Live data from Hacker News

Reversing a Fingerprint Reader Protocol (2021)

blog.th0m.as

1–10 of 17 posts

Re: Reversing a Fingerprint Reader Protocol (2021)

#4
As noted in the article I reversed the protocol for a related Goodix device (which was on Intel so used actual SGX instead of the white-box): I used the firmware update system to insert additional vulnerabilities in the sensor firmware and extract the PSK from that side.

I did a talk about it here: https://www.youtube.com/watch?v=IyjUY-xvFw4

Re: Reversing a Fingerprint Reader Protocol (2021)

#5
post #3

Damn, I always thought that the fingerprint data was encoded somehow and never left the sensor hardware itself! OS-level access to the imagery seems like a security risk, but also opens some interesting possibilities for alternative uses.

AFAIK it depends per reader. This one seems to be a weird webcam on steroids, but others do the matching locally.

IIRC, none of them do it particularly securely.

Re: Reversing a Fingerprint Reader Protocol (2021)

#6
post #5
post #3

Damn, I always thought that the fingerprint data was encoded somehow and never left the sensor hardware itself! OS-level access to the imagery seems like a security risk, but also opens some interesting possibilities for alternative uses.

AFAIK it depends per reader. This one seems to be a weird webcam on steroids, but others do the matching locally. IIRC, none of them do it particularly securely.

What's the security status of fingerprints on phones? Surely they don't leave the security chip? I hope?

Re: Reversing a Fingerprint Reader Protocol (2021)

#7
post #5

Earlier quoted context omitted.

AFAIK it depends per reader. This one seems to be a weird webcam on steroids, but others do the matching locally. IIRC, none of them do it particularly securely.

What's the security status of fingerprints on phones? Surely they don't leave the security chip? I hope?

I don't think fingerprints should be regarded as a secret.

Re: Reversing a Fingerprint Reader Protocol (2021)

#9
post #7

Earlier quoted context omitted.

What's the security status of fingerprints on phones? Surely they don't leave the security chip? I hope?

I don't think fingerprints should be regarded as a secret.

Can you please post a link to high quality images of your own fingerprints? It should be fine, probably nobody has the technology to make them show up on a threatening letter mailed to the government, or anything like that.
Post reply on HN