Samsung: Anyone's thumbprint can unlock Galaxy S10 phone
bbc.co.uk
bbc.co.uk
It just says “simply look at your phone to securely unlock it.” They make no claims about how secure it is.
In fact there are already articles showing how the unlock feature works while you’re asleep: https://9to5google.com/2019/10/16/pixel-4-tidbits-face-unloc...
To my knowledge, Apple is the only vendor that actually made in-depth claims about the security of their face unlock solution. They’re the only vendor that assumed anyone cared.
Android OEMs are working off a feature checklist and that’s about it.
The fix will just have to be building a profile of what screen protectors look like to the sensor and rejecting registrations that look like them with a helpful message about screen protectors.
I was able to register my nose to unlock the phone via the "fingerprint" sensor. Interestingly enough, it will reliably unlock with my nose, but not with either of my daughters' noses.
Something you have.
Something you are.
Something you nose.
Is this an example of AI gone bad, or something else?
That’s a total f’n failure, not just “a bug.” You only release such things after super duper thorough testing.
The process described above proved to be somewhat unreliable as the depth of the ridges created by the toner was a little too shallow. Therefore an alternative process based on the same principle was utilized and has been demonstrated in an extended video available here. First, the residual fingerprint from the phone is either photographed or scanned with a flatbed scanner at 2400 dpi. Then the image is converted to black & white, inverted and mirrored. This image is then printed onto transparent sheet at 1200 dpi. To create the mold, the mask is then used to expose the fingerprint structure on photo-senistive PCB material. The PCB material is then developed, etched and cleaned. After this process, the mold is ready. A thin coat of graphite spray is applied to ensure an improved capacitive response. This also makes it easier to remove the fake fingerprint. Finally a thin film of white wood glue is smeared into the mold. After the glue cures the new fake fingerprint is ready for use."
I'm not sure I would classify a process like that as being similar to putting a screen protector on.
Hah, this was the first thing I tested with Face ID when I got my iphone 10. If you look at it with your eyes closed then it won't unlock. Open your eyes and it instantly unlocks. It spent about five minutes playing peek-a-boo with it.
I've been here 10 years and it hasn't become like Reddit yet. Every person saying that HN will become like Reddit has been wrong so far.
I’ve personally feel/seen some erosion but it’s hard to quantify and measure.
On HN jokes do get up voted - if they're original, related to the topic and actually funny.
Random person tries to get in (eg phone was stolen in the subway, ...): biometrics work, password works.
Close person tries to get in (significant other, coworker, ...): biometrics is flawed, password works.
Government respecting your rights tries to get in: biometrics is completly broken, password works.
Government that don't respect your rights tries to get in: https://xkcd.com/538/
Although in that last case, as-in the case of Government respecting your rights but the court order you to give access, password still allows you to have the ability to block/brick/wipe the phone.
All of this of course is if you have a good password hygiene, but if you don't I don't think you have a claim to complain about weak security models.
I do disagree with a couple of your conclusions though, because the attacks you describe are all targeting you as an individual. There's a much broader class of attacks that should be worrisome -- adversaries seeking _any_ compromise of _any_ individual. Like getting a dump of passwords from neopets or something and trying all those passwords on Chase.
For that kind of adversary, password is vulnerable, and biometrics is secure. And that kind of adversary is by far the most dangerous and prevelant. Especially biometrics in the Apple secure enclave model, where the key material is secured by the biometrics but is very strong -- far stronger than a password can be.
The applications I'm familiar with, the password takes precedence. It doesn't require password and fingerprint.
The thing is, if you add an extra factor, either you are required to use all of them, in which case it increases the risk of being wrongly locked out, or you are required to use any of them, in which case it increases the risk of the wrong person getting in.
I found it functionally impossible to secure the android against my girlfriend as she could watch me enter any code or password multiple times.
She was not able to get into the iPhone, because the biometrics prevented her from being able to view the passcode being entered.
Summary: biometrics are a reasonable substitute for a trusting relationship. :)
From a usability perspective, passwords are a nightmare, TouchID is a bit better (e.g. dry or wet fingers don't reliably work), FaceID is quite usable.
Apple seems the only company worth criticizing in this space.
>Close person tries to get in (significant other, coworker, ...): biometrics is flawed, password works.
