Live data from Hacker News

Fingerprints can be hacked

blog.kraken.com

321–330 of 333 posts

Re: Fingerprints can be hacked

#321
post #217

Earlier quoted context omitted.

wait it's based on birth month/year/place? is there an algorithm to generate it or something?

There's not quite an "algorithm"; SSN's are so short (it's just a 9-digit number, so max 1 billion unique SSNs) that they have a very simple procedure for assigning them. The Social Security Administration explains it here: https://www.ssa.gov/history/ssn/geocard.html - The first set of three digits is called the Area Number - The second set of two digits is called the Group Number - The final set of four digits is t…

Not even worth the effort considering how many companies have been hacked.

https://www.popsci.com/social-security-number-equifax-leak/ https://www.forbes.com/sites/suzannerowankelleher/2019/08/01...

Re: Fingerprints can be hacked

#322
post #187

Earlier quoted context omitted.

> Biometric security (i.e something you are) does not need to be secret nor revoked. That's the entire point. It's a piece of information that even when it's known by everyone still can't be reproduced. If that's the point, the effort is doomed. All biometrics will be able to be reproduced sooner or later. There's no way around that. So, like all other identifiers, revocation is an important trait. Even if successful…

> If that's the point, the effort is doomed. All biometrics will be able to be reproduced sooner or later. There's no way around that. All encryption will eventually be broken therefore what’s the point is a pretty bad security posture. But like no it won’t. Even if you can fake every other metric (good luck with eyes) a fresh blood sample taken by a guard with hypothetical futuristic instant DNA sequencing will neve…

> All encryption will eventually be broken therefore what’s the point is a pretty bad security posture.

When a given crypto scheme is broken, you can change to one that isn't. When your physicality is compromised, you can't change to a new body.

Re: Fingerprints can be hacked

#323
post #2

My favorite photograph of a fingerprint is when the Chaos Computer Club reproduced the German Foreign ministers fingerprint from a photo. So much for military grade security. https://www.dw.com/en/german-defense-minister-von-der-leyens... - The core problems with biometrics are that: 1) Not revokable (unlike compromised credentials) 2) Not a secret 3) Usually trivial to reproduce and spoof (even "liveliness" tests)

I'm sure the military has better than average tech when it comes to security, but I wonder if they're agile enough to embrace the rapid technological change that is necessary to stay on the bleeding edge. These days when I hear military + security in the same sentence I think of aging warships running windows 2000, using oddball niche technology supplied by equally oddball government contractors/vendors.

Isn't Windows 2000 kind of a very respected operating system doing a lot of things right?

You assume 'old' strictly implies outdated, or bad, which isn't true. E.g. good passwords are still undefeated. And security protocol redundancies surely can make intrusion impractical, even if individual components fail.

I assume, military hard- and software to be made meticulously, double checking everything, on literally battle tested chips and gear. I mean, I really had no contact with anything military ever, so that's a guess based on aircraft and space development, pictures of überfunctional UIs and the ridiculous finances of the US military.

Re: Fingerprints can be hacked

#324
post #2

My favorite photograph of a fingerprint is when the Chaos Computer Club reproduced the German Foreign ministers fingerprint from a photo. So much for military grade security. https://www.dw.com/en/german-defense-minister-von-der-leyens... - The core problems with biometrics are that: 1) Not revokable (unlike compromised credentials) 2) Not a secret 3) Usually trivial to reproduce and spoof (even "liveliness" tests)

In the case of Apple’s TouchID, the fingerprint is less a password and more of a session extender. You need to login with ID and password to establish a session. Then the fingerprint gives you access to that session. Once the session ends, you need to reestablish your credentials. This obviously not as secure as a system when you must use your credentials frequently to maintain access, but it seems entirely appropria…

Potatoes, potatoes, or something.

So far I haven't encountered a device where a fingerprint was used to unlock disk encryption, so your objection is actually implied, I think. Especially, with the increasing uptime of Apple's new hardware, a running session is what you more often than not got these days.

