Live data from Hacker News

Fingerprints can be hacked

blog.kraken.com

211–220 of 333 posts

Re: Fingerprints can be hacked

#211

The broader argument here is less about fingerprints, and more about using anything immutable as authentication. You cannot change your fingerprints. You cannot change your social security number (at least not easily). These should therefore, NEVER be a primary method to authorize access to anything. Once stolen, the proverbial horse is out of the barn.

You can in fact change your fingerprints; glassblowing and metalwork, for example, offer numerous opportunities to do so.

Don't they regenerate? I vaguely recall reading that criminals have tried lots of surgical ideas but none would last longer than a couple of months.

Re: Fingerprints can be hacked

#212

As an IT professional you should know to never use fingerprints or facial recognition for logins.

It seems you are stating that biometrics should not be used to restrict account access according to specific individuals ("John can only access john.harrey and finance.12")

Re: Fingerprints can be hacked

#213
post #201

Earlier quoted context omitted.

> The huge advantage of biometrics ... is the ease with which a user can unlock their phone This does not prevent involuntary unlocking - it actually can allow for eased against-will unlocking. «Ease» and security may sometimes not be friends.

At least on iPhones though they have a way to activate a mode that prevents the use of TouchID and FaceID. If I press the power button on my phone 5 times in a row that turns that off. Yes I still run the risk of my device being unlocked against my will if I'm caught by surprise. But I'm able to disable this functionality in places where I think the risk of that may be higher, e.g. while traveling. I'll still take th…

On modern FaceID phones you need to hold the power and down volume key to bring up the Reset/PowerOff and cancel. Just clicking multiple times will bring up wallet, siri, or do nothing.

Re: Fingerprints can be hacked

#214
post #140

The biggest problem imho is that we only have two states on our phones - locked and unlocked. Ideally, I should be able to unlock the phone and take photos using just my fingerprint. In my case I would also like to be able to call, message, play games and similar. But to access the 2fa app, cryptoasset app or similar, I must further authenticate in a way that I only reveal parts of my secret ("Enter 3rd, 8th and 11th…

On Android (don't know about iOS) you can take photos without even unlocking - double press on the power button opens the camera. You can't access anything else (including existing photos in the camera roll).

It works the same way on iPhones. The lock screen includes a camera button. When tapped, the phone enter a camera-only mode in which only photos taken during that session are accessible.

Re: Fingerprints can be hacked

#215

Earlier quoted context omitted.

I’m waiting on a court case with a fingerprint as key evidence for conviction, in which the defendant brings this up. Might not pass reasonable doubt muster, but what if somebody sold fingerprint forgery kits online that made it push-button simple? Just supply an image or two, run it through some ML to reconstruct the print, laser etch a latex glove or similar… I wonder if you could use CRISPR or “lab-grown meat” tec…

Most of the evidence that shows up at a court case is forgeable. Simply showing that a particular piece of evidence could be forged in no way proves that it is forged. You would need some sort of argument to prove your contention.

Sadly, "forensic science" is often not science at all. Much of it is barely an improvement on the techniques from the Victorian era. Altogether too much of it is an expert saying "these two samples look like a match" without a quantifiable metric. DNA evidence has made enormous leaps in the right direction, but even that requires a good chain of custody, good lab practices, and honest actors throughout the process.

Re: Fingerprints can be hacked

#216
post #180

Earlier quoted context omitted.

> lengthy [...] password policies Bizarrely, my organization limits passwords to a length of 12 characters or shorter. I agree with you, I don't want a password the size of a paragraph, but c'mon... 12 characters?

I think you misread me, or I didn't communicate clearly. By "lengthy" I was referring to the policy , not password length. Indeed max password length itself is another common bit of foolishness, for sanity reasons arguably it shouldn't be infinite but ~150 characters should be fine so that if people want to have a long diceware passphrase that's fine. To the extent passwords are used at all it should be exclusively a…

Ah, gotcha, sorry. "Lengthy (password policies)", not "(lengthy password) policies". I wouldn't call the policies themselves particularly lengthy, though we do have multiple systems with different policies for which we're supposed to use the same password, so there's that -- it's possible to set a password in one place that can't be set in the other. (Would something bad happen if they weren't in sync? I can't see how, other than it wouldn't be clear half the time which password to use.)

Re: Fingerprints can be hacked

#217

Earlier quoted context omitted.

> The core problems with biometrics are that: … is that they're treated as passwords instead of usernames. The three problems you list all have the biometric=password assumption in them. See also using the American SSN usage: it's treated like a (secret) token, and so when it leaks it can be used to access sensitive information. Using it as 'just' a username would probably reduce a lot of problems as well.

> American SSN usage Nothing like a secret token that can be reliably guessed using only your birth month+year and place of birth!

wait it's based on birth month/year/place? is there an algorithm to generate it or something?

Re: Fingerprints can be hacked

#218
post #2

My favorite photograph of a fingerprint is when the Chaos Computer Club reproduced the German Foreign ministers fingerprint from a photo. So much for military grade security. https://www.dw.com/en/german-defense-minister-von-der-leyens... - The core problems with biometrics are that: 1) Not revokable (unlike compromised credentials) 2) Not a secret 3) Usually trivial to reproduce and spoof (even "liveliness" tests)

My problem with this reasoning is that it leads people to think that biometrics therefore shouldn't be used.

Can biometrics be spoofed? Absolutely. Is it likely to happen to the average person? Not at all. For a typical everyday user, a fingerprint or face scan is probably more secure than the common alternatives of "sticky note" passwords, easily guessed PINs, or no authentication at all.

Biometrics are a compromise between security and convenience. Before iPhones got Touch ID, it was not uncommon for people to just not put a lock on their phone out of convenience. Now it is impossible to find an iPhone out in the wild that is not fully encrypted. The average level of security on consumer devices that hold sensitive information has increased dramatically thanks to biometrics.

Re: Fingerprints can be hacked

#219

The biggest problem imho is that we only have two states on our phones - locked and unlocked. Ideally, I should be able to unlock the phone and take photos using just my fingerprint. In my case I would also like to be able to call, message, play games and similar. But to access the 2fa app, cryptoasset app or similar, I must further authenticate in a way that I only reveal parts of my secret ("Enter 3rd, 8th and 11th…

You can already configure apps you are allowed to use on iPhone & Android without unlocking the device. And individual apps are anyways free to implement their own security mechanisms.

Re: Fingerprints can be hacked

#220
post #107
post #2

My favorite photograph of a fingerprint is when the Chaos Computer Club reproduced the German Foreign ministers fingerprint from a photo. So much for military grade security. https://www.dw.com/en/german-defense-minister-von-der-leyens... - The core problems with biometrics are that: 1) Not revokable (unlike compromised credentials) 2) Not a secret 3) Usually trivial to reproduce and spoof (even "liveliness" tests)

This meme really really has to die. It's so annoying that it's spread so far. Biometric security (i.e something you are) does not need to be secret nor revoked. That's the entire point . It's a piece of information that even when it's known by everyone still can't be reproduced. The strength of a security system based on biometrics is exactly how well that system can detect that it's reading from an living breathing…

>- Perfect: A human guard manually taking a fingerprint reading. Can't be beat because the guard can obviously see that it's not really your hand.

"Perfect" is too strong a statement. This is only true if the guard very carefully checks every fingertip to ensure nothing is glued over your normal fingertips, and even then it's possible to distract the guard or rush them with a socially-engineered premise. Or just bribe or blackmail them.

Post reply on HN