>Government respecting your rights tries to get in: biometrics is completly broken, password works.
The first is fully incorrect, the second far too generalized and heavily incorrect. PINs/passwords are far, FAR more trivial to skim then biometrics. Even mere shoulder surfing isn't hard, but in a world with approaching ubiquitous hard to notice downward looking cameras if you ever input a password anywhere that isn't physically secure, and with no one looking, you can easily have it compromised. And it of course takes essentially zero resource expenditure and offers zero visibility to merely use the password once it's acquired.
If it's at a random incident and a first-world type government wants to look, you can trivially disable biometrics on any decent implementation without even looking. So lack of biometrics buys you nothing. If it's a sting against you specifically then they can shoulder surf/camera it (remember the constant improvements in drones, are you REALLY not being watched well away from buildings even?) or just wait for you to unlock it and then swoop in and try to physically grab you while it's unlocked anyway. The scenario space where it'd make a difference is very, very minimal. Really, you want both: a strong password and biometrics for public usage. And for scenarios like border searches they can lawfully cause you enough inconvenience regardless that standard passcode is still not really the right response anyway. A burner, clean+remote load later, or alt-codes or the like would be the right way to go, though sadly I think only the first two are available right now.
>Government that don't respect your rights tries to get in: https://xkcd.com/538/
Possibly the dumbest xkcd ever made.
At best, biometrics are good as a username to identify who you are, but not that you consent to login.
At best, todays biometrics are a trade off in security for convenience, partially because most can be faked.
I look to modern banking startups for biometrics use because money and personal data are similarly valuable and sensitive. If they aren't using it, it's not secure, or ready.
We are somehow ok with touch and faceid without some form of 2FA.
But right now I doubt the fingerprint sensors will go away soon, nothing really beats them in terms of convenience.
The Pixel 4 does not have a fingerprint reader....
https://www.newscientist.com/article/mg21128225-100-fingerpr...
Nevertheless it probably won't ever be completely reliable short of installing a hypodermic needle with the sensor to take a blood sample every time :)
now I just use the 8 digit pin to login
Just like "something you know" can have different strengths, "something you are" can too and changes in technology and threats will enable new options alongside new attacks as we go along. It's a process.
Not only can "something you are" change (in some instances), it can also be something that can be difficult for technology to not recognize correctly. A username or password must be correct (unless you're Facebook and do that goofy thing where you allow both the upper and lower case versions) but a biometric is more fudgable.
Of course, the something you are necessitates a biometric system that itself can be trusted to be secure.
I'm somewhat surprised because it's definitely not new, I don't know what the exact genesis of that particular cryptographer's verse is but my vague recollection is I first heard it the late 90s, and the idea of extracting bits showing identity from physical qualities unique to a person certainly dates back a long ways. "Something you are" can cover a lot of possibilities too, and with vastly more variety and subtlety than I think a lot of people consider even in security fields. For example, there was recently a genuinely very interesting idea of measuring bottoms. As in, your actual behind/ass, via sensors in chairs. It should be unsurprising if you consider it, but of course the patterns of musculature/fat/bone structure are fairly unique to you for any part of your body if you have sensitive enough tools. It's a transparent measure for certain use cases like a workstation or the like since you're sitting down anyway, and hard to clone from afar since our butts are typically covered and subdermal is challenging without near contact. Another place if you want to look for cutting edge possibilities is advertising/surveillance. Near anything used for tracking fingerprinting could in principle be used for authentication too, and again there are potentially a lot of bits of entropy to be found there. Our gaits as we walk, our patterns of typing, our micro muscle movements, all sorts of things aren't so generic to a powerful enough system. "Biometrics" is to some extent at the stage of 80s or early 90s passwords, something to keep in mind in these discussions when people complain about them. 8-character alphanumeric passwords protected by crypt aren't exactly good these days either, but auth tech moved on even as tech benefitted attackers. In the future biometrics will undoubtedly consider far more than our current early generation systems, up to and including implants.
FWIW, I have (more rarely) seen a few other classes of factor suggested that do make sense, and are arguably distinct categories. One is spatiotemporal, ie., "somewhere/somewhen you are". This is used de facto by any sort of air gapping or "this system can only be accessed from this one place and console" or the like. It could though be taken advantage of far more thanks to more ubiquitous high resolution GPS and the like in our systems. Having certain kinds of data only become accessible in the right place/time could be very useful.
