Live data from Hacker News

Fingerprints can be hacked

blog.kraken.com

181–190 of 333 posts

Re: Fingerprints can be hacked

#181
post #107

Earlier quoted context omitted.

This meme really really has to die. It's so annoying that it's spread so far. Biometric security (i.e something you are) does not need to be secret nor revoked. That's the entire point . It's a piece of information that even when it's known by everyone still can't be reproduced. The strength of a security system based on biometrics is exactly how well that system can detect that it's reading from an living breathing…

> Biometric security (i.e something you are) does not need to be secret nor revoked. That's the entire point. It's a piece of information that even when it's known by everyone still can't be reproduced. If that's the point, the effort is doomed. All biometrics will be able to be reproduced sooner or later. There's no way around that. So, like all other identifiers, revocation is an important trait. Even if successful…

Furthermore, that guard can be incapacitated, or easier still, bribed.

Re: Fingerprints can be hacked

#182

The broader argument here is less about fingerprints, and more about using anything immutable as authentication. You cannot change your fingerprints. You cannot change your social security number (at least not easily). These should therefore, NEVER be a primary method to authorize access to anything. Once stolen, the proverbial horse is out of the barn.

You can in fact change your fingerprints; glassblowing and metalwork, for example, offer numerous opportunities to do so.

Re: Fingerprints can be hacked

#183
> while your fingerprint is unique to you,

Has this been proven to some degree or is it merely a conjecture.

I suppose by now, governments have collected enough fingerprints to pretty much confirm this, but I haven’t seen any studies.

Re: Fingerprints can be hacked

#184

Earlier quoted context omitted.

Most of the evidence that shows up at a court case is forgeable. Simply showing that a particular piece of evidence could be forged in no way proves that it is forged. You would need some sort of argument to prove your contention.

All evidence is ultimately forgeable. At some point a modern day Godel could prove that “justice” in a free society is mathematically impossible. The law has to operate within a practical compromise and err heavily on the side of reducing false convictions.

Or err heavily on reducing the release of the guilty, depending on the region.

Re: Fingerprints can be hacked

#185

Earlier quoted context omitted.

I’m waiting on a court case with a fingerprint as key evidence for conviction, in which the defendant brings this up. Might not pass reasonable doubt muster, but what if somebody sold fingerprint forgery kits online that made it push-button simple? Just supply an image or two, run it through some ML to reconstruct the print, laser etch a latex glove or similar… I wonder if you could use CRISPR or “lab-grown meat” tec…

Fingerprint recognition has been mainstream in consumer tech/iPhones for 8 years. Surely it would have already happened?

Sure. No one has ever faked a fingerprint to access phone of the partner or used a printout to trick facial recognition to see the latest mails. Today even little Kids fake fingerprints of their parents to buy some microtransactions.

Re: Fingerprints can be hacked

#186
post #157

Earlier quoted context omitted.

Pin/password can also be hacked and there is no need for fancy 3D printer. Someone can use their smartphone to film other person as they type stuff in, no need for printing fake print. They can steal phone/laptop as soon as they are done filming. This is the case that fingerprint sensors are preventing. Pointing out problems is useless - as people don't have alternative that would be "all-mighty secure without flaws"…

> This is the case that fingerprint sensors are preventing. They aren't. Your parent post already mentioned that they were extracted by filming. Passwords don't have the other 2 problems, and I'm not really sure what is gained by not talking about them.

For fingerprint it is "using several close-range photos in order to capture every angle" - to get PIN, I need one angle and probably not even close-range of video and even weird angle if I have to sneak up onto someone in a metro or in a coffee shop.

Re: Fingerprints can be hacked

#187
post #107

Earlier quoted context omitted.

This meme really really has to die. It's so annoying that it's spread so far. Biometric security (i.e something you are) does not need to be secret nor revoked. That's the entire point . It's a piece of information that even when it's known by everyone still can't be reproduced. The strength of a security system based on biometrics is exactly how well that system can detect that it's reading from an living breathing…

> Biometric security (i.e something you are) does not need to be secret nor revoked. That's the entire point. It's a piece of information that even when it's known by everyone still can't be reproduced. If that's the point, the effort is doomed. All biometrics will be able to be reproduced sooner or later. There's no way around that. So, like all other identifiers, revocation is an important trait. Even if successful…

> If that's the point, the effort is doomed. All biometrics will be able to be reproduced sooner or later. There's no way around that.

All encryption will eventually be broken therefore what’s the point is a pretty bad security posture. But like no it won’t. Even if you can fake every other metric (good luck with eyes) a fresh blood sample taken by a guard with hypothetical futuristic instant DNA sequencing will never be broken. If your threat model is someone cloning you, the you have bigger problems and they still can’t clone your fingerprints!

You’ve got revocation completely ass-backwards. If someone successfully tricks a biometric system you don’t need to revoke someone’s fingerprint, you revoke the reader! That’s the thing that actually provides all the security.

The point of the guard is that a human has absolutely no trouble determining whether they’re taking a reading of a real hand, scanning a real eyeball, to taking a real blood sample. Maybe in mission impossible movies but you’re really really overstating the resources required to make a convincing hand to someone specifically looking for fakes. Yes social engineering is a problem which is why an autonomous system with the detection quality of a human would be nigh unbeatable.

Re: Fingerprints can be hacked

#188

Earlier quoted context omitted.

How the heck did they get the fingerprint from that? Is there actually tech to enhance blurry images like that?

iirc they had a waiter as a conspirator serving that guy at a banquet

There were (at least) two such "stunts" in the past involving German ministers:

In 2008. "fingerprint of then interior minister and current Finance Minister Wolfgang Schäuble" was sourced from a glass:

https://freerepublic.com/focus/f-news/1995935/posts

In 2014. "A speaker at the yearly conference of the Chaos Computer Club has shown how fingerprints can be faked using only a few photographs. To demonstrate, he copied the thumbprint of the German defense minister" Ursula von der Leyen

https://m.dw.com/en/german-defense-minister-von-der-leyens-f...

Re: Fingerprints can be hacked

#189
post #95

Earlier quoted context omitted.

No, I think that adding torture to the mix will make the FMRI results even less readable

What I was thinking was using FMRI to find out if they actually do remember the password (FMRI lie detection really only works with yes/no questions, AFAIK). If they don't know, then torture is a waste of time. If they do know, then you know torture may be fruitful.

FMRI uses indicators like pulse, heartrate, etc. to make a more or less estimate on the truthfulness. Torture can make these indicators useless. Torture is a very flawed method to extract informations. You can't be sure that the victim isn't telling lies or admits to crimes just to make the torture stop.

Re: Fingerprints can be hacked

#190
post #186

Earlier quoted context omitted.

> This is the case that fingerprint sensors are preventing. They aren't. Your parent post already mentioned that they were extracted by filming. Passwords don't have the other 2 problems, and I'm not really sure what is gained by not talking about them.

For fingerprint it is "using several close-range photos in order to capture every angle" - to get PIN, I need one angle and probably not even close-range of video and even weird angle if I have to sneak up onto someone in a metro or in a coffee shop.

well, TFA used one photo...
Post reply on HN