Live data from Hacker News

Fingerprints can be hacked

blog.kraken.com

71–80 of 333 posts

Re: Fingerprints can be hacked

#71
post #64

Earlier quoted context omitted.

> Spiegel also reported another security hole from the conference: reading a user's PIN code from reflections in their pupils while taking selfies. https://www.dw.com/en/german-defense-minister-von-der-leyens...

I don't understand this one - when are people taking a selfie at the same time they're typing in their pin? I have an android phone, and I don't even unlock to take pictures. I just don't follow the timeline and geometry. Seems theoretical only maybe.

Reflections of the fingerprint marks on the screen that are usually present for those who don't regularly wipe their screen off?

Re: Fingerprints can be hacked

#72
post #18

in biometrics this is called a Presentation Attack (PA), here the fake fingerprint is the analog of presenting a photograph, video or 3dp mask to a face recognition system. this is usually mitigated by the use of Presentation Attack Detection (PAD) systems, either hardware, software or hybrid. in this particular case it can easily be mitigated by some hardware that measures the amount of water in the biometric sample…

[deleted]

Re: Fingerprints can be hacked

#74
post #64

Earlier quoted context omitted.

> Spiegel also reported another security hole from the conference: reading a user's PIN code from reflections in their pupils while taking selfies. https://www.dw.com/en/german-defense-minister-von-der-leyens...

I don't understand this one - when are people taking a selfie at the same time they're typing in their pin? I have an android phone, and I don't even unlock to take pictures. I just don't follow the timeline and geometry. Seems theoretical only maybe.

It's badly worded in the article but I think it means person A is entering his pin. Persons B, C, D, etc. take selfies in the vicinity of person A. By comparing multiple selfies from sightly different times, you can determine person A's pin.

Re: Fingerprints can be hacked

#75

Biometrics are great for authentication but terrible for authorization. Anything sensitive should require both. There's nothing wrong with a fingerprint and a password or a fingerprint and an RFID card as an authorization/authentication pair; you just have to keep these things in mind. I've fallen to the laziness of using fingerprints on my devices as well, but they still require a password to decrypt the contents of…

> Biometrics are great for authentication but terrible for authorization What does that mean? Unlocking your MacBook gives access to your RSA keys and all is lost.

As the other commenter pointed out, he probably meant "great for identification but terrible for authentication".

Re: Fingerprints can be hacked

#77

Biometrics are great for authentication but terrible for authorization. Anything sensitive should require both. There's nothing wrong with a fingerprint and a password or a fingerprint and an RFID card as an authorization/authentication pair; you just have to keep these things in mind. I've fallen to the laziness of using fingerprints on my devices as well, but they still require a password to decrypt the contents of…

This doesn't make sense to me. In what use-cases do we use our personal computers authenticated but also unauthorized?

Re: Fingerprints can be hacked

#78
post #3

Fingerprints are usernames, not passwords. Here is an excellent (and timeless) post on this fact: https://blog.dustinkirkland.com/2013/10/fingerprints-are-use...

>Fingerprints are usernames, not passwords. Here is an excellent (and timeless) post on this fact

No, that is complete absolute shit post that isn't even self coherent. Like, it literally whines about needing something that can be "independently chosen, changed, and rotated", which obviously describes usernames so obviously biometrics can't possibly be usernames by that very post! Why is this dumb meme so fucking persistent? Fingerprints are one of many biometrics. They aren't usernames, which aren't an authentication factor at all. They aren't passwords. They aren't tokens. They are their own thing. They have their own pluses and minuses as part of a comprehensive response to a given threat scenario. That's it. Trying to shoehorn them into something else is the same as trying to shoehorn everything into a car analogy.

All security exists solely in the context of an equation of threat scenario (the word "threat" doesn't even appear in that post), defender vs attacker resources and the value of what is being defended. Real security must work for actual real humans too. For example, rotating passwords every day/week/month is "secure" except that it's also a huge PITA or even outright impossible for many humans and defending against what should be a non-existent threat scenario anyway. So the obvious and inevitable result is that everyone starts to use crappy passwords, write them all down on sticky notes and text files and such everywhere, or both. That is not the fault of the users, it's the fault of a shitty system.

Another word that doesn't appear in that post? "Camera". Biometrics is an enormously rich potential field, fingerprints are about the worst lowest hanging fruit and in no way represent everything particularly as we use more and more wearables (there are bits of entropy to be found in your body's cardiac cycle for example). But even for fingerprints, which is really lower resource for attackers: getting a reproducing a fingerprint, or having AI go through every single networked look-down camera for the obvious obvious pattern of a human pulling out a slab of screen and then entering a PIN or passcode into it then recording that? Are people expected to never ever unlock a device anywhere but a physically secure area? Because see above, that is not realistic for real humans and thus a worthless security response.

As is usually the case, the best answer is hybrid, with multiple levels of factor usage to try to combine the strengths of each. And indeed that is the way things are going.

Edit to add: And if I sound irritated about this I am. This is the same kind of user hostile shallow anti-security thinking that brought us things like "security" questions, password rotation policies, lengthy and baroque "must contain 2 caps 1 number 3 special characters but not those special characters and cannot START with a number" password policies, etc. All of which add aggravation and failure points to no good end. Bad security practices affect our entire industry to the detriment of us all, but "bad security" isn't just a technical thing it's a human UX thing.

Re: Fingerprints can be hacked

#79

Using same idea, could’t AI generate FaceId from videos?

Sounds likely. When you train FaceID you are filmed. What's to stop someone from using film of you giving a speech?

At best the biometric locks are like locks on your house. Stops most people but not someone really determined.

Re: Fingerprints can be hacked

#80
post #78
post #3

Fingerprints are usernames, not passwords. Here is an excellent (and timeless) post on this fact: https://blog.dustinkirkland.com/2013/10/fingerprints-are-use...

> Fingerprints are usernames, not passwords. Here is an excellent (and timeless) post on this fact No, that is complete absolute shit post that isn't even self coherent. Like, it literally whines about needing something that can be "independently chosen, changed, and rotated", which obviously describes usernames so obviously biometrics can't possibly be usernames by that very post! Why is this dumb meme so fucking pe…

[deleted]
Post reply on HN