No matter how you twist it, biometrics are fundamentally flawed and not even Apple can magically fix that. At least one component of access needs to be a secret, which cannot be extracted without cooperation, or "cooperation".

Re: Fingerprints can be hacked

#325

Earlier quoted context omitted.

I'm sure the military has better than average tech when it comes to security, but I wonder if they're agile enough to embrace the rapid technological change that is necessary to stay on the bleeding edge. These days when I hear military + security in the same sentence I think of aging warships running windows 2000, using oddball niche technology supplied by equally oddball government contractors/vendors.

Isn't Windows 2000 kind of a very respected operating system doing a lot of things right? You assume 'old' strictly implies outdated, or bad, which isn't true. E.g. good passwords are still undefeated. And security protocol redundancies surely can make intrusion impractical, even if individual components fail. I assume, military hard- and software to be made meticulously, double checking everything, on literally batt…

I'm not speaking from personal experience either, sorry if I seemed to imply that. I just meant it as a general comment with regards to anything that the military does. There is so much red-tape surrounding procurement, implementation that I wonder if they are agile enough to be on the cutting edge.

I don't mean to diss W2k in general, Its an OS that is well understood by now - weaknesses, mitigations, etc. Slowmoving entities like the government accrue so much cruft that it makes it exceedingly difficult to move to newer (and possibly better) platforms to take advantage of newer security tech.

Re: Fingerprints can be hacked

#326
post #148

Earlier quoted context omitted.

Right but exactly like hashing you can set the difficulty of breaking it to your risk tolerance. Your phone should probably be a little loose but the retina scanner at the datacenter of the dod will be a lot stricter.

That’s not a thing (Re: dod)

[deleted]

Re: Fingerprints can be hacked

#327

Earlier quoted context omitted.

A gesture unlock will provide the same and does not need a biological marker. I believe biometrics aren't necessary to establish security and in the worst case reveal unnecessary information.

Reveal unnecessary information to whom? Both Windows Hello and iOS TouchID/FaceID never allow biometric data to leave the device. In the case of iOS, that data never even leaves the secure enclave.

By their own statements that might be true.

Re: Fingerprints can be hacked

#328

Earlier quoted context omitted.

Isn't Windows 2000 kind of a very respected operating system doing a lot of things right? You assume 'old' strictly implies outdated, or bad, which isn't true. E.g. good passwords are still undefeated. And security protocol redundancies surely can make intrusion impractical, even if individual components fail. I assume, military hard- and software to be made meticulously, double checking everything, on literally batt…

I'm not speaking from personal experience either, sorry if I seemed to imply that. I just meant it as a general comment with regards to anything that the military does. There is so much red-tape surrounding procurement, implementation that I wonder if they are agile enough to be on the cutting edge. I don't mean to diss W2k in general, Its an OS that is well understood by now - weaknesses, mitigations, etc. Slowmovin…

If I understand correctly, the military doesn't really want to be cutting edge, as things go boom with yesterday's tech, without the trade-offs of untested, novel "innovations". I think there isn't much advantage in new developments, apart from convenience.

And for W2k, I wasn't merely suggesting it's well-tested, but also a different, better thing than say WindowsXP. At least, I got the impression operating systems folks reference it for a "many good ideas" kinda thing.

Sorry, I don't have any expertise in any of this and talk mostly out of my ass.

Re: Fingerprints can be hacked

#329
We can use fingerprints for additional security, but it has to be done carefully. If fingerprints or any biometric data is hacked, the users can change it, so they have to be contained. The best way I know is to use a mobile device with fingerprint or biometric input, which is saved only on the device. Then use the biometric to enable the user to accept the authentication request but use the mobile device specific info as a password replacement.

Re: Fingerprints can be hacked

#330
We can use fingerprints for additional security, but it has to be done carefully. If fingerprints or any biometric data is hacked, the users can not change it, so they have to be contained. The best way I know is to use a mobile device with fingerprint or biometric input, which is saved only on the mobile device. Then use the biometric to enable the user to accept the authentication request but use the mobile device specific info as a password replacement.
Post reply on HN