Another fuzzier category is "something you do", as-in observing the actions you take. I felt at one point that this was merely another way of measuring "something you are", but I can see the idea that it'd be distinct because it's about revealing your direct state of mind, whereas at least for the foreseeable future "something you are" tends to focus on more bulk matter aspects of your being. Technically state of mind is physical too, there is a specific vector state of axons and neurons and firing patterns that represent it, but it might make sense still to distinguish that from physical body structure or even implants. Whatever the case though it's still an interesting consideration, and makes a lot of sense in old school counterops. Sometimes the first sign of someone who "shouldn't be authenticated to use this" has been "they were 'acting funny'" after all.
Something you have can have strong copy protection like a yubikey and can be given away.
FWIW, I don’t think anyone has done this credibly yet.
Usernames can be guessed remotely, fingerprints can't really.
Please demonstrate an attack that takes "a wee bit" of effort where you can use a fingerprint you found in the wild to auth.
[1] https://www.macrumors.com/2014/12/29/ccc-reproduce-fingerpri...
https://www.forbes.com/sites/gordonkelly/2019/10/15/samsung-...
With this in mind, they would not be completely off the mark.
There is a video circulating these comments. It shows someone register their finger without the screen, slap the screen protector over top and unlock with a different, previously rejected finger.
Edit: https://twitter.com/sta_light_/status/1184475413252210688?s=...
I'm not dismissing the claims, but I would like to see if the behavior can be replicated with a brand new screen protector.
I'm unusually eager to know the full story!
Can only unlock with my scanned fingers, so will leave my scans as is until a fix eventuates (if it does).
Edit: Here is a video demonstration, posted by someone else in this discussion
If you record a new fingerprint without any protection, or one that doesn't confuse the sensor, you can't then put the flawed protection on top and have it bypass security.
I'm quite baffled by it honestly.
Surely the sensor must be able to tell the difference (even if it's currently doing it incorrectly)
Couldn't tell whether the N10 was completely naked during scan due to the quality of the video.
Would like to see verification, and to learn if the S105G sensor would be affected as well. It operates a bit better than the S10+, so it may not be identical - although that might be position only.
You'd have to take the phone, put a screen protector on, give it back, have them retrain the detection, then steal it again and finally unlock it.
I could imagine it's possibly like putting foggy privacy tint on a window. You can see through clearly before, but after the tint is applied, everybody looks pretty much the same.
It seems like it.
- The chip Samsung uses is by Qualcomm. Their big claim is that their ultrasound fingerprint scanner is the only US government approved non-optical way of electronically scanning a fingerprint (those sensors they have at airports use basically the same technology)
- It's supposed to be more secure than the capacitive technology Apple used to use since it grabs a true image of the fingerprint and not just a low-res representation
- Given this, it's probably a problem with the software on Samsung's part, not Qualcomm
- However, it's interesting that adding the screen protector is what broke it. It suggests that there could be any number of unintentional biometric security holes
- It demonstrates that consumer tech companies (with possible exception of Apple) don't really have the expertise or motivation to properly implement biometric authentication
(edit - newlines)
testResult = TestFingerprint(fingerprint);
if(testResult)
return UNLOCK_OK;
else
return UNLOCK_FAIL;
to this: testResult = TestFingerprint(fingerprint);
if(testResult == RESULT_OK)
return UNLOCK_OK;
else
return UNLOCK_FAIL;Of course the fact that they're using hashes of the fingerprint means this theory is bogus and the issue is probably a lot more complex/involved.
I'm not sure I want any tech company storing high resolution scans of my biometrics.
The fingerprint sensor is active only when the capacitive steel ring that surrounds the Home button detects the touch of a finger, which triggers the advanced imaging array to scan the finger and send the scan to the Secure Enclave. Communication between the processor and the Touch ID sensor takes place over a serial peripheral interface bus. The processor forwards the data to the Secure Enclave but can’t read it. It’s encrypted and authenticated with a session key that is negotiated using a shared key provisioned for each Touch ID sensor and its corresponding Secure Enclave at the factory. The shared key is strong, random, and different for every Touch ID sensor. The session key exchange uses AES key wrapping with both sides providing a random key that establishes the session key and uses AES-CCM transport encryption.
