Live data from Hacker News

Smartphones can be fooled by fake, digitally composed fingerprints

nytimes.com

11–20 of 114 posts

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#11

Totally not relevant, but holy cow Google Translate is getting good. I swear I've read articles in plain English that were less comprehensible than this translated on, by a mile.

First sentence:

> The fact that the fingerprint sensors on smartphones are not quite as secure as the manufacturers want us to believe, has already emerged with the first iPhone with this feature.

Ok, a bit awkward

> The technique has improved since then, the methods to crack it but also turn.

Uh, what?

> And not with the means of the analog, but the digital world - via machine learning and an artificial intelligence.

I agree that if you're scanning, you might not realize that you're reading a translation, but it's very obvious to me if I slow down and actually read it.

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#12
post #7

Honestly, I've never cared about the fingerprint reader for security. I just see it as a better way to prevent my phone from turning on in my pocket and butt-dialing someone. I never put a password on my phone before the fingerprint reader. The apps that I care about protecting have password functionality built-in.

What about 2-factor auth or sms two factor auth or access to your gmail client?

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#13
post #3

There's no reason to cite a Google-translated version of this article when a suitable, well-explained English article exists in the New York Times: https://mobile.nytimes.com/2017/04/10/technology/fingerprint... As the article notes, you really need more than one imprint in order to get into a phone - the authors suggest that five distinct imprints could get into about 40-50% of phones, which fits within the 5 try li…

Right. Url changed from https://translate.google.com/translate?sl=auto&tl=en&u=https....

Submitters: Please don't post Google translate links.

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#14
post #7

Honestly, I've never cared about the fingerprint reader for security. I just see it as a better way to prevent my phone from turning on in my pocket and butt-dialing someone. I never put a password on my phone before the fingerprint reader. The apps that I care about protecting have password functionality built-in.

> I never put a password on my phone before the fingerprint reader. The apps that I care about protecting have password functionality built-in.

What email client and web browser do you use that protect access via a password?

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#15

Totally not relevant, but holy cow Google Translate is getting good. I swear I've read articles in plain English that were less comprehensible than this translated on, by a mile.

First sentence: > The fact that the fingerprint sensors on smartphones are not quite as secure as the manufacturers want us to believe, has already emerged with the first iPhone with this feature. Ok, a bit awkward > The technique has improved since then, the methods to crack it but also turn. Uh, what? > And not with the means of the analog, but the digital world - via machine learning and an artificial intelligence…

In context, I think it (that specific bit) is fairly easy to follow:

The technique has improved since then, the methods to crack it but also turn. The eternal cat and mouse game between team blue and team red.

So, apparently the first sentence means that the technique has improved since then, but so have the methods trying to crack it.

Though, to be fair, I have no clue what rumgeilt means and that was apparently just not translated at all.

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#16
post #6

Totally not relevant, but holy cow Google Translate is getting good. I swear I've read articles in plain English that were less comprehensible than this translated on, by a mile.

I didn't look closely at the link or url and didn't realize that I was reading Google Translate until I saw your comment. That's scary good translation.

I didn't realize either but I had a very hard time following what was being explained and assumed it was just poorly written.

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#17

Totally not relevant, but holy cow Google Translate is getting good. I swear I've read articles in plain English that were less comprehensible than this translated on, by a mile.

It's pretty good at European languages, but still terrible at Arabic and Japanese. The system still has a very shallow understanding of the content. One of my primarily Arabic-speaking colleagues was actually offended by Google Translate butchering their language so badly; their culture places a relatively high value on poetry, calligraphy, etc.

As an exercise, try translating your search queries into Arabic before searching. Then, let Google translate the results for you. It is hilarious.

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#18
post #12
post #7

Honestly, I've never cared about the fingerprint reader for security. I just see it as a better way to prevent my phone from turning on in my pocket and butt-dialing someone. I never put a password on my phone before the fingerprint reader. The apps that I care about protecting have password functionality built-in.

What about 2-factor auth or sms two factor auth or access to your gmail client?

You know, not everyone uses gmail.

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#19
post #3

There's no reason to cite a Google-translated version of this article when a suitable, well-explained English article exists in the New York Times: https://mobile.nytimes.com/2017/04/10/technology/fingerprint... As the article notes, you really need more than one imprint in order to get into a phone - the authors suggest that five distinct imprints could get into about 40-50% of phones, which fits within the 5 try li…

From the NYT article.

> The researchers did not test their approach with real phones, and other security experts said the match rate would be significantly lower in real-life conditions. Still, the findings raise troubling questions about the effectiveness of fingerprint security on smartphones.

I wonder what the actual impact/severity is.

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#20
> "Dr. Memon said their findings indicated that if you could somehow create a magic glove with a MasterPrint on each finger, you could get into 40 to 50 percent of iPhones within the five tries allowed before the phone demands the numeric password, known as a personal identification number."

I don't understand how this is possible at all. I've always assumed that each fingerprint is essentially turned into a hash, and that there must be something like at least 10,000+ possible hashes. I mean, I used to belong to a gym that used a fingerprint reader for entry, and it correctly identified me (flashing my name) from the other 1,000+ members each time.

So as long as the hash space is reasonably large, it doesn't matter what these 5 magic imprints are, they still each convert to just 1 hash, no different from any other fingerprints.

Am I missing some critical aspect here to explain how "master prints" are even plausible -- how they could possibly act as "wildcards" for large swathes of hashes?

Post reply on HN