Live data from Hacker News

Fingerprints can be hacked

blog.kraken.com

171–180 of 333 posts

Re: Fingerprints can be hacked

#171
post #2

My favorite photograph of a fingerprint is when the Chaos Computer Club reproduced the German Foreign ministers fingerprint from a photo. So much for military grade security. https://www.dw.com/en/german-defense-minister-von-der-leyens... - The core problems with biometrics are that: 1) Not revokable (unlike compromised credentials) 2) Not a secret 3) Usually trivial to reproduce and spoof (even "liveliness" tests)

I really like it in Demolition Man, how they thought of a future which used biometrics for secure access (in that case retina scan). But they also saw how easy it was to bypass it when Simon (Wesley Snipes) simply takes the eye of the warden to escape his prison.

I don’t think this was intentional but they managed to demonstrate (or at least for-shadow) the incompetent police force of the future this way.

Re: Fingerprints can be hacked

#172
post #107
post #2

My favorite photograph of a fingerprint is when the Chaos Computer Club reproduced the German Foreign ministers fingerprint from a photo. So much for military grade security. https://www.dw.com/en/german-defense-minister-von-der-leyens... - The core problems with biometrics are that: 1) Not revokable (unlike compromised credentials) 2) Not a secret 3) Usually trivial to reproduce and spoof (even "liveliness" tests)

This meme really really has to die. It's so annoying that it's spread so far. Biometric security (i.e something you are) does not need to be secret nor revoked. That's the entire point . It's a piece of information that even when it's known by everyone still can't be reproduced. The strength of a security system based on biometrics is exactly how well that system can detect that it's reading from an living breathing…

> Biometric security (i.e something you are) does not need to be secret nor revoked. That's the entire point. It's a piece of information that even when it's known by everyone still can't be reproduced.

If that's the point, the effort is doomed. All biometrics will be able to be reproduced sooner or later. There's no way around that.

So, like all other identifiers, revocation is an important trait. Even if successful reproduction is difficult and rare, it would be utterly devastating to those affected unless there's a way to revoke.

> Perfect: A human guard manually taking a fingerprint reading. Can't be beat because the guard can obviously see that it's not really your hand.

Not at all perfect. Can that human guard really see if you're wearing a fake fingerprint? I doubt it, unless he's closely examining everyone's fingerprints first. And even then...

Re: Fingerprints can be hacked

#173

Think this is still overestimating the threat. It's kinda like saying you can hack someone's password by watching video of them typing. True, but also non-trivial. If you're already being personally targeted by an organization professional enough to follow you around, take a photo of your fingerprint on something you touched, then painstakingly reproduce said fingerprint through highly technical means and then gain p…

Yep, physical proximity is a huge barrier to any attack, and requiring persistent physical access even more so. If you have a plug in USB keyboard, this sort of quick attack through MitM passthrough is even easier.

However, having some experience with biometric sensors the False Accept/Reject ratio both for matching the fingerprint and detecting "liveness/spoof" is a BIG DEAL. Matching many prints or to many people is also MUCH HARDER (combinatorically). At high SNR (more expensive, higher resolution, larger sensor, higher power, longer latency) these problems can be largely mitigated with accurate recognition and very difficult to spoof systems. Those aren't the ones people attack for online fame.

However, when display integrated ultra-thin low cost very convenient matching is required... it will trade off for False Accept/Reject ratios and make the system significantly (orders of magnitude) less accurate. Unfortunately, it appears that the old MacBook touchbar integrated sensor has sacrificed significantly in this area.

Time of Flight 3D sensors make spoofing Face ID with easily carried biometrics significantly more challenging (they tend to be head sized).

Re: Fingerprints can be hacked

#174
post #43
post #8

Earlier quoted context omitted.

Even for that it's not safe if anyone can bypass it with a $5 trick. It's definitely a thumb idea

You can unlock most home doors within seconds even without having the key Nonetheless, we still lock our doors and thieves often break in, even though picking the lock is both safer and less likely to arouse suspicion. Your argument makes sense, but we humans aren't really rational

There's a good reason why criminals don't carry lockpicks around and that's because they're regulated, in much of the world mere possession of them outside of your residence is a criminal offence and even in places where you can carry them legally they not only show prior intent, their use in criminal activities carries a charge just like breaking and entering. I'd also argue that being stuck picking a stubborn lock for 2-3 minutes is significantly more suspicion arousing than the literal seconds it takes to break a window but that's neither here nor there.

On the rationality of having locks when criminals can very easily break a window, the old saying that locks keep honest people out rings true. Locks do serve a purpose even if they do very little to slow criminals down. To bring the analogy full circle fingerprint readers always seemed like windows to me in how easy they are to bypass, luckily they're more of a luxury than a necessity. :-)

Re: Fingerprints can be hacked

#175
post #3

Fingerprints are usernames, not passwords. Here is an excellent (and timeless) post on this fact: https://blog.dustinkirkland.com/2013/10/fingerprints-are-use...

