Live data from Hacker News

Fingerprints can be hacked

blog.kraken.com

191–200 of 333 posts

Re: Fingerprints can be hacked

#191
post #58

Earlier quoted context omitted.

It would probably cause a huge media storm. Then the politicians would "fix it" by replacing it with face recognition... (suddenly Face/Off is no longer science fiction)

suddenly Face/Off is no longer science fiction Didn't a woman in France already have a face transplant?

I don't think it was the type of transplant Face/Off was depicting, hers was very natural-looking but also visibly not a normal face.

I'd like to see Mission: Impossible type transplants, or even masks like the ones they use, for that matter.

Re: Fingerprints can be hacked

#192
post #112

Earlier quoted context omitted.

I’m waiting on a court case with a fingerprint as key evidence for conviction, in which the defendant brings this up. Might not pass reasonable doubt muster, but what if somebody sold fingerprint forgery kits online that made it push-button simple? Just supply an image or two, run it through some ML to reconstruct the print, laser etch a latex glove or similar… I wonder if you could use CRISPR or “lab-grown meat” tec…

Could work for a digital intrusion, but for crime scenes there is dna

DNA evidence is overrated. People leave their DNA everywhere, so it's not that hard to get some and then plant it somewhere else.

The tests also have varying accuracy rates, but people misunderstand what it means. If the test is 99.99% accurate, that doesn't mean that there is a 99.99% chance that the defendant is the perpetrator. It means that in a region with ten million people, you've whittled your suspect list down to a thousand people. If you pick one of them at random there is only a tenth of a percent chance it was them.

This especially problematic when dealing with "DNA databases" because then with a large database you have a high probability of finding a false positive match and the true perpetrator might not even be in the database.

Re: Fingerprints can be hacked

#194
post #2

My favorite photograph of a fingerprint is when the Chaos Computer Club reproduced the German Foreign ministers fingerprint from a photo. So much for military grade security. https://www.dw.com/en/german-defense-minister-von-der-leyens... - The core problems with biometrics are that: 1) Not revokable (unlike compromised credentials) 2) Not a secret 3) Usually trivial to reproduce and spoof (even "liveliness" tests)

> The core problems with biometrics are that: … is that they're treated as passwords instead of usernames. The three problems you list all have the biometric=password assumption in them. See also using the American SSN usage: it's treated like a (secret) token, and so when it leaks it can be used to access sensitive information. Using it as 'just' a username would probably reduce a lot of problems as well.

Exactly. This is a point everyone seems to gloss over but is fundamental to the entire concept of using biometrics.

Re: Fingerprints can be hacked

#195
The huge advantage of biometrics (fingerprints, FaceID, etc.) is the ease with which a user can unlock their phone. A passcode may be better than a fingerprint, but a fingerprint+longer passcode is better than a shorter passcode (or no passcode at all).

Having a 12 character alphanumeric passphrase you enter each time you want to unlock is not something most users want to do.

See e.g.: https://www.businesstoday.in/technology/news/story/what-kick...

Only about 49 per cent of the users were setting a passcode, which meant that the remaining 51 per cent were not benefiting from the data protection mechanism. When Apple dug in to understand the reason, the findings revealed that users unlock their devices a lot - on an average about 80 times a day. And about half of its users simply didn't want the inconvenience of having to enter their passcode into their device, at times. At that time, in 2012-2013, the default passcode length for iPhone was four digits, which happens to be six today.

Apple realised that it needed to come up with a mechanism that's fast and secure, and doesn't involve typing in the passcode. That's when Apple introduced Touch ID, which was easy, fast and secure. The way that biometric authentication worked on Apple platforms was that the user must set a passcode to be able to use the biometrics. And just as Apple thought, there was a much higher adoption of biometric-based TouchID. Apple says over 92 per cent chose to use Touch ID and had therefore set the passcode, which in turn meant users were able to use Apple's data protection encryption system.

Re: Fingerprints can be hacked

#196
post #8
post #5

Earlier quoted context omitted.

That's why this is a dumb idea, merchants can just use the replay attack: https://www.wsj.com/articles/in-china-paying-with-your-face-... . The only place where you should be using your biometrics is to unlock devices you carry with you, like the iPhone.

Even for that it's not safe if anyone can bypass it with a $5 trick. It's definitely a thumb idea

> definitely a thumb idea

Four hours have gone by without comment on this and I feel the offense should be recognized.

Re: Fingerprints can be hacked

#197
post #3

Fingerprints are usernames, not passwords. Here is an excellent (and timeless) post on this fact: https://blog.dustinkirkland.com/2013/10/fingerprints-are-use...

Fingerprints are not usernames. I wish that idea would die but people just love putting things in existing categories so much they keep thinking "fingerprints aren't the same as passwords... so they must be the same as usernames!".

Re: Fingerprints can be hacked

#199
post #195

The huge advantage of biometrics (fingerprints, FaceID, etc.) is the ease with which a user can unlock their phone. A passcode may be better than a fingerprint, but a fingerprint+longer passcode is better than a shorter passcode (or no passcode at all). Having a 12 character alphanumeric passphrase you enter each time you want to unlock is not something most users want to do. See e.g.: https://www.businesstoday.in/te…

> The huge advantage of biometrics ... is the ease with which a user can unlock their phone

This does not prevent involuntary unlocking - it actually can allow for eased against-will unlocking.

«Ease» and security may sometimes not be friends.

Re: Fingerprints can be hacked

#200
post #2

My favorite photograph of a fingerprint is when the Chaos Computer Club reproduced the German Foreign ministers fingerprint from a photo. So much for military grade security. https://www.dw.com/en/german-defense-minister-von-der-leyens... - The core problems with biometrics are that: 1) Not revokable (unlike compromised credentials) 2) Not a secret 3) Usually trivial to reproduce and spoof (even "liveliness" tests)

> The core problems with biometrics are that: … is that they're treated as passwords instead of usernames. The three problems you list all have the biometric=password assumption in them. See also using the American SSN usage: it's treated like a (secret) token, and so when it leaks it can be used to access sensitive information. Using it as 'just' a username would probably reduce a lot of problems as well.

> American SSN usage

Nothing like a secret token that can be reliably guessed using only your birth month+year and place of birth!

Post reply on HN