The raster scan is temporarily stored in encrypted memory within the Secure Enclave while being vectorized for analysis, and then it’s discarded. The analysis utilizes sub dermal ridge flow angle mapping, which is a lossy process that discards minutia data that would be required to reconstruct the user’s actual fingerprint. The resulting map of nodes is stored without any identity information in an encrypted format that can only be read by the Secure Enclave. This data never leaves the device. It isn’t sent to Apple, nor is it included in device backups.
In practice it may be possible to reverse-engineer the stored hashes but this has not been demonstrated (yet).
What I know about prints is that you’re looking for some number of correlations between features. So of 90 points from the first scan, you’ll need 16 to match on entry.
So... I don’t think without knowing which 16-90 points you’re going to compare that you can hash all the combinations.
I could be wrong, but I suspect this is something they don’t JUST hash.
I suspect Samsung can muster a fair bit of expertise if they feel the need. We're not exactly talking about a fly-by-night tech startup here...
>Some of the biometrics, including the ability to unlock your phone by scanning your face or irises, are so poorly executed that they feel like marketing gimmicks as opposed to actual security features.
https://www.nytimes.com/2017/09/05/technology/personaltech/s...
> The probability that a random person in the population could unlock your iPhone is 1 in 50,000 with Touch ID or 1 in 1,000,000 with Face ID. This probability increases with multiple enrolled fingerprints (up to 1 in 10,000 with five fingerprints) or appearances (up to 1 in 500,000 with two appearances).
The problem is that it says random people, but people aren't random. We don't periodically just stir all the people in the entire world and redistribute them across the globe.
In courts you'd get a situation where a jury is told there's only 1-in-10-million chance this evidence would match a random person. Only a few hundred people in the whole world could have been the one, and yet this suspect matches. And what they may not get told unless a defence lawyer brings it up is oh, by the way, six of those few hundred people were in the place where it happened and four more lived in the same street as the suspect.
Bob's Face ID may only match 1 in a million people. But if one of those "1 in a million" people is Bob's twin brother Dave who is always pranking him, and another is Bob's cousin Barry who doesn't look that similar to a person, but mathematically it turns out Bob and Barry's faces look identical to a computer vision system due to their bone structure, then Bob won't find "Face ID" much use.
That’s not accurate. Family members have more similarity in their prints than among random people, twins even more similarity, and identical yet more.
I can’t immediately find authoritative references for family and fraternal twins, but here’s a reference for identical twins:
“Identical twins have the same chromosomes and similar physical characteristics and, therefore, they have a high class/type similarity in their fingerprints.” https://www.ncbi.nlm.nih.gov/pmc/articles/PMC3338710/
(1-p)^n
by 1 - n × x
is absolutely fine. For example (1-0.00002)^5 = 0.999900004
Rounding gives you that “one in 10,000”You can ask the same question of face/iris scans, people have and it's quite difficult to replicate, but not impossible. There's a plethora of YouTube videos about this.
I recently bought a Samsung watch. It's a solid responsive device with ok software, depending on what you may do in the wearables app it may or may not crash(The watch itself seems to have good battery life and pretty stable). I had an apple watch for a while that I gave my mom and unfortunately I have to say the Samsung device feels like a device with a lot of potential but not quite there yet. A lot of it has to do with the ecosystem. Tizen seems great, but the app store is so-so. The entire samsung login, region, payment, app store experience feels half-baked compared to the experience on a mac/apple device. I've been recently trying to figure out if I should buy a samsung device to access the ToF camera, but the documentation is virtually none existent(it's scheduled to come "eventually")
I somewhat wish they would license their tizen version to other vendors since it's way better than the WatchOS alternative.
I haven't been using mac/iphones in a few years rather than to test stuff, so maybe it really got a lot worse since then. But from what I remember the general experience felt a bit more smooth.
https://www.blog.google/products/pixel/titan-m-makes-pixel-3...
Never used a Samsung myself so I'm just remembering stories.
But, you can you elaborate?
Spring and summer, TouchID works flawlessly. Once the air gets dry in the fall and my skin starts to get gross, TouchID struggles. But I guess that's to be expected.