Getting an ID card checked by security at the door of a secure establishment allows the people inside that building to know that the holder truly is who they say they are. Inside that space the person has access to confidential information and they do not need security to constantly verify their credentials. ..and yet ID cards can be copied and faked - so why do we do this?

This model is how a fingerprint can be used as a shortcut to deliver certain privileges. The user must first pass security by entering their password, and then later numerous safety triggers are in place to require that password again. Meaning that once a person is validated a stand-in can be suitable rather than fully evaluating each and every time.

Back to fingerprints: copying a fingerprint has numerous barriers that these exploits frequently ignore. First it needs to be the correct finger, it must be clear and complete enough to copy and finally it must be used at a time when the device will accept it. While such barriers may be insufficient for a secure environment, this approach provides more security than, for example, a person repeatedly entering a pincode into their phone through the day - something that is both easily observed and remembered (and worse too if it's a gestural passcode.)

To relegate fingerprints as only this or that throws the baby out with the bathwater - appropriate rules and context can make it a useful security improvement over the status quo. That doesn't mean it's perfect or that it has to be.

Re: Fingerprints can be hacked

#176

Think this is still overestimating the threat. It's kinda like saying you can hack someone's password by watching video of them typing. True, but also non-trivial. If you're already being personally targeted by an organization professional enough to follow you around, take a photo of your fingerprint on something you touched, then painstakingly reproduce said fingerprint through highly technical means and then gain p…

>If you're already being personally targeted by an organization professional enough to follow you around, take a photo of your fingerprint on something you touched, then painstakingly reproduce said fingerprint through highly technical means and then gain physical access to your personal device that uses a fingerprint reader to use said fingerprint, you should be aware of your position and have multi-factor authentic…

[deleted]

Re: Fingerprints can be hacked

#177
post #41

The uniqueness of fingerprints is also questionable. e.g.: https://mathblog.com/are-fingerprints-unique/

One thing that's never been explained to me is how large the space is. Does everyone have one big swirl on their thumb that goes clockwise or counter-clockwise? Could you have two swirls? What is the space of potential fingerprints?

Fingerprint scanners compile a small set of identifying features (typically where ridges end or split). They don't characterize the entire fingerprint. The higher quality the scanning system, the more identifying features they use -- so the size of the search space is both smaller than most people think, and varies depending on the quality of the system.

Re: Fingerprints can be hacked

#178

Earlier quoted context omitted.

> What they can’t do is make you remember a code/password which you have “forgotten.” They might be able to with an FMRI machine.

In the US at least FMRI should fall under fifth amendment, right? Otherwise the fifth amendment would be useless. A right to remain silent wouldn’t exist if you can’t silence your brain. If one day there are stargate replicators that can reach into your mind, would that be legal?

In court, absolutely.

There are still plenty of places where polygraph examinations are used legally.

Re: Fingerprints can be hacked

#179
post #2

My favorite photograph of a fingerprint is when the Chaos Computer Club reproduced the German Foreign ministers fingerprint from a photo. So much for military grade security. https://www.dw.com/en/german-defense-minister-von-der-leyens... - The core problems with biometrics are that: 1) Not revokable (unlike compromised credentials) 2) Not a secret 3) Usually trivial to reproduce and spoof (even "liveliness" tests)

I’m waiting on a court case with a fingerprint as key evidence for conviction, in which the defendant brings this up. Might not pass reasonable doubt muster, but what if somebody sold fingerprint forgery kits online that made it push-button simple? Just supply an image or two, run it through some ML to reconstruct the print, laser etch a latex glove or similar… I wonder if you could use CRISPR or “lab-grown meat” tec…

Why in the world would you need CRISPR or lab grown meat? Just sequence the DNA and send it off to a DNA assembly service. The price is a couple hundred bucks a pop. You don't have to replicate the entire DNA, just the segments used for forensic PCR.

(On a side note, the state of biotechnology and life science knowledge on HN is utterly deplorable, repeating buzz words does not reality make.)

Re: Fingerprints can be hacked

#180
post #78

Earlier quoted context omitted.

> Fingerprints are usernames, not passwords. Here is an excellent (and timeless) post on this fact No, that is complete absolute shit post that isn't even self coherent. Like, it literally whines about needing something that can be "independently chosen, changed, and rotated", which obviously describes usernames so obviously biometrics can't possibly be usernames by that very post! Why is this dumb meme so fucking pe…

> lengthy [...] password policies Bizarrely, my organization limits passwords to a length of 12 characters or shorter. I agree with you, I don't want a password the size of a paragraph, but c'mon... 12 characters?

I think you misread me, or I didn't communicate clearly. By "lengthy" I was referring to the policy, not password length. Indeed max password length itself is another common bit of foolishness, for sanity reasons arguably it shouldn't be infinite but ~150 characters should be fine so that if people want to have a long diceware passphrase that's fine. To the extent passwords are used at all it should be exclusively as input to a KDF or adaptive-hash anyway so storage-side it should all be normalized regardless of input length.
Post reply on HN