Live data from Hacker News

Fingerprints can be hacked

blog.kraken.com

201–210 of 333 posts

Re: Fingerprints can be hacked

#201
post #195

The huge advantage of biometrics (fingerprints, FaceID, etc.) is the ease with which a user can unlock their phone. A passcode may be better than a fingerprint, but a fingerprint+longer passcode is better than a shorter passcode (or no passcode at all). Having a 12 character alphanumeric passphrase you enter each time you want to unlock is not something most users want to do. See e.g.: https://www.businesstoday.in/te…

> The huge advantage of biometrics ... is the ease with which a user can unlock their phone This does not prevent involuntary unlocking - it actually can allow for eased against-will unlocking. «Ease» and security may sometimes not be friends.

At least on iPhones though they have a way to activate a mode that prevents the use of TouchID and FaceID. If I press the power button on my phone 5 times in a row that turns that off.

Yes I still run the risk of my device being unlocked against my will if I'm caught by surprise. But I'm able to disable this functionality in places where I think the risk of that may be higher, e.g. while traveling.

I'll still take the trade off of longer password (not just a few numbers) on my phone while using a biometric test for normal access.

Of course not everyone may have the same threats to consider and others may make different choices. Doesn't make either of our choices wrong.

Re: Fingerprints can be hacked

#202

Earlier quoted context omitted.

I’m waiting on a court case with a fingerprint as key evidence for conviction, in which the defendant brings this up. Might not pass reasonable doubt muster, but what if somebody sold fingerprint forgery kits online that made it push-button simple? Just supply an image or two, run it through some ML to reconstruct the print, laser etch a latex glove or similar… I wonder if you could use CRISPR or “lab-grown meat” tec…

Why in the world would you need CRISPR or lab grown meat? Just sequence the DNA and send it off to a DNA assembly service. The price is a couple hundred bucks a pop. You don't have to replicate the entire DNA, just the segments used for forensic PCR. (On a side note, the state of biotechnology and life science knowledge on HN is utterly deplorable, repeating buzz words does not reality make.)

And what is involved in the DNA sequencing? And the DNA assembly service will probably take record of the operation itself (it is not a common service).

In the context...

Re: Fingerprints can be hacked

#203

Earlier quoted context omitted.

suddenly Face/Off is no longer science fiction Didn't a woman in France already have a face transplant?

I don't think it was the type of transplant Face/Off was depicting, hers was very natural-looking but also visibly not a normal face. I'd like to see Mission: Impossible type transplants, or even masks like the ones they use, for that matter.

The CIA's former Chief of Disguise says they very much exist and are used, with some limitations [1]. Her comment on the 3d printer making the mask: "What if I said we had it".

Of course that's not really surprising when you look at the kind of Halloween masks you can get if you are willing to pay [2]. I imagine if you could special order them to perfectly fit your head they would be very convincing to the casual observer and to software.

1: https://youtu.be/mUqeBMP8nEg?t=673

2: https://www.youtube.com/watch?v=Y32hdPV0L3k

Re: Fingerprints can be hacked

#204
Yes. But at a certain point one has to consider how much security is "enough." Someone could break into my house, even when locked, by kicking in the door or breaking a window, but I don't necessarily need to turn it into Fort Knox in response. If you are a high-value target, it is worth thinking about this, but for the average person, I think it might be a reasonable trade-off.

Re: Fingerprints can be hacked

#205
post #2

My favorite photograph of a fingerprint is when the Chaos Computer Club reproduced the German Foreign ministers fingerprint from a photo. So much for military grade security. https://www.dw.com/en/german-defense-minister-von-der-leyens... - The core problems with biometrics are that: 1) Not revokable (unlike compromised credentials) 2) Not a secret 3) Usually trivial to reproduce and spoof (even "liveliness" tests)

I’m waiting on a court case with a fingerprint as key evidence for conviction, in which the defendant brings this up. Might not pass reasonable doubt muster, but what if somebody sold fingerprint forgery kits online that made it push-button simple? Just supply an image or two, run it through some ML to reconstruct the print, laser etch a latex glove or similar… I wonder if you could use CRISPR or “lab-grown meat” tec…

Considering the extremely dubious evidence that makes its way into courts, such as bite mark analysis, I doubt you'd get that much traction arguing about these scenarios with fingerprints.

Re: Fingerprints can be hacked

#206

Earlier quoted context omitted.

> The core problems with biometrics are that: … is that they're treated as passwords instead of usernames. The three problems you list all have the biometric=password assumption in them. See also using the American SSN usage: it's treated like a (secret) token, and so when it leaks it can be used to access sensitive information. Using it as 'just' a username would probably reduce a lot of problems as well.

> American SSN usage Nothing like a secret token that can be reliably guessed using only your birth month+year and place of birth!

[deleted]

Re: Fingerprints can be hacked

#208
post #107
post #2

My favorite photograph of a fingerprint is when the Chaos Computer Club reproduced the German Foreign ministers fingerprint from a photo. So much for military grade security. https://www.dw.com/en/german-defense-minister-von-der-leyens... - The core problems with biometrics are that: 1) Not revokable (unlike compromised credentials) 2) Not a secret 3) Usually trivial to reproduce and spoof (even "liveliness" tests)

This meme really really has to die. It's so annoying that it's spread so far. Biometric security (i.e something you are) does not need to be secret nor revoked. That's the entire point . It's a piece of information that even when it's known by everyone still can't be reproduced. The strength of a security system based on biometrics is exactly how well that system can detect that it's reading from an living breathing…

My thought is that biometrics should be the root of identity, not the endpoint. You shouldn't need to scan your retina, fingerprint, or face at every point you want to verify your identity. Instead you use other things like public key cryptography to verify your identity remotely, id cards (perhaps with strong cryptography) for in-person interactions, etc.

Lost/stolen cryptographic keys or ID cards could be revoked and would require a trip to your a certified biometric verification facility where a thorough in-person inspection would confirm that your fingerprints are real, you aren't using a fake eye, etc. Then you'd be issued new keys/cards at that location. Loss of ID is inconvenient, but not catastrophic. Leaking your biometrics is irrelevant.

Is it an infallible system? Certainly not, but it should be able to uniquely identify someone and not allow faking biometrics.

Re: Fingerprints can be hacked

#209
post #186

Earlier quoted context omitted.

For fingerprint it is "using several close-range photos in order to capture every angle" - to get PIN, I need one angle and probably not even close-range of video and even weird angle if I have to sneak up onto someone in a metro or in a coffee shop.

well, TFA used one photo...

How convenient for them that they:

1) did not write what are needed parameters of the photo or quality of left fingerprint

2) it does not look like they used photo from an angle of the screen as in article but some other closeup

3) somehow unlock stuff with thumb where most people use index finger

4) then they use index finger to operate "thumb" print

5) who touches screen like that with thumb, who touches back of the phone like that

In the end with PIN I can look over someones shoulder and not even have to make a video.

I agree with the premise of what they say that people might think fingerprint is "super secure" while it is not...

But it is secure enough for most of the people and more secure that typing in PIN or short password or for people using 0000 or 1234 as PIN.

Re: Fingerprints can be hacked

#210
post #3

Fingerprints are usernames, not passwords. Here is an excellent (and timeless) post on this fact: https://blog.dustinkirkland.com/2013/10/fingerprints-are-use...

Fingerprints are not usernames. I wish that idea would die but people just love putting things in existing categories so much they keep thinking "fingerprints aren't the same as passwords... so they must be the same as usernames!".

It seems you are stating that fingerprints do not identify an account holder. You should justify the statement.
Post reply on HN