Live data from Hacker News

Fingerprints can be hacked

blog.kraken.com

241–250 of 333 posts

Re: Fingerprints can be hacked

#241
post #35

Earlier quoted context omitted.

I've always disliked this breakdown. My body is something I have -- it's just potentially (not always practically -- see the article) more difficult to clone or otherwise use without my consent than a key fob or something. Edit: To be clear, I don't think this is an argument for biometrics, but rather an argument against them. They can't complement something I have in a two factor scheme, because my biometrics are so…

Your body isn’t very easy to replace. Passwords and devices are.

This is precisely why he is a poor “password” / secret replacement.

Whelp, your fingerprints have been cloned. Time to go get them burned off and get some new ones. Yeah, that’s not gonna work.

Re: Fingerprints can be hacked

#243
post #107

Earlier quoted context omitted.

This meme really really has to die. It's so annoying that it's spread so far. Biometric security (i.e something you are) does not need to be secret nor revoked. That's the entire point . It's a piece of information that even when it's known by everyone still can't be reproduced. The strength of a security system based on biometrics is exactly how well that system can detect that it's reading from an living breathing…

>- Perfect: A human guard manually taking a fingerprint reading. Can't be beat because the guard can obviously see that it's not really your hand. "Perfect" is too strong a statement. This is only true if the guard very carefully checks every fingertip to ensure nothing is glued over your normal fingertips, and even then it's possible to distract the guard or rush them with a socially-engineered premise. Or just brib…

You’re missing the point.

Biometrics are not the weakness. Current implementations are.

Re: Fingerprints can be hacked

#244
post #146

Earlier quoted context omitted.

So wear fingerless gloves and social engineer a little bit (it's cold, it's winter, I have bad circulation, etc). If you think having a human guard makes a system infallible, I have some bad news for you.

Oh lord, this is firmly off that point. An alert motivated human looking for fakes can identify them with nigh perfect accuracy. This means that it should be possible to build an autonomous system that can do the same which is the goal of biometric auth systems. There is nothing that fundamentally breaks biometric auth until you can burn fingerprints on someone or replace eyes or gene therapy new DNA or whatever. And…

Exactly, every keeps going on about magic social engineering attacks without providing details.

Anyone who has had their fingerprints taken by the FBI knows that there is a solid procedure that will detect fakes. The idea is to replicate this near perfection, not bolt on some revocation system for fingerprints (ouch!)

Re: Fingerprints can be hacked

#245
post #8

Earlier quoted context omitted.

Even for that it's not safe if anyone can bypass it with a $5 trick. It's definitely a thumb idea

> definitely a thumb idea Four hours have gone by without comment on this and I feel the offense should be recognized.

I thought it was intentional, won’t lie, I laughed.

Re: Fingerprints can be hacked

#247

Earlier quoted context omitted.

It seems you are stating that fingerprints do not identify an account holder. You should justify the statement.

No, I'm stating that fingerprints to not have the same security and privacy properties as usernames. Therefore they are not equivalent to usernames. * Usernames can be changed. Fingerprints can't. * Usernames can be denied. Fingerprints can't. * Usernames are zero effort to copy. Fingerprints require some skill and effort (if you have a decent fingerprint reader). * People are happy to share usernames online. Fingerp…

Or, model-wise, "account holders are not accounts", "users are not usernames", "individuals are not their operating identities".

Biometrics should be considered as part of the indication of an entity before its own accounts.

Re: Fingerprints can be hacked

#249

Earlier quoted context omitted.

I’m waiting on a court case with a fingerprint as key evidence for conviction, in which the defendant brings this up. Might not pass reasonable doubt muster, but what if somebody sold fingerprint forgery kits online that made it push-button simple? Just supply an image or two, run it through some ML to reconstruct the print, laser etch a latex glove or similar… I wonder if you could use CRISPR or “lab-grown meat” tec…

Why in the world would you need CRISPR or lab grown meat? Just sequence the DNA and send it off to a DNA assembly service. The price is a couple hundred bucks a pop. You don't have to replicate the entire DNA, just the segments used for forensic PCR. (On a side note, the state of biotechnology and life science knowledge on HN is utterly deplorable, repeating buzz words does not reality make.)

hahaha - Friend, this is a news website not a scientific forum. Relax.

Re: Fingerprints can be hacked

#250

Earlier quoted context omitted.

My intent wasn't to find out which states require prints, it was to drive conversation in order to refute the claim that state driver licenses are honeypots for fingerprints. Fingerprints are not required as a part of Real ID implementation. Real ID seems like it would be the main driver for feature parity between licenses of different states. If fingerprints aren't required by Real ID, then it seems like it would be…

Particularly since it's only being done in four states. That explains why I'd never heard of the practice.

It appears JohnFen partially geolocated me!

A few years ago I had top tier frequent flier status, and the airline kept offering to pay the Global Entry fee for me. Sit for a lame interview and provide a bunch of info to power-starved snooping Karens? No thanks.

Post reply on HN