Live data from Hacker News

Fingerprints can be hacked

blog.kraken.com

81–90 of 333 posts

Re: Fingerprints can be hacked

#81
post #25
post #2

My favorite photograph of a fingerprint is when the Chaos Computer Club reproduced the German Foreign ministers fingerprint from a photo. So much for military grade security. https://www.dw.com/en/german-defense-minister-von-der-leyens... - The core problems with biometrics are that: 1) Not revokable (unlike compromised credentials) 2) Not a secret 3) Usually trivial to reproduce and spoof (even "liveliness" tests)

And they distributed it with the Datenschleuder. Cannot remember the issue, but I have it still somewhere at home. It is like a highly distributed backup of that fingerprint.

State driver license in USA is a honey pot of thumb/finger scans. Anyone on HN think the NSA doesn't have access? NSA info sharing with trusted foreign countries makes a reliable distributed backup for use by foreign spooks.

Re: Fingerprints can be hacked

#82

Think this is still overestimating the threat. It's kinda like saying you can hack someone's password by watching video of them typing. True, but also non-trivial. If you're already being personally targeted by an organization professional enough to follow you around, take a photo of your fingerprint on something you touched, then painstakingly reproduce said fingerprint through highly technical means and then gain p…

Agree with your overall post entirely, the thing about physical attacks is they don't scale well. If you're subject to an actual individual threat, it's a whole different and enormously scarier/more challenging threat scenario.

>Think this is still overestimating the threat. It's kinda like saying you can hack someone's password by watching video of them typing. True, but also non-trivial.

Isn't that genuinely getting pretty trivial in public though? And in turn I think that is a real argument for biometrics too. The amount of over-the-shoulder camera surveillance in business and urban areas is pretty scary at this point, as are the concealability and cheapness of even very tiny spy cams. There have been plenty of scandals around it even in things like AirBNBs or hotels, historically from the context of sex, but not a stretch to imagine that passwords could be a much bigger and more lucrative target. And ML/AI is getting ever more sophisticated, and humans entering PINs/passwords is pretty repetitive behavior with a high degree of uniformity in how it's done, at least the device-unlock level. Seems very amenable to highly reliable automated analysis, to the extent I'd be genuinely surprised if that's not secretly deployed already in surveillance states.

I don't enter PINs/passwords in public anymore if I can possibly help it. It just seems scalable in a way that physical attacks aren't.

Re: Fingerprints can be hacked

#83
post #41

The uniqueness of fingerprints is also questionable. e.g.: https://mathblog.com/are-fingerprints-unique/

One thing that's never been explained to me is how large the space is. Does everyone have one big swirl on their thumb that goes clockwise or counter-clockwise? Could you have two swirls? What is the space of potential fingerprints?

Re: Fingerprints can be hacked

#84

The broader argument here is less about fingerprints, and more about using anything immutable as authentication. You cannot change your fingerprints. You cannot change your social security number (at least not easily). These should therefore, NEVER be a primary method to authorize access to anything. Once stolen, the proverbial horse is out of the barn.

It would be funny to use this technique to make fake fingerprints that are used as the keys. “Hardware key on MBP!”

Re: Fingerprints can be hacked

#85
post #3

Fingerprints are usernames, not passwords. Here is an excellent (and timeless) post on this fact: https://blog.dustinkirkland.com/2013/10/fingerprints-are-use...

Secrecy is only an approximation of difficulty. Given the difficulty, I would estimate it as a two character password. It should be fine for people who have nothing to hide.

> Given the difficulty, I would estimate it as a two character password.

Sorry, but that is _way_ off.

I can run through 2 character passwords by hand in a few hours at most, likely faster. (Assuming a qwerty keyboard, 62 alphanumeric, plus roughly 33 other characters makes for 9025 possible passwords.)

To reproduce a fingerprint requires access, money, time, and expertise. It's not _hard_ but it is not trivial either. You need access to a good fingerprint. You need the money to buy the supplies (a laser printer, some acetate, and some wood glue). You need time to both capture the fingerprint, refine it in the photo editor of you choice, and then actually turn it into something that scans. And you need to know that this is all actually doable. And then that all assumes that it actually works; I can assure you this is not a 100% success rate.

Put another way, if you told me you _personally_ had a two character password on a specific account, I could likely log into it _today_. Conversely, if you told me it also required a fingerprint to log into, I'd be out of luck. I'd have to learn who you are, where you lived, and then concoct a way to capture a clean print.

As others have pointed out, biometrics != password. It's an apples to oranges comparison.

Re: Fingerprints can be hacked

#86
[edit for clarity]

As someone who doesn’t specialize in security, one claim that has stood out to me for not using fingerprints is that you can't run bcrypt (or some other salting algorithm) on fingerprints [1].

I don’t see any discussion of that here thus far. Is that still the case? I feel like I would have heard about developments in this area if something had changed. But perhaps I've always misunderstood the criticism?

[1] https://www.rsaweb.co.za/fingerprint-security-fingerprints-a...

Re: Fingerprints can be hacked

#87

Biometrics are not secrets (it must be assumed that attackers always possess all biometric data), but they can nevertheless be a good form of authentication when combined with situational awareness . If you try to use one of these hot glued fingerprints in front of a security guard, it isn't going to go well for you. At the moment, humans are still necessary for situational awareness, but probably machines can get th…

I bet you could make one that looks like part of your skin pretty easily.

Re: Fingerprints can be hacked

#88
post #2

My favorite photograph of a fingerprint is when the Chaos Computer Club reproduced the German Foreign ministers fingerprint from a photo. So much for military grade security. https://www.dw.com/en/german-defense-minister-von-der-leyens... - The core problems with biometrics are that: 1) Not revokable (unlike compromised credentials) 2) Not a secret 3) Usually trivial to reproduce and spoof (even "liveliness" tests)

I’m waiting on a court case with a fingerprint as key evidence for conviction, in which the defendant brings this up. Might not pass reasonable doubt muster, but what if somebody sold fingerprint forgery kits online that made it push-button simple? Just supply an image or two, run it through some ML to reconstruct the print, laser etch a latex glove or similar… I wonder if you could use CRISPR or “lab-grown meat” tec…

From the linked article, it sounds like that already exists in some form.

> Using several close-range photos in order to capture every angle, Krissler used a commercially available software called VeriFinger to create an image of the minister's fingerprint.

Re: Fingerprints can be hacked

#89
post #2

My favorite photograph of a fingerprint is when the Chaos Computer Club reproduced the German Foreign ministers fingerprint from a photo. So much for military grade security. https://www.dw.com/en/german-defense-minister-von-der-leyens... - The core problems with biometrics are that: 1) Not revokable (unlike compromised credentials) 2) Not a secret 3) Usually trivial to reproduce and spoof (even "liveliness" tests)

The video from the conference, in German:

https://media.ccc.de/v/31c3_-_6450_-_de_-_saal_1_-_201412272...

Post reply on HN