Live data from Hacker News

Researchers Created Fake 'Master' Fingerprints to Unlock Smartphones

motherboard.vice.com

21–30 of 69 posts

Re: Researchers Created Fake 'Master' Fingerprints to Unlock Smartphones

#21
post #5

Earlier quoted context omitted.

I don't know where I read it, but it always stuck to me: identification is more like a username, not a password, and should be used as such.

I believe everybody knows fingerprints or face are not a perfect solution for unlocking mobile phones, but so far they seem to be the best option currently available (taking into account the ease of shoulder surfing and inconvenience of entering secure passwords on small screen).

I'm not going to dispute shoulder surfing is a big problem for unlock patterns, but if you do not care about that attack vector patterns are super efficient and freakingly hard to brute-froce. Considering about 400k combinations [1] on a 3x3 board with a 30sec lockdown every 5 tries it will take on average about 14 days to unlock (given that the pattern is random enough). The average 4 digit pin is doable in about 8 hours on average.

I'm willing to neglect the shoulder surfing attack vector as I feel I keep my phone sufficiently secure from pick pocketing and am not afraid of an "inside attack". Might definitely reconsider this, if I would have to carry a business phone with important secret information though.

[1] https://math.stackexchange.com/questions/634437/how-many-com...

Re: Researchers Created Fake 'Master' Fingerprints to Unlock Smartphones

#22
I'm fine with "casual" security like my fingerprints for my phone and laptop as primary authentication. It annoys me I have to enter a password first from a user experience perspective.

There's definitely need for very hardened phones from physical attack (journalists, canaries, whistleblowers, etc). I'm just not that important so I wish I could choose my security level.

Re: Researchers Created Fake 'Master' Fingerprints to Unlock Smartphones

#23

Speaking of biometrics: anyone remember that Vietnamese shop (Bkav) who made a big stir out of breaking Face ID a week after launch? Was that ever independently verified, or has anyone else broken Face ID a year later? I remember there being a lot of skepticism about their claim because they didn’t go into that much technical detail, but rather seemed more interested in winning press and fame (as well as being incred…

Bkav seem to be a bunch of fear-peddling shysters. Their antivirus software is notorious for false positives.

Re: Researchers Created Fake 'Master' Fingerprints to Unlock Smartphones

#24

There actually is no proof that finger prints are unique. Last time I looked into it. The same goes for DNA.

How could DNA be non-unique, except for identical twins or clones?

Chance?

Hashes are not unique by definition, though we can treat them as such in many practical situations. The same is true for anything with a fixed number of variables with finite states, e.g. DNA.

Re: Researchers Created Fake 'Master' Fingerprints to Unlock Smartphones

#25

Not enough detail in the article. There is no discussion of what sensors were used to "fool". Now everyone will assume it works on all actual devices using fingerprints, yet there is no information to support that conclusion. If this technique were applied to actual devices (with fingerprints not included in the study) and it worked reliably, then this would be a meaningful study.

Here is the paper on arxiv: https://arxiv.org/abs/1705.07386

So the experiment is done against VeriFinger [1], which seems like a software solution for fingerprint identification. No actual device is used in the paper, and I assume it is less sophisticated then Apple Touch ID or something.

[1] https://www.neurotechnology.com/verifinger.html

Re: Researchers Created Fake 'Master' Fingerprints to Unlock Smartphones

#26

I'm fine with "casual" security like my fingerprints for my phone and laptop as primary authentication. It annoys me I have to enter a password first from a user experience perspective. There's definitely need for very hardened phones from physical attack (journalists, canaries, whistleblowers, etc). I'm just not that important so I wish I could choose my security level.

This approach brings up a host of issues, such as: if you’re the only one with a strongly secured device, it raises suspicion; it requires much more effort to become a whistleblower etc, and people inclined to do it, won’t; if “casual” is deemed good enough for most people, strongly secured devices won’t be made or will be so expensive no one can reasonably obtain them; etc.

Re: Researchers Created Fake 'Master' Fingerprints to Unlock Smartphones

#27
post #6

Earlier quoted context omitted.

And honestly they're not that convenient. The Touch ID in my iPhone 8+ rejects my print at least a dozen times a day. On some days it rejects it many times in a row, forcing me to key in my unlock code. Research like this, while ostensibly threatening an increase in false positives (due to unauthorized use of fake prints), will in all likelihood cause vendors to tighten the confidence interval, leading to greatly inc…

Sounds like you should maybe retrain it. My iPhone 6, which has the older sensor tech is fine: unless my hands are wet

I retrain it all the time. It doesn't help. If there's any skin oil or sweat on the sensor it doesn't work.

It also gets confused if there's any dead skin on my thumb, something that seems to happen pretty often (and I don't even play Nintendo anymore).

Re: Researchers Created Fake 'Master' Fingerprints to Unlock Smartphones

#28

There actually is no proof that finger prints are unique. Last time I looked into it. The same goes for DNA.

Fingerprints, and especially the data captured by fingerprint sensors, is not unique, but it is so unlikely that two people will be recognized as the same one, that they are good enough.

Re: Researchers Created Fake 'Master' Fingerprints to Unlock Smartphones

#29
post #21

Earlier quoted context omitted.

I believe everybody knows fingerprints or face are not a perfect solution for unlocking mobile phones, but so far they seem to be the best option currently available (taking into account the ease of shoulder surfing and inconvenience of entering secure passwords on small screen).

I'm not going to dispute shoulder surfing is a big problem for unlock patterns, but if you do not care about that attack vector patterns are super efficient and freakingly hard to brute-froce. Considering about 400k combinations [1] on a 3x3 board with a 30sec lockdown every 5 tries it will take on average about 14 days to unlock (given that the pattern is random enough). The average 4 digit pin is doable in about 8…

"I'm not going to dispute shoulder surfing is a big problem for unlock patterns..."

I always liked the password alternative of showing the user a bunch of pictures or photos in random positions and have them select a number of them in sequence, perhaps showing a whole new set of pictures in between each selection.

Humans tend to have much better visual memory than verbal memory, so they're able to remember this kind of sequence better than a password, especially if the pictures they select are somehow meaningful to them. This is also very difficult for someone to shoulder surf effectively, as they'll be seeing these pictures for the first time and the pictures won't have any meaning for them.

I heard about this idea decades ago, but have never seen it implemented.

Re: Researchers Created Fake 'Master' Fingerprints to Unlock Smartphones

#30

There actually is no proof that finger prints are unique. Last time I looked into it. The same goes for DNA.

There are no proofs of any kind about the natural world. However, it could be shown with a small population sample that fingerprint and dna signatures from the respective technologies are statistically unique.

So, for fingerprints, have actual similarity studied been performed on a sample size large enough to draw conclusions about the test of the population?
Post reply on HN