Live data from Hacker News

Fingerprints can be hacked

blog.kraken.com

121–130 of 333 posts

Re: Fingerprints can be hacked

#121

Earlier quoted context omitted.

I would argue that the devices you carry with you are exactly the ones you shouldn’t use biometrics for. Law enforcement can force you to use biometrics to unlock a phone. They have used dead bodies to unlock phones.[0] What they can’t do is make you remember a code/password which you have “forgotten.” [0] https://www.forbes.com/sites/thomasbrewster/2018/03/22/yes-c...

The vast majority people will never encounter a circumstance where that will be an issue. To withhold a (n optional) feature from the masses based on the hypothetical actions of an agency who can abuse your fingerprints but will stop short of torture doesn't really make sense.

HN, and the tech bubble at large, is all about "edge-cases." Too many Debbie Downers getting off on playing "what if" scenarios, while ignoring reality.

Re: Fingerprints can be hacked

#124
post #59

Earlier quoted context omitted.

Maybe at some point in the future, but we definitely aren't at the stage of being able to parse out a specific password from an FMRI reading right now.

No, but combined with torture it might be effective enough.

For some, being placed in the MRI would be torture. Hope you don't have a plate in your head or other bodily location. Would torturers be so concerned with this, or is that just part of the threat.

TLA person: Give us the code or we put you the MRI machine!!

Victim: Can't you just use a $5 wrench instead?

Re: Fingerprints can be hacked

#125
post #91

Earlier quoted context omitted.

State driver license in USA is a honey pot of thumb/finger scans. Anyone on HN think the NSA doesn't have access? NSA info sharing with trusted foreign countries makes a reliable distributed backup for use by foreign spooks.

> State driver license in USA In which states? The only thing I have been fingerprinted for is in the US is The Global Entry program.

If your argument is that the NSA doesn't have your fingerprint because only the Global Entry Program has your fingerprint, I find that highly suspect. Of all the databases to be shared with the CIA and the NSA, Global Entry seems entirely reasonable that they be given access. Unlike state's driver license database where it's objectionable that the NSA be allowed to access it, Global Entry has to do with people coming in and out of the country and so seems entirely reasonable the NSA would have access, never mind the fine print no one reads when signing up for the program. I wouldn't be surprised if any of the three programs (Global Entry, TSA Pre, Clear) have it in their fine print that the CIA is legally given access to that database.

Re: Fingerprints can be hacked

#126
post #29
post #2

My favorite photograph of a fingerprint is when the Chaos Computer Club reproduced the German Foreign ministers fingerprint from a photo. So much for military grade security. https://www.dw.com/en/german-defense-minister-von-der-leyens... - The core problems with biometrics are that: 1) Not revokable (unlike compromised credentials) 2) Not a secret 3) Usually trivial to reproduce and spoof (even "liveliness" tests)

The title almost sounds like that they have a meaningful fingerprint ready to open her iPhone... Was that the case? Or do they have a somewhat accurate partial fingerprint? I failed to find recoding of the presentation.

AFAIK iOS actually uses the pattern of veins below the fingertip rather than an image of the fingerprint itself. So I can't imagine this would be enough to unlock an iPhone.

Re: Fingerprints can be hacked

#127
post #91

Earlier quoted context omitted.

> State driver license in USA In which states? The only thing I have been fingerprinted for is in the US is The Global Entry program.

More and more states require fingerprints for driver licenses because of the RealID program. Eventually (soonish) you won't be able to use your driver license to fly without it being RealID compliant. One state I lived in gave me the option of not having a RealID-compliant license if I wanted to. Another didn't, so fingerprints were compulsory.

heads up that the RealID deadline got pushed back to May 3, 2023

Re: Fingerprints can be hacked

#128
post #117

Earlier quoted context omitted.

> That's the entire point. It's a piece of information that even when it's known by everyone still can't be reproduced. And yet, it can be reproduced. So it seems like the entire point is... invalid.

Produce me a living breathing human with a chosen fingerprint -- biometrics are not "a picture of your fingerprint is the password."

But similar to hash collisions, a total break (arbitrary hash values can be output) isn't required for it to be a problem. Where fingerprint scanners aren't magic (especially given the sloppiness of input data), that they're defeatable in corner cases should be enough to be worrisome.

Re: Fingerprints can be hacked

#130
post #107

Earlier quoted context omitted.

This meme really really has to die. It's so annoying that it's spread so far. Biometric security (i.e something you are) does not need to be secret nor revoked. That's the entire point . It's a piece of information that even when it's known by everyone still can't be reproduced. The strength of a security system based on biometrics is exactly how well that system can detect that it's reading from an living breathing…

> Perfect: A human guard manually taking a fingerprint reading. Can't be beat because the guard can obviously see that it's not really your hand. Well, the argument some people are making is that this might be no better than a human checking your ID. Yes, there the guard can verify that there is some real human there, but both the ID and the fingerprint could be faked (e.g. a fake fingertip mold which matches the vic…

[deleted]
Post reply on HN