Live data from Hacker News

Fingerprints can be hacked

blog.kraken.com

221–230 of 333 posts

Re: Fingerprints can be hacked

#221
post #140

The biggest problem imho is that we only have two states on our phones - locked and unlocked. Ideally, I should be able to unlock the phone and take photos using just my fingerprint. In my case I would also like to be able to call, message, play games and similar. But to access the 2fa app, cryptoasset app or similar, I must further authenticate in a way that I only reveal parts of my secret ("Enter 3rd, 8th and 11th…

On Android (don't know about iOS) you can take photos without even unlocking - double press on the power button opens the camera. You can't access anything else (including existing photos in the camera roll).

you definitely don't need to unlock to take photos on iOS.

Re: Fingerprints can be hacked

#222
post #107

Earlier quoted context omitted.

This meme really really has to die. It's so annoying that it's spread so far. Biometric security (i.e something you are) does not need to be secret nor revoked. That's the entire point . It's a piece of information that even when it's known by everyone still can't be reproduced. The strength of a security system based on biometrics is exactly how well that system can detect that it's reading from an living breathing…

> Biometric security (i.e something you are) does not need to be secret nor revoked. That's the entire point. It's a piece of information that even when it's known by everyone still can't be reproduced. If that's the point, the effort is doomed. All biometrics will be able to be reproduced sooner or later. There's no way around that. So, like all other identifiers, revocation is an important trait. Even if successful…

>Not at all perfect. Can that human guard really see if you're wearing a fake fingerprint? I doubt it, unless he's closely examining everyone's fingerprints first. And even then...

The procedure at the USCIS to get my green card was remarkably thorough. The guard manually and visually checked each of my fingertips carefully to ensure I had no fake print overlayed on top of my real print and I had to keep my hands within a small area with a camera on it for the entire process or they would restart everything.

Re: Fingerprints can be hacked

#223
post #217

Earlier quoted context omitted.

> American SSN usage Nothing like a secret token that can be reliably guessed using only your birth month+year and place of birth!

wait it's based on birth month/year/place? is there an algorithm to generate it or something?

There's not quite an "algorithm"; SSN's are so short (it's just a 9-digit number, so max 1 billion unique SSNs) that they have a very simple procedure for assigning them. The Social Security Administration explains it here: https://www.ssa.gov/history/ssn/geocard.html

- The first set of three digits is called the Area Number

- The second set of two digits is called the Group Number

- The final set of four digits is the Serial Number

Certain geographic areas get certain "Areas Numbers", then Group Numbers are assigned consecutively, then Serial Numbers are assigned consecutively. This entire system of consecutive assignment makes it trivial to guess pretty well, or even exactly, what someone's SSN is.

Re: Fingerprints can be hacked

#224
post #217

Earlier quoted context omitted.

wait it's based on birth month/year/place? is there an algorithm to generate it or something?

There's not quite an "algorithm"; SSN's are so short (it's just a 9-digit number, so max 1 billion unique SSNs) that they have a very simple procedure for assigning them. The Social Security Administration explains it here: https://www.ssa.gov/history/ssn/geocard.html - The first set of three digits is called the Area Number - The second set of two digits is called the Group Number - The final set of four digits is t…

Not since June 25, 2011 when they started randomizing assignment[1]. They still don't use 666 as an area number, though.

[1] https://www.ssa.gov/employer/randomization.html

Re: Fingerprints can be hacked

#225
post #116

How about .... Fingerprint sensors + inbuilt IR sensors that verify that there is a "live" finger with blood and pulse behind that print. Would that help make FP authentication more robust?

Yes, if you're interested in this kind of stuff you basically have to work for the military because they're the only ones with the funding and motivation for this kind of stuff.

Check out the LivDet - Liveness Detection Competitions - https://livdet.org/index.php

Re: Fingerprints can be hacked

#227
post #2

My favorite photograph of a fingerprint is when the Chaos Computer Club reproduced the German Foreign ministers fingerprint from a photo. So much for military grade security. https://www.dw.com/en/german-defense-minister-von-der-leyens... - The core problems with biometrics are that: 1) Not revokable (unlike compromised credentials) 2) Not a secret 3) Usually trivial to reproduce and spoof (even "liveliness" tests)

Me and my team have developed a solution for the 3 problems mentioned. Anyone interested to discuss further find my email on my profile.

Re: Fingerprints can be hacked

#228
post #140

The biggest problem imho is that we only have two states on our phones - locked and unlocked. Ideally, I should be able to unlock the phone and take photos using just my fingerprint. In my case I would also like to be able to call, message, play games and similar. But to access the 2fa app, cryptoasset app or similar, I must further authenticate in a way that I only reveal parts of my secret ("Enter 3rd, 8th and 11th…

On Android (don't know about iOS) you can take photos without even unlocking - double press on the power button opens the camera. You can't access anything else (including existing photos in the camera roll).

True, and it is a step in right direction. However I still don't want to expose my bank app credentials every time I show someone my vacation photos.

Re: Fingerprints can be hacked

#229
post #3

Fingerprints are usernames, not passwords. Here is an excellent (and timeless) post on this fact: https://blog.dustinkirkland.com/2013/10/fingerprints-are-use...

There are two threat models:

- Virtual

- Physical

In the virtual threat model, difficulty needs to be insane, since any of 7 billion people can launch automated attacks on my server.

In the physical threat model, difficulty can be moderate, since the only people who can attack are ones physically here. My front door has a pickable lock, and my windows are breakable. My key threat is my crazy stalker ex.

Fingerprints are usually in the latter category, and provide pretty good security.

Re: Fingerprints can be hacked

#230

Earlier quoted context omitted.

You can in fact change your fingerprints; glassblowing and metalwork, for example, offer numerous opportunities to do so.

Don't they regenerate? I vaguely recall reading that criminals have tried lots of surgical ideas but none would last longer than a couple of months.

if they do you're not burning deep enough

I dunno, I have psoriasis on my hands bad enough that sometimes i dont properly speaking have skin on some fingertips, so my experiences aren't normal.

I recall hitting someones' demo of the "first PAM integrated fingerprint ID system" in '98 and crashing their machine repeatedly with my thumb. It couldn't even scan me.

Post reply on HN