Live data from Hacker News

Fingerprints can be hacked

blog.kraken.com

61–70 of 333 posts

Re: Fingerprints can be hacked

#61
post #5

Earlier quoted context omitted.

That's why this is a dumb idea, merchants can just use the replay attack: https://www.wsj.com/articles/in-china-paying-with-your-face-... . The only place where you should be using your biometrics is to unlock devices you carry with you, like the iPhone.

I would argue that the devices you carry with you are exactly the ones you shouldn’t use biometrics for. Law enforcement can force you to use biometrics to unlock a phone. They have used dead bodies to unlock phones.[0] What they can’t do is make you remember a code/password which you have “forgotten.” [0] https://www.forbes.com/sites/thomasbrewster/2018/03/22/yes-c...

> What they can’t do is make you remember a code/password which you have “forgotten.”

But they can lock you up for not supplying it.

Re: Fingerprints can be hacked

#62

Also remember, in the USA, the police can legally force your finger onto a reader to defeat the lock, without violating your 5th Amendment right against self-incrimination.

Remember (on an iPhone) you can squeeze the power button and one of the volume keys for a few seconds. This disables biometric authentication until a passcode is entered.

This can protect you against this "attack vector".

Re: Fingerprints can be hacked

#63

Biometrics are great for authentication but terrible for authorization. Anything sensitive should require both. There's nothing wrong with a fingerprint and a password or a fingerprint and an RFID card as an authorization/authentication pair; you just have to keep these things in mind. I've fallen to the laziness of using fingerprints on my devices as well, but they still require a password to decrypt the contents of…

> Biometrics are great for authentication but terrible for authorization

What does that mean? Unlocking your MacBook gives access to your RSA keys and all is lost.

Re: Fingerprints can be hacked

#64
post #2

My favorite photograph of a fingerprint is when the Chaos Computer Club reproduced the German Foreign ministers fingerprint from a photo. So much for military grade security. https://www.dw.com/en/german-defense-minister-von-der-leyens... - The core problems with biometrics are that: 1) Not revokable (unlike compromised credentials) 2) Not a secret 3) Usually trivial to reproduce and spoof (even "liveliness" tests)

> Spiegel also reported another security hole from the conference: reading a user's PIN code from reflections in their pupils while taking selfies. https://www.dw.com/en/german-defense-minister-von-der-leyens...

I don't understand this one - when are people taking a selfie at the same time they're typing in their pin? I have an android phone, and I don't even unlock to take pictures.

I just don't follow the timeline and geometry. Seems theoretical only maybe.

Re: Fingerprints can be hacked

#65

Biometrics are great for authentication but terrible for authorization. Anything sensitive should require both. There's nothing wrong with a fingerprint and a password or a fingerprint and an RFID card as an authorization/authentication pair; you just have to keep these things in mind. I've fallen to the laziness of using fingerprints on my devices as well, but they still require a password to decrypt the contents of…

"Authentication is the act of proving an assertion, such as the identity of a computer system user. In contrast with identification, the act of indicating a person or thing's identity, authentication is the process of verifying that identity." (https://en.wikipedia.org/wiki/Authentication)

So it's not useful for authentication but could be used for identification.

Re: Fingerprints can be hacked

#66
post #59

Earlier quoted context omitted.

> What they can’t do is make you remember a code/password which you have “forgotten.” They might be able to with an FMRI machine.

Maybe at some point in the future, but we definitely aren't at the stage of being able to parse out a specific password from an FMRI reading right now.

No, but combined with torture it might be effective enough.

Re: Fingerprints can be hacked

#67
post #49

No, the fingerprints are not hacked. The MacBook Pro scanner is. Fingerprints and biometrics in general are not a secret. Consider your fingerprint like your face. Anyone can reproduce your face, there are cameras everywhere, and it is probably already easy to find on the internet. "Hacking" your face by taking a picture is the most boring "hack" ever. Now, if I print your face on a piece of paper, wear it as a mask…

Eh... fingerprints are quite a bit simpler than faces. They're just patterns. I don't know how you could detect a fake fingerprint. You'd need something that could tell there wasn't real skin on the device. I would say warmth but obviously he has the fake skin over his actual thumb so it's probably still warm.

Re: Fingerprints can be hacked

#68
By "laser printer" do they mean regular office printer or laser engraver? It's a bit hard to believe that the super thin layer of black paint produces an imprint thats significant enough for this to work.

Re: Fingerprints can be hacked

#69
post #64

Earlier quoted context omitted.

> Spiegel also reported another security hole from the conference: reading a user's PIN code from reflections in their pupils while taking selfies. https://www.dw.com/en/german-defense-minister-von-der-leyens...

I don't understand this one - when are people taking a selfie at the same time they're typing in their pin? I have an android phone, and I don't even unlock to take pictures. I just don't follow the timeline and geometry. Seems theoretical only maybe.

Take a selfie with someone unlocking their phone positioned over your shoulder. Seems very practical and surreptitious.

Re: Fingerprints can be hacked

#70
post #35

Earlier quoted context omitted.

I believe it's - Something you have (key, device,...) - Something you know - Something you are (biometry) In Europe there is a regulation (PSD2) that defines a strong authentication as 2 of the 3 listed above.

I've always disliked this breakdown. My body is something I have -- it's just potentially (not always practically -- see the article) more difficult to clone or otherwise use without my consent than a key fob or something. Edit: To be clear, I don't think this is an argument for biometrics, but rather an argument against them. They can't complement something I have in a two factor scheme, because my biometrics are so…

But it's the parts that are easily forgeable (fingerprints, retinas, etc) that are being relied upon. By "forgeable" I mean "things that someone else can also have by creating copies."

I don't think we have yet good metrics on how to detect specific individuals using a full-body scan. Not to mention the invasiveness of creating your personal initial dataset. Most folks won't stand for it. So right back to parts that are forgeable...

Post reply on HN