Live data from Hacker News

Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys

cnet.com

81–90 of 141 posts

Re: Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys

#81
post #5
post #2

"used her mother's thumb to unlock a phone and open the Amazon app as mom napped on the couch" Or she made it up.....

This is one of those stories where even if it is partially or entirely fabricated, the probability of something like it happening somewhere is nearly 100%. The odd thing about the story may be that this is the one that happened to get to the news, given how many times such things have probably happened. (Similarly for the DailyWTF stories that people often claim can't be real. Well, even if the story you're looking a…

I actually heard a similar story within my family very recently. My sister had left her young (~1 yrl) daughter with a phone to amuse itself .. and later received an email from eBay letting her know she'd been outbid - on a car.

I must admit, however, my first thought wasn't about authentication - but on the wisdom of using phones as babysitters.

(Of course, I should say I have no idea whether this actually happened either, or if my sister just realised she hadn't reminded us she's a mother for 20 minutes. I didn't ask, it's drama I could live without.)

Re: Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys

#82

Earlier quoted context omitted.

This is the problem with "news" stories like this... and why I hate them. We would have no way of knowing if this happened or not. It's plausible, but plausible isn't the same as "it happened". One could say at best its value is as a cautionary tale to other parents, but I'm willing to bet that if you're a parent you've probably seen the potential for this sort of thing develop in your child already... of course that…

"and once upon a time that sort of thing [autoplay video/audio] was avoided" It was? I remember websites showing off their ability to make your browser automatically play background music as early as the late 90's / early 00's.

I'm not suggesting that it didn't ever happen at all; it certainly did on things like personal/vanity sites, some artsy-fartsy sites, but not on the more professional/commercial sites.

Professionally, I remember being in design meetings ~'96/'97 where someone would say, "hey, we could...[blast audio/video]" and the more in the know people would down the idea as being bad form [without regard to the bandwidth issues at the time]. That's the attitude I miss.

Re: Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys

#83

It seems like they could add a few less-predictable factors to improve the security of thumbprints without completely ruining their convenience. For instance: — Maybe you must use two or more particular fingerprints in sequence, selected by you in advance. This would require a “sleep attack” to at least try different combinations of your fingers (without knowing which to use first or how many fingers are required). —…

This will only end in nano-blood-draws with genotypic personalization built into my online refrigerator all over LDAP.

Of course both the blood drawer and the genotype analytics service will both be operating on two different clouds. Don't forget to pay your Internet bill if you don't want to starve.

Re: Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys

#84
post #66

Earlier quoted context omitted.

They'd need your whole hand, since any finger can be used for a smartphone biometric scanner. Truthfully, lots of different scannable areas will unlock a phone. I've successfully and reliably configured my toes, the knuckles on my hands, and the tip of my nose. All of them work pretty good. Unless observed using biometric security in a specific manner, an adversary might have a hard time deducing what kind of print w…

If you're robbing an iPhone user, you'd probably be safe hacking off a thumb. Can't imagine many people give up the convenience of using their thumbs to unlock. With me they'd have to take my index fingers because I've got a phone with the reader on the back of the device (which, imo, is the best place to put it, as far as convenience goes.)

> If you're robbing an iPhone user, you'd probably be safe hacking off a thumb. Can't imagine many people give up the convenience of using their thumbs to unlock.

Anecdotal, but I know people who have configured only the index finger to unlock the phone because they prefer it to the thumb.

Re: Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys

#85
post #77
post #64

Earlier quoted context omitted.

And I thought me using a keylogger as a teen to access my mom's AOL account was impressive. Clever 6 year old.

I wish my tech arms race with my parents had been simple...I had to socially engineer my dad into logging into the router on my desktop(no keylogger, just firefox password saving) so I could bypass whatever he was doing to cut me off at midnight.

In some ways mine wasn't as simple as it seems. My primary source of consistent access to the internet was a 1 hour time-limited, content-restricted AOL account. I had to learn and acquire anything I needed within those confines. Even Google was blocked...I had to use some weird, generic search engine. And I couldn't escape to do these things at school because their computers were even more locked down/monitored. After I got busted for using the keylogger (less than 24 hours later), I discovered the wonderful world of using fake info to get unlimited juno trial accounts (x hours for free!!)

Re: Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys

#86

i'm seeing two (obvious) bigger picture trends here that this story reinforces. 1. Digital authentication for purchasing is moving towards non-transferable biometrics ( i cant divulge my thumbprint like i can my pin ) 2. Goods of all kinds are being delivered faster The scary thing for me is that thieves love goods delivered quickly, so they can turn them quickly, and cut down on their ability to get intercepted. So…

Chopping off your thumb is only in movies, where logic barely exists. In real life, you can cancel your funds and reverse their fraudulent transactions.

How're you gonna do that without thumbs?

Re: Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys

#87
post #29

Earlier quoted context omitted.

That's a really nice distinction. It feels like there's a bit of a spectrum, though. The lock on a houses door won't prevent a determined criminal, but it sends a very strong signal and is inconvenient to break. Perhaps we should thing of there as being multiple dimensions to locks, such as security, signaling, effort to circumvent, and convenience? (Perhaps also conscientiousness in disabling, in relation to @saoseb…

Definitely a spectrum. Bike locks are for security, but mainly just to make your bike less convenient than another one nearby. If someone wants into YOUR phone, they'll get it. If someone wants into A phone, a thumbprint may be plenty.

Being widespread is a double-edged sword though. The more people have such an inconvenience-based security, the better they are, but if everyone has bike locks, the thieves simply start carrying bolt cutters with them. We're maybe two or three years before majority of smartphones in use have fingerprint scanners...

Re: Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys

#88

i'm seeing two (obvious) bigger picture trends here that this story reinforces. 1. Digital authentication for purchasing is moving towards non-transferable biometrics ( i cant divulge my thumbprint like i can my pin ) 2. Goods of all kinds are being delivered faster The scary thing for me is that thieves love goods delivered quickly, so they can turn them quickly, and cut down on their ability to get intercepted. So…

Well, a common type of robbery in Brazil is what's called "lightning kidnapping" due to this reason. Assailants take people by force in order to make them withdraw money from ATMs using biometric security.

Re: Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys

#89
post #37

i'm seeing two (obvious) bigger picture trends here that this story reinforces. 1. Digital authentication for purchasing is moving towards non-transferable biometrics ( i cant divulge my thumbprint like i can my pin ) 2. Goods of all kinds are being delivered faster The scary thing for me is that thieves love goods delivered quickly, so they can turn them quickly, and cut down on their ability to get intercepted. So…

The most fascinating part for me is that 6 year old managed to find a way to circumvent biometric security without hacking off someone's finger: authenticate while the user is asleep. Necessity is truly the mother of innovation.

Many friends of mine disabled that feature right after the story about someone's wife unlocked it while he was asleep. That can be orders of magnitude more expensive than $250, in one touch.

Re: Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys

#90
Biometrics are _not_ passwords! You can never change them. You know, if everyone starts spreading their biometrics around willy-nilly, one day one of those databases WILL be hacked. And then what? Oops all the biometric data leaked and now every service that uses them as a password just got pwned.

I will never be providing any biometrics to a service that uses them as a password if I have the power to do so. Biometrics work great as a _username_, not passwords!

Post reply on HN