect's name was Usry.

New Orleans filmmaker cleared in cold case murder

In reality, even exact matches at 37 markers can indicate shared ancestry dating back for several thousand years. There are also some false positive 37/37 marker matches as a result of convergence.

As a result of this incident the valuable Sorenson Molecular Genealogy Foundation website was shut down by AncestryDNA.

RIP Sorenson - a crushing loss by Roberta Estes

In an investigation into the murder of Sarah Yarborough a Y-DNA match was said to indicate that the suspect's surname was Fuller.

DNA links 1991 killing to Colonial era family

In an awkward coincidence there was a William Fuller who was a colleague of the victim's father. His daughter was the best friend of the victim. In this case no DNA testing was done on the family members but his name was made public and must have led to some unwelcome gossip in his local community. The killer has never been found.

Cops hope Colonial ties reheat cold case

Ancestry.com
According to the book I'll Be Gone in the Dark by Michelle McNamara Ancestry.com's Y-STR database was also used in the search for the Golden State Killer:

https://books.google.co.uk/books?id=aSZHDwAAQBAJ&q=Ancestry#v=snippet&q=Ancestry&f=false

AncestryDNA discontinued Y-DNA and mtDNA testing back in June 2014 and closed down their Y-DNA and mtDNA matching databases in September 2014:

Ancestry.com announcement regarding discontinuation of Y-DNA and mtDNA tests.

UK position
Although these searches took place in America, Professor Denise Syndercombe Court, Professor of Forensic Genetics at Kings College London, has suggested that the same methodology could be deployed in the UK. See the following article in the Daily Mail:

UK police could now start using genealogy DNA databases to catch criminals despite ethical concerns after US police used one to snare the 'Golden State Killer', says top forensics expert

My view is that it is unlikely that such searches would be used in the UK. There are not enough British people in the GEDmatch database to make a search worthwhile. Such searches are also likely be in breach of article 8 of the European Convention on Human Rights. However, I am not a lawyer and we are in uncharted territory so I would not rule out the possibility.

The floodgates have opened
The Golden State Killer case has now opened the floodgates. Parabon has announced a new genetic genealogy service for law enforcement and has already "screened samples for nearly 100 agencies":

Parabon® announces Snapshot® Genetic Genealogy Service for law enforcement


Parabon uses an Illumina CytoSNP-850K chip:

https://docs.parabon.com/pub/Parabon_Snapshot_Scientific_Poster-ISHI_2016.pdf

The citizen scientist who finds killers from her couch A profile of CeCe Moore, Parabon's genetic genealogist, by Antonio Regalado and Brian Alexander, MIT Technology Review

Second success for the DNA Project
The DNA Doe Project has announced its second success with the identification of Lyle Stevik:

Dead man found in Washington State, who had ties to N.M., ID'd through DNA

The first success for the Parabon genetic genealogy service
The Parabon genetic genealogy unit led by CeCe Moore has announced its first success with the arrest of a suspect in a 1987 doubler murder

A double murder from 1987 was just solved thanks to the genealogy website used for the Golden State Killer by Peter Aldhous, BuzzFeed News

The recording of the press conference Kiro7 News on Facebook

The coming wave of murders solved by genealogy by Sarah Zhang, The Atlantic

GEDmatch has now been used in seven cases

Genealogists turn to family trees to cousins' DNA and family trees to crack five more cold cases by Heather Murphy, New York Times

Conclusions
Opinion within the genetic genealogy community has been divided. Many people are happy to have their DNA used to solve a crime and put a potential killer behind bars. Others are uncomfortable with the prospect of police intrusion into a genealogy database. It is up to each individual to make their own informed decision.

It is particularly important that if you are uploading kits to GEDmatch on behalf of relatives you make them fully aware of all the possible uses of their data. If you do not have their consent I recommend changing the settings and making their kits research use only so that they are not participating in the matching database. The same applies to kits uploaded to Ysearch.

For information on changing settings at GEDmatch see this article by David Moberly:

Protecting your privacy on GEDmatch

See also my blog post dated 21st May 2018 on updates to the Terms of Service and Privacy Policy at GEDmatch

Sunday, 30 July 2017

Living DNA updates and GEDmatch Genesis

While I was away on holiday in California in June Living DNA rolled out a couple of updates.

