Archives

Genotype Extraction and False Relative Attacks: Security Risks to Third-Party Genetic Genealogy Services Beyond Identity Inference

This paper analyzes the security practices of GEDmatch, the largest third-party genetic genealogy service, for security and privacy issues. We find that an attacker can extract a large percentage of the genetic markers from other users and that an adversary can construct genetic data files that falsely appear like relatives to other samples in the database. We conclude with security recommendations for genetic genealogy services. This paper is accepted to the 2020 Network and Distributed System Security Symposium (NDSS).