Live data from Hacker News

Fingerprints can be hacked

blog.kraken.com

11–20 of 333 posts

Re: Fingerprints can be hacked

#11
post #3

Fingerprints are usernames, not passwords. Here is an excellent (and timeless) post on this fact: https://blog.dustinkirkland.com/2013/10/fingerprints-are-use...

I always thought that since the beginning, but unfortunately the world went into another direction. People always said "something you have and something you know", but now for most cases it's just "something you have - your body". Obviously if in the future remote mind-readers are invented, the "something you know" part will also get obsolete, but for now we should stick to it.

I believe it's - Something you have (key, device,...) - Something you know - Something you are (biometry)

In Europe there is a regulation (PSD2) that defines a strong authentication as 2 of the 3 listed above.

Re: Fingerprints can be hacked

#12
post #3

Fingerprints are usernames, not passwords. Here is an excellent (and timeless) post on this fact: https://blog.dustinkirkland.com/2013/10/fingerprints-are-use...

Secrecy is only an approximation of difficulty. Given the difficulty, I would estimate it as a two character password. It should be fine for people who have nothing to hide.

Re: Fingerprints can be hacked

#13
Biometrics are not secrets (it must be assumed that attackers always possess all biometric data), but they can nevertheless be a good form of authentication when combined with situational awareness. If you try to use one of these hot glued fingerprints in front of a security guard, it isn't going to go well for you.

At the moment, humans are still necessary for situational awareness, but probably machines can get there pretty soon. A phone, for example, that monitors its surroundings continuously and has enough intelligence to reliably distinguish normal access by its owner from duress or the presentation of fake biometrics seems like it's within reach of current technology (though it doesn't actually exist).

Re: Fingerprints can be hacked

#16
post #9
post #6

Do you think that a 3d printer can replace the whole process ?

It probably lacks the resolution to do it. That said, why do you want that when a 2d printer works fine?

Only optical scanners would be fooled, capacitive and ultrasonic readers actually read the 3D ridges of your finger.

Re: Fingerprints can be hacked

#17
post #5
post #2

My favorite photograph of a fingerprint is when the Chaos Computer Club reproduced the German Foreign ministers fingerprint from a photo. So much for military grade security. https://www.dw.com/en/german-defense-minister-von-der-leyens... - The core problems with biometrics are that: 1) Not revokable (unlike compromised credentials) 2) Not a secret 3) Usually trivial to reproduce and spoof (even "liveliness" tests)

That's why this is a dumb idea, merchants can just use the replay attack: https://www.wsj.com/articles/in-china-paying-with-your-face-... . The only place where you should be using your biometrics is to unlock devices you carry with you, like the iPhone.

until you fall asleep with your phone on you.

Re: Fingerprints can be hacked

#18
in biometrics this is called a Presentation Attack (PA), here the fake fingerprint is the analog of presenting a photograph, video or 3dp mask to a face recognition system. this is usually mitigated by the use of Presentation Attack Detection (PAD) systems, either hardware, software or hybrid. in this particular case it can easily be mitigated by some hardware that measures the amount of water in the biometric sample, for instance capacitive sensor, transparent conductive electrodes or maybe even better some optical sensor that is sensitive to SWIR wavelengths reflectivity differences (1000 and 1200 nm would be great here). a short scholar search will indeed reveal that this is a very active area of research, and probably will reveal tens of papers from our group which is a leader in this.

Re: Fingerprints can be hacked

#19
post #5
post #2

My favorite photograph of a fingerprint is when the Chaos Computer Club reproduced the German Foreign ministers fingerprint from a photo. So much for military grade security. https://www.dw.com/en/german-defense-minister-von-der-leyens... - The core problems with biometrics are that: 1) Not revokable (unlike compromised credentials) 2) Not a secret 3) Usually trivial to reproduce and spoof (even "liveliness" tests)

That's why this is a dumb idea, merchants can just use the replay attack: https://www.wsj.com/articles/in-china-paying-with-your-face-... . The only place where you should be using your biometrics is to unlock devices you carry with you, like the iPhone.

I would argue that the devices you carry with you are exactly the ones you shouldn’t use biometrics for.

Law enforcement can force you to use biometrics to unlock a phone. They have used dead bodies to unlock phones.[0] What they can’t do is make you remember a code/password which you have “forgotten.”

[0] https://www.forbes.com/sites/thomasbrewster/2018/03/22/yes-c...

Re: Fingerprints can be hacked

#20
post #9

Earlier quoted context omitted.

It probably lacks the resolution to do it. That said, why do you want that when a 2d printer works fine?

Only optical scanners would be fooled, capacitive and ultrasonic readers actually read the 3D ridges of your finger.

The 3d ridges from the 2d printer comes from the raised lettering, which is transferred to the dried acetate glue.
Post reply on HN