They have now provided us with the facility to download our raw data. You will find the new menu when you log into your Living DNA account.


We can use the raw data to do our own analyses and to upload the results to third-party sites to get additional interpretations. However, Living DNA uses a different chip from the other main testing companies (23andMe, AncestryDNA, Family Tree DNA and MyHeritage). The Living DNA test is run on the new Illumina Global Screening Array chip whereas the other companies are currently using the Illumina OmniExpress chip. As a result the Living DNA raw data is not compatible with other sites as there are not enough overlapping SNPs (markers) to make reliable relationship predictions. (Note, however, that if you are interested in getting health reports, you can upload your Living DNA raw data to Promethease.)

It's already been announced that 23andMe will be moving over to the GSA chip in due course, and it's likely that the other companies will eventually follow suit as the Illumina OmniExpress is being phased out. The GSA chip is designed for imputation. This is the process of inferring missing markers using statistical algorithms. Imputation can be done with a high degree of accuracy provided that sufficient reference populations are available. We will need to wait and see how the companies cope with the change but in theory the GSA chip is backwardly compatible with the OmniExpress. Much will depend on the quality of the imputation.

In the meantime the wonderful team at GEDmatch have come to the rescue. They are now beta-testing a new service called Genesis which will allow people to upload kits using formats that are not compatible with the main GEDmatch database. This includes Living DNA kits and exome sequences. The intention is that eventually the two databases will be merged.

GEDmatch are also in the process of developing an exciting new Genesis Algorithm which promises to provide more accurate matches. This is what the new Genesis home page looks like.

Here is a screenshot of the upload page.

I was successfully able to upload my Living DNA raw data to GEDmatch Genesis. When uploading your Living DNA data make sure you use the link for "Generic uploads (23andMe, FTDNA, Ancestry, most others)". Within a few minutes of uploading my raw data I was able to use the Genesis site to look at the various admixture calculators.

Here is a report using my Living DNA data with the Eurogenes K13 report. There are just 58623 SNPs used in this report.


When using the same Eurogenes K13 calculator on my standard GEDmatch kit 181512 SNPs are used in the comparison. However, as you can see from the screenshot below, the two reports are remarkably similar, despite the reduced number of SNPs used for the Living DNA comparison.


A few hours after I'd uploaded my results I was able to access my matches. Here is a screenshot of my matches with the kit numbers, names and e-mail addresses blurred out. Click on the image to enlarge it.


We are given information on the largest shared segment, the total cMs shared and the number of overlapping SNPs. Information is also provided about the confidence of the results. Confidence is very high for comparisons between two Living DNA kits but very low for comparisons with other companies.

All my matches are currently very low resolution and they go right down to matches that share a total of just 5 cMs. Few if any of these matches are likely to fall into a genealogical timeframe. Interestingly I've already spotted the names of four people I know amongst my Living DNA matches! As more people add their results to the Genesis database it will be a very useful way of making connections and doing comparisons across different testing companies. I look forward with interest to seeing how the Genesis algorithm develops.

The other new feature that Living DNA have rolled is what they call Family Views, which allows you to view your admixture results in Complete, Standard and Cautious modes. With the launch of this feature all our admixture results were completely rerun. This is because of teething problems with the new GSA chip. After initial quality control checks Illumina issued a new validation file to correct the errors. As validation continues it's possible that there will be further changes in the future. I will write separately about my updated Living DNA results in a future blog post.

There are also other updates in the pipeline as I learned at the Southern California Genealogical Society's Jamboree conference in June when a group of us attended a get-together with David Nicholson and Martin Blythe from Living DNA.

Living DNA should be able to accept uploads from other companies by the end of July. However, there are only a few days of July left and this hasn't yet happened so perhaps the launch of this feature has been delayed.

Living DNA are also working on a matching programme which they hope to start beta-testing in September.

A big update to our admixture results can be expected by the end of the year as more reference datasets are added to the collection. They will be including data from the Symons Genome Diversity Project, data from Asia and data from Aboriginals in Australia. Their Irish DNA Research Project is going well and they already have 1200 samples. They now have 450 people in their German DNA Research Project. Further projects are planned for France, Portugal, Austria, Belgium and the Netherlands.

We can look forward to some very exciting new developments in the next six months.

Further reading