Live data from Hacker News

Smartphones can be fooled by fake, digitally composed fingerprints

nytimes.com

91–100 of 114 posts

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#91

Earlier quoted context omitted.

The article currently linked here is not the same one originally linked. It was changed after I made my post. That said, the headline still explicitly calls out smartphones.

>article currently linked here is not the same one originally linked // Grr, hate it when they do that, it's clearly too hard to add a second link "previously the linked article was: ..."?

Like here? https://news.ycombinator.com/item?id=14318899

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#92
post #50

Earlier quoted context omitted.

> I don't see which iPhone they were able to unlock with this method They either didn't try, or were unable to and didn't document the results.

According to the article itself, they never actually tried unlocking a real phone.

That strains credulity.

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#93

Earlier quoted context omitted.

>> "Dr. Memon said their findings indicated that if you could somehow create a magic glove with a MasterPrint on each finger, you could get into 40 to 50 percent of iPhones within the five tries allowed before the phone demands the numeric password, known as a personal identification number." >I don't understand how this is possible at all. You're confusing Sensitivity (also called the true positive rate), Specificit…

I think the point is that it recognizes their fingerprint, and doesn't mistake it for any of the 999 other users. If it can tell the differences between a thousand fingerprints, why can't it be sensitive enough to reject at least 999/1000 false fingerprints? Think of it this way: What's the probability that one of the 5 master prints match their specific 1/1000 fingerprint, and not one of the other 999 customers? If…

You're assuming an equivalent amount of entropy between the 1000 real fingerprints and constructed fake ones which are attempting to be as close as possible to the real one. That seems unreasonable to me.

You're still also only considering false negatives (user is erroneously rejected). You have no data points about false positives (user is erroneously allowed).

If the sensor always detects and admits Bob, even when it's Alice, you'd have the exact same success data for Bob.

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#94

Earlier quoted context omitted.

I think the point is that it recognizes their fingerprint, and doesn't mistake it for any of the 999 other users. If it can tell the differences between a thousand fingerprints, why can't it be sensitive enough to reject at least 999/1000 false fingerprints? Think of it this way: What's the probability that one of the 5 master prints match their specific 1/1000 fingerprint, and not one of the other 999 customers? If…

You're assuming an equivalent amount of entropy between the 1000 real fingerprints and constructed fake ones which are attempting to be as close as possible to the real one. That seems unreasonable to me. You're still also only considering false negatives (user is erroneously rejected). You have no data points about false positives (user is erroneously allowed). If the sensor always detects and admits Bob, even when…

>You're still also only considering false negatives (user is erroneously rejected). You have no data points about false positives (user is erroneously allowed).

As far as I understood, the system is distinguishing between its members so we have some data about false positives because OP was always identified as themselves and never as another member.

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#95

There are all sorts of reasons fingerprints are not a highly secure authentication mechanism. Just as there are all sorts of reasons passwords and other techniques are imperfect. Password entry can be observed. Chosen passwords are frequently insecure, particularly on smartphones where brevity is so important. Fingerprints are an excellent mechanism for almost all threat vectors for your average consumer smartphone.…

>It's important for people who are dissidents or engaging in criminal activity to be aware that their brain is more secure than their fingerprint, although that seems entirely obvious to anyone capable of maintaining a high security lifestyle.

The problem with the brain is that it forgets. For example if you have an important piece of information that you encrypt with a long passphrase, you will likely have no problem decrypting it if you do so every day but if you don't use the passphrase for a few months, you probably won't remember it. However you probably will remember where you have the passphrase if you write it down and put it somewhere secret where nobody will be able to both find it and to know what it's for. IOW, don't hide the paper in your house.

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#96
Modern fingerprint scanners use various methods to detect if it's a living finger or if it's a static image.

This "research" could not beat any phone using a modern fingerprint scanner with liveness detection.

Using fingerprints may not be a perfect solution but it beats 4-digit pincodes and passw0rds. Next level in a few years, we'll have retina scanners in our phones, cars and IoT including peppes pizza ads in Oslo. Then 1984 will look like a bedtime story for kids.

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#97

I shouldn't be surprised, but the reporting on this makes it sound way different than the actual research. Specifically, none of the research appears to have been performed on, or tested against ACTUAL SMARTPHONE implementations - for example: "Experiments on a capacitive fingerprint dataset, similar to the one used by Apple TouchID, showed that it is possible to break 6.88% of users’ account in 5 attempts if the FMR…

> The researchers did not test their approach with real phones, and other security experts said the match rate would be significantly lower in real-life.

You are indeed correct. I wish someone would do a full test on how secure the readers are.

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#98

There are all sorts of reasons fingerprints are not a highly secure authentication mechanism. Just as there are all sorts of reasons passwords and other techniques are imperfect. Password entry can be observed. Chosen passwords are frequently insecure, particularly on smartphones where brevity is so important. Fingerprints are an excellent mechanism for almost all threat vectors for your average consumer smartphone.…

Considering there is no 'active' part (e.g. no known secret) it cannot be used for authorization, only for identification. The 'kids unlock phone with sleeping parent and buy stuff' techniques are a clear proof of this. Fine for identification, do not use for authorization (e.g. using secrets like when you buy stuff).

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#99
Biometrics are in general a bad way to implement security. Finger prints and iris scans can easily be stolen many times by just browsing a person's Facebook profile photos. We have already started depending on these to allow access to bank accounts.

I live in India, and there are already companies with phones that have iris and fingerprint scanners to link with each individual's Aadhar ID and grant access to all government and financial services including bank accounts, and even online shopping [1]. Unlike regular credit card transactions, these are supposed to be authenticated, so you cannot ask for a chargeback. Data for 130 million Indian people including their Aadhaar numbers and bank details was recently leaked accidentally. [2] There is a big disaster here just waiting to happen.

[1]: http://www.ndtv.com/india-news/shop-online-soon-with-fool-pr...

[2]: http://indiatoday.intoday.in/technology/story/aadhaar-data-o...

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#100
post #74
post #70

Earlier quoted context omitted.

In "real life"—unless there was some absolute urgency to the problem—you wouldn't try to reconstruct a smudged partial print; you'd just use social engineering/espionage tactics to get a good print. (Remember that iOS locks and/or wipes devices after 10 failed attempts. You want to go to however much effort is required to be perfect the first time.) I can think of a number of situations one could create where a perso…

I imagine that sort of "committed adversary" is also quite capable of hitting you with a $5 wrench until you tell them the passcode...

They only have to hit you once, and then put your finger on the button
Post reply on HN