Fingerprints can be hacked
41–50 of 333 posts
Re: Fingerprints can be hacked
#42Earlier quoted context omitted.
I’m waiting on a court case with a fingerprint as key evidence for conviction, in which the defendant brings this up. Might not pass reasonable doubt muster, but what if somebody sold fingerprint forgery kits online that made it push-button simple? Just supply an image or two, run it through some ML to reconstruct the print, laser etch a latex glove or similar… I wonder if you could use CRISPR or “lab-grown meat” tec…
'what if somebody ...' made SaaS service to upload pictures and overnight ship the fingertip.
Re: Fingerprints can be hacked
#43Earlier quoted context omitted.
That's why this is a dumb idea, merchants can just use the replay attack: https://www.wsj.com/articles/in-china-paying-with-your-face-... . The only place where you should be using your biometrics is to unlock devices you carry with you, like the iPhone.
Even for that it's not safe if anyone can bypass it with a $5 trick. It's definitely a thumb idea
Nonetheless, we still lock our doors and thieves often break in, even though picking the lock is both safer and less likely to arouse suspicion.
Your argument makes sense, but we humans aren't really rational
Re: Fingerprints can be hacked
#44Earlier quoted context omitted.
That's why this is a dumb idea, merchants can just use the replay attack: https://www.wsj.com/articles/in-china-paying-with-your-face-... . The only place where you should be using your biometrics is to unlock devices you carry with you, like the iPhone.
Even for that it's not safe if anyone can bypass it with a $5 trick. It's definitely a thumb idea
Re: Fingerprints can be hacked
#45in biometrics this is called a Presentation Attack (PA), here the fake fingerprint is the analog of presenting a photograph, video or 3dp mask to a face recognition system. this is usually mitigated by the use of Presentation Attack Detection (PAD) systems, either hardware, software or hybrid. in this particular case it can easily be mitigated by some hardware that measures the amount of water in the biometric sample…
And if we're talking about authenticating people in truly secure environments, my gut tells me that adding a couple more factors to even a simple fingerprint reader ought to be more secure and robust than making a super-complicated fingerprint reader and leaving it as the only factor.
Re: Fingerprints can be hacked
#46Re: Fingerprints can be hacked
#47This is why multi-factor authentication is a thing. Generally, pick two: something you have, something you know, or something you are.
If the scanner doesn't like your fingerprint this morning, just use your proximity badge instead, and if someone takes a photo of your fingerprint, it's still useless unless they also know your PIN.
The issue is that a lot of our hardware, particularly phones and laptops, is single-factor authentication. And on top of that, this hardware knows the login to a bunch of other very sensitive material, like your bank accounts.
Re: Fingerprints can be hacked
#48Re: Fingerprints can be hacked
#49Fingerprints and biometrics in general are not a secret. Consider your fingerprint like your face. Anyone can reproduce your face, there are cameras everywhere, and it is probably already easy to find on the internet. "Hacking" your face by taking a picture is the most boring "hack" ever.
Now, if I print your face on a piece of paper, wear it as a mask and try to say to a security guard that I am you, normally, he won't let me in. If he does, the problem is not that I managed to make a paper mask with a picture of you, this will always be possible, the problem is that your guard is stupid and you need a better one.
And if your fingerprint scanner can be fooled by a dab of glue and a laser printer, you probably need a better scanner, something that Apple should be able to do. Smartphone manufacturers like Apple are usually good at bringing fancy tech to the masses, and they could work on defeating these old attacks.
Re: Fingerprints can be hacked
#50Earlier quoted context omitted.
I’m waiting on a court case with a fingerprint as key evidence for conviction, in which the defendant brings this up. Might not pass reasonable doubt muster, but what if somebody sold fingerprint forgery kits online that made it push-button simple? Just supply an image or two, run it through some ML to reconstruct the print, laser etch a latex glove or similar… I wonder if you could use CRISPR or “lab-grown meat” tec…
'what if somebody ...' made SaaS service to upload pictures and overnight ship the fingertip.