Security Flaw Left Popular DNA Software Vulnerable to Hacking for 30 Years

627199.jpg

In May, forensic researchers discovered a security flaw in Applied Biosystems Human Identification Software—the software most American crime labs use to read DNA evidence—that left it vulnerable to nearly undetectable modification to .fsa/.hid file outputs. According to the Wall Street Journal, the vulnerability is likely to have existed since 1995—potentially putting 31 years of prosecutions at risk.

On Friday, Thermo Fisher Scientific issued a Security Bulletin that addressed the problem and confirmed a solution in place: security updates that implement the use of digital signatures to add an extra layer of protection that, moving forward, will help customers verify that data files have not been modified.

Laura Gaydosh Combs, forensic scientist and University of New Haven professor, and Sarah Chu, the director of policy and reform at the Perlmutter Center for Legal Justice, both worked on the research project identifying the security flaw.

According to the Journal, they found that with the help of computer code written by widely available AI software, they could alter the data produced from computerized scans of physical DNA evidence without leaving any trace they had tampered with the records.

Nathan Adams, a systems engineer at Forensic Bioinformatics, an Ohio-based DNA consulting company, tested the issue earlier this year using a public data set of DNA files. Using Anthropic’s Claude, Adams said his first success at changing a file took about 45 minutes. While some file types have a higher level of encryption, Adams was easily able to find a decryption key that has existed on the internet for years. In a test, Adams’s code was able to combine the scans of two individual DNA profiles into a new file that appeared untouched since 2015. The modified file raised no red flags in the Applied Biosystems Human Identification Software.

While the risk may be three decades old, the recent explosion of amateur AI tools made potential tampering much easier than it would have been even just a couple years ago. 

No known exploitation

In a separate note to customers, Thermo Fisher Scientific emphasized that there were no known instances where the vulnerability had been exploited in the past, the Journal reports.

However, the security risk itself is described as an “undetectable modification.” That being said, someone would need local or remote access to the crime lab’s servers to corrupt the digital evidence files, even in an undetectable way.

Thermo’s updated software versions to address the security risk include:

  • Applied Biosystems 3500/3500xL Series Data Collection Software version 4.0.2 and earlier
  • Applied Biosystems 3730/3730xL Series Data Collection Software version 5.0.2 and earlier
  • Applied Biosystems SeqStudio Genetic Analyzer Data Collection Software version 1.2.5 and earlier
  • Applied Biosystems SeqStudio Flex Series Instrument Software version 1.2.0 and earlier
  • Applied Biosystems GeneMapper™ ID-X Software version v1.7.3 and earlier

For software versions that have reached end-of-life, Thermo Fisher Scientific will not be providing an update. These include: Applied Biosystems 3130 Series Data Collection Software version 4.1 and earlier; ABI PRISM 3100/3100-Avant Data Collection Software version 2.0 and earlier; and ABI PRISM 310 Data Collection Software version 3.1 and earlier.

For customers unable to implement the updates or use another third-party analysis platform, Thermo Fisher Scientific said they recommend best practices “in alignment with your organization’s security measures and policies,” including a secure chain of custody for files, storing generated files on encrypted storage media, restricting access to authorized personnel only, limiting user permissions, and leveraging firewalls.



Subscribe to our e-Newsletters
Stay up to date with the latest news, articles, and products for the lab. Plus, get special offers from Forensic – all delivered right to your inbox! Sign up now!

More News