Earlier quoted context omitted.
The article currently linked here is not the same one originally linked. It was changed after I made my post. That said, the headline still explicitly calls out smartphones.
>article currently linked here is not the same one originally linked // Grr, hate it when they do that, it's clearly too hard to add a second link "previously the linked article was: ..."?
Smartphones can be fooled by fake, digitally composed fingerprints
91–100 of 114 posts
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#92Earlier quoted context omitted.
> I don't see which iPhone they were able to unlock with this method They either didn't try, or were unable to and didn't document the results.
According to the article itself, they never actually tried unlocking a real phone.
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#93Earlier quoted context omitted.
>> "Dr. Memon said their findings indicated that if you could somehow create a magic glove with a MasterPrint on each finger, you could get into 40 to 50 percent of iPhones within the five tries allowed before the phone demands the numeric password, known as a personal identification number." >I don't understand how this is possible at all. You're confusing Sensitivity (also called the true positive rate), Specificit…
I think the point is that it recognizes their fingerprint, and doesn't mistake it for any of the 999 other users. If it can tell the differences between a thousand fingerprints, why can't it be sensitive enough to reject at least 999/1000 false fingerprints? Think of it this way: What's the probability that one of the 5 master prints match their specific 1/1000 fingerprint, and not one of the other 999 customers? If…
You're still also only considering false negatives (user is erroneously rejected). You have no data points about false positives (user is erroneously allowed).
If the sensor always detects and admits Bob, even when it's Alice, you'd have the exact same success data for Bob.
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#94Earlier quoted context omitted.
I think the point is that it recognizes their fingerprint, and doesn't mistake it for any of the 999 other users. If it can tell the differences between a thousand fingerprints, why can't it be sensitive enough to reject at least 999/1000 false fingerprints? Think of it this way: What's the probability that one of the 5 master prints match their specific 1/1000 fingerprint, and not one of the other 999 customers? If…
You're assuming an equivalent amount of entropy between the 1000 real fingerprints and constructed fake ones which are attempting to be as close as possible to the real one. That seems unreasonable to me. You're still also only considering false negatives (user is erroneously rejected). You have no data points about false positives (user is erroneously allowed). If the sensor always detects and admits Bob, even when…
As far as I understood, the system is distinguishing between its members so we have some data about false positives because OP was always identified as themselves and never as another member.
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#95There are all sorts of reasons fingerprints are not a highly secure authentication mechanism. Just as there are all sorts of reasons passwords and other techniques are imperfect. Password entry can be observed. Chosen passwords are frequently insecure, particularly on smartphones where brevity is so important. Fingerprints are an excellent mechanism for almost all threat vectors for your average consumer smartphone.…
The problem with the brain is that it forgets. For example if you have an important piece of information that you encrypt with a long passphrase, you will likely have no problem decrypting it if you do so every day but if you don't use the passphrase for a few months, you probably won't remember it. However you probably will remember where you have the passphrase if you write it down and put it somewhere secret where nobody will be able to both find it and to know what it's for. IOW, don't hide the paper in your house.
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#96This "research" could not beat any phone using a modern fingerprint scanner with liveness detection.
Using fingerprints may not be a perfect solution but it beats 4-digit pincodes and passw0rds. Next level in a few years, we'll have retina scanners in our phones, cars and IoT including peppes pizza ads in Oslo. Then 1984 will look like a bedtime story for kids.
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#97I shouldn't be surprised, but the reporting on this makes it sound way different than the actual research. Specifically, none of the research appears to have been performed on, or tested against ACTUAL SMARTPHONE implementations - for example: "Experiments on a capacitive fingerprint dataset, similar to the one used by Apple TouchID, showed that it is possible to break 6.88% of users’ account in 5 attempts if the FMR…
You are indeed correct. I wish someone would do a full test on how secure the readers are.
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#98There are all sorts of reasons fingerprints are not a highly secure authentication mechanism. Just as there are all sorts of reasons passwords and other techniques are imperfect. Password entry can be observed. Chosen passwords are frequently insecure, particularly on smartphones where brevity is so important. Fingerprints are an excellent mechanism for almost all threat vectors for your average consumer smartphone.…
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#99I live in India, and there are already companies with phones that have iris and fingerprint scanners to link with each individual's Aadhar ID and grant access to all government and financial services including bank accounts, and even online shopping [1]. Unlike regular credit card transactions, these are supposed to be authenticated, so you cannot ask for a chargeback. Data for 130 million Indian people including their Aadhaar numbers and bank details was recently leaked accidentally. [2] There is a big disaster here just waiting to happen.
[1]: http://www.ndtv.com/india-news/shop-online-soon-with-fool-pr...
[2]: http://indiatoday.intoday.in/technology/story/aadhaar-data-o...
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#100Earlier quoted context omitted.
In "real life"—unless there was some absolute urgency to the problem—you wouldn't try to reconstruct a smudged partial print; you'd just use social engineering/espionage tactics to get a good print. (Remember that iOS locks and/or wipes devices after 10 failed attempts. You want to go to however much effort is required to be perfect the first time.) I can think of a number of situations one could create where a perso…
I imagine that sort of "committed adversary" is also quite capable of hitting you with a $5 wrench until you tell them the passcode...