Live data from Hacker News

Researchers Created Fake 'Master' Fingerprints to Unlock Smartphones

motherboard.vice.com

61–69 of 69 posts

Re: Researchers Created Fake 'Master' Fingerprints to Unlock Smartphones

#61

I always get a kick out of technical methods like this because all you would really have to do is punch the owner in the face and use his or her fingerprint to unlock the device. It's sort of like the 5 dollar crowbar from xkcd.

True, although these methods can be used more clandestinely. If you punch someone in the face and use their fingerprint, they know it.

If you compromise their accounts from the other side of the world by tricking a fingerprint reader, they won’t know immediately. And you’ll have broken fewer laws, and possibly be located in a country without extradition.

Re: Researchers Created Fake 'Master' Fingerprints to Unlock Smartphones

#62

There actually is no proof that finger prints are unique. Last time I looked into it. The same goes for DNA.

How could DNA be non-unique, except for identical twins or clones?

The DNA usually isn’t completely sequenced. Instead, they look at specific regions of the genome called short tandem repeats, or STRs. Each STR consists of a short pattern of a few bases that repeats over and over. The theory is that individuals have different numbers of repeats—you might have ten repeats of AATG at the TPOX locus, while I only have nine. Individually, this doesn’t tell you much, but if you combine information from multiple loci—six repeats there, seven here, and four there-you can rapidly find profiles that are unlikely to belong to more than one person. This works best if the set are statistically independent.

Still, one can be (un)lucky, or the statistical models could be wrong—maybe the number of repeats is different in a sub population or the STRs aren’tstatistically independent.

Re: Researchers Created Fake 'Master' Fingerprints to Unlock Smartphones

#63
post #6

Earlier quoted context omitted.

And honestly they're not that convenient. The Touch ID in my iPhone 8+ rejects my print at least a dozen times a day. On some days it rejects it many times in a row, forcing me to key in my unlock code. Research like this, while ostensibly threatening an increase in false positives (due to unauthorized use of fake prints), will in all likelihood cause vendors to tighten the confidence interval, leading to greatly inc…

Sounds like you should maybe retrain it. My iPhone 6, which has the older sensor tech is fine: unless my hands are wet

I've always just entered the same finger for every finger option, not really sure how much it helps however.

Re: Researchers Created Fake 'Master' Fingerprints to Unlock Smartphones

#64
post #4
post #2

> Biometric IDs seem to be about as close to a perfect identification system as you can get. This seems a massive assertion that’s not qualified at all in the article. It was my understanding that biometrics in consumer hardware have always been easily circumvented and are largely about convenience.

I think you need to read that sentence with emphasis on "seem". They make this clear two sentences later: > In recent years, however, security researchers have demonstrated that it is possible to fool many, if not most, forms of biometric identification.

I've personally never considered them secure because of stuff like the gummi bear hack [0] popping up semi-regularly [1]. That they say "in recent years" researchers have demonstrated ways to fool them tells me these occurrences are less well-known than I thought.

[0] https://www.theregister.co.uk/2002/05/16/gummi_bears_defeat_...

[1] https://whatis.techtarget.com/definition/gummy-bear-hack

Re: Researchers Created Fake 'Master' Fingerprints to Unlock Smartphones

#65
post #21

Earlier quoted context omitted.

I believe everybody knows fingerprints or face are not a perfect solution for unlocking mobile phones, but so far they seem to be the best option currently available (taking into account the ease of shoulder surfing and inconvenience of entering secure passwords on small screen).

I'm not going to dispute shoulder surfing is a big problem for unlock patterns, but if you do not care about that attack vector patterns are super efficient and freakingly hard to brute-froce. Considering about 400k combinations [1] on a 3x3 board with a 30sec lockdown every 5 tries it will take on average about 14 days to unlock (given that the pattern is random enough). The average 4 digit pin is doable in about 8…

> Considering about 400k combinations [1] on a 3x3 board with a 30sec lockdown every 5 tries it will take on average about 14 days to unlock (given that the pattern is random enough).

Not very imaginative. One of my brother's friends got into my brother's phone on the very first try by holding it up to a light and looking at the smudge pattern on the screen. A tapped-out 4-digit PIN would at least stop this method from working so easily.

Re: Researchers Created Fake 'Master' Fingerprints to Unlock Smartphones

#66

Really interesting work. Snippet from the paper's summary for the lazy: > The proposed method [...] is based on training a Generative Adversarial Network on a set of real fingerprint images. Stochastic search [...] is then used to search for latent input variables to the generator network that can maximize the number of impostor matches as assessed by a fingerprint recognizer. So I hadn't heard about "MasterPrints";…

Presumably an eigen-face acts as a master-face of sorts?

I’m going to save eigen-face as a pocket insult the next time I need to call someone generic-looking.

Re: Researchers Created Fake 'Master' Fingerprints to Unlock Smartphones

#67

Really interesting work. Snippet from the paper's summary for the lazy: > The proposed method [...] is based on training a Generative Adversarial Network on a set of real fingerprint images. Stochastic search [...] is then used to search for latent input variables to the generator network that can maximize the number of impostor matches as assessed by a fingerprint recognizer. So I hadn't heard about "MasterPrints";…

I imagine to make it to the real world you only need a 3d printer (that can print at sufficiently high density) using a gel substance. After that you can simply lick it and apply.

Re: Researchers Created Fake 'Master' Fingerprints to Unlock Smartphones

#68
post #45

I'm fine with "casual" security like my fingerprints for my phone and laptop as primary authentication. It annoys me I have to enter a password first from a user experience perspective. There's definitely need for very hardened phones from physical attack (journalists, canaries, whistleblowers, etc). I'm just not that important so I wish I could choose my security level.

It's still very important to know that these owls aren't necessarily what they seem. People will hear the phrase "fingerprint recognition" and think "Oh that's clever because I'm the only one with these fingerprints!" and assume that that makes it secure. But of course the reality is more complicated than that, and personally I prefer a passphrase because I understand much better how that works and what the potential…

Exactly, actually. My point being that swiping my fingerprints is a big enough pain in the butt for relatively low value of return, and it doesn't scale across users.

Re: Researchers Created Fake 'Master' Fingerprints to Unlock Smartphones

#69
post #3

i wonder if you can just chop up 50 fingerprints an feed them to https://github.com/mxgmn/WaveFunctionCollapse

That's pretty amazing, though the fact that fingerprints are much less symmetrical would be an issue for how it works, so my guess is no.
Post reply on HN