It routinely misses touches altogether, complains that I'm not covering the sensor even when I am doing (and yet this doesn't seem to bother Touch ID in the slighest) and doesn't seem to have much of a delay between attempts making it very easy to "lock out" the fingerprint sensor and being forced to enter the PIN due to several mismatches in a short space of time.
Also whoever decided to put the fingerprint sensor on the back of the phone should be prevented from designing phones ever again.
> Also whoever decided to put the fingerprint sensor on the back of the phone should be prevented from designing phones ever again.
Why? My phone has a fingerprint reader on the back, and I quite like it- I don't have to move my fingers much to use it, it's also the lock button, which makes it rather easy to "log in" to the phone.Just tested it- less than one second to log in via finger, and it works almost all the time. (I've had motor oil on my fingers and it's still worked, not that that's a good idea...)
Also people who suggest serious consequences for failure to abide by a personal opinion should, IMO, stop talking.
I hope it means that Samsung compares the data on the whole sensor, and not that anyone can unlock it :)
I found it to be the worst place to put it.
- Xiaomi Redmi Note 4 - pretty good finger print scanner on the back
- Samsung Galaxy S8 - absolutely terrible fingerprint scanner that was so bad I switched to pin after a while
- Samsung Galaxy S10 - new fingerprint scanner under display, works most of the time but still unreliable, also it is not the quickest.
You would have thought that leading brand (Samsung) would have decent fingerprint scanners on their flagships, but it is just not the case.
The thing with bad fingerprint scanners is that you cant rely on them, so I rather choose reliable slower 3s unlock with pin than unreliable maybe faster 1-10s unlock with fingerprint.
They also touted "face recognition" but it was a poorly-made piece of software that used a conventional camera (no depth) and was just a marketing check-off item, and not a real feature.
That's certainly a matter of opinion, and is not a "huge downgrade for no reason". I prefer my fingerprint scanners on the front, and I know others do as well.
As for the unlock feature, it took the user through all steps of fingerprint setup only to work with any finger (or anything else warm toughing it, for that matter).
Pressing the valid finger against the protector leaves an imprint in the gel, and this is what is read when it reads the invalid finger. I don't think that this is a bug in Samsung's code but rather a flaw in the technology that they chose to use.
> After buying a £2.70 gel screen protector on eBay, Lisa Neilson found her left thumbprint, which was not registered, could unlock the phone.
This suggests that an attack of "put a malicious screen protector on phone to unlock" is possible. I'm curious whether there was any re-training after applying the protector.
Are long pins and passwords still the most secure way to control access to your phone? Is there U2F for phones as a 2nd factor?
Fingerprint replicas (or your actual fingers) are obtainable by targeted attackers of some sophistication. But if you're targeted by attackers willing to go that length for you, you have other problems. IMO, fingerprints provide the best practical security.
Pin, fingerprint reader (that works) is enough.
Btw, I don't think 'casual attackers' really fits with access to, and willingness to go through cctv.
Consider also a roommate or someone you've recently started seeing. They can very easily unlock your phone by using your finger while you're asleep. They could shoulder-surf as well, but you can be vigilant against that. It's almost impossible to be vigilant against someone grabbing your finger while sleeping
I believe most phones have a way to easily disable fingerprint or face unlock until the next time the pass code is entered.
For example, on recent iPhones, just hold both the power button and one of volume buttons down for a couple seconds, which brings up the screen for power off, medical ID, and emergency SOS. Hit cancel on that screen, and biometrics are disabled until you next enter the pass code.
It should be reasonably possible to be vigilant enough to do that before going to sleep.
If I remember the order correctly: One of the first attacks on finger print readers was to blow on them, making them read the remains on the previous fingerprint used. That was fixed by adding a temperature sensor to the reader, so to attack it you had to use a plastic bag with water at around human temperature. The easy fix was to also check for a pulse while reading the fingerprint, this also make it impossible to use a removed body part.
I have not kept up with the progress in the last years, so not sure how good creating a fake fingerprint that you put on top of your own prints work, like they do in movies. Finding and reproducing a print is not that hard.
As others have written, fingerprint are usernames. It is not secret and you can not change it
IMO a combination of bio-metric and pin/password/phrase would be a good solution.
wow. in what line of business do you work if you don't mind me asking?
;)
Mind you, there are some quite dumb criminals, so "likely probability" besides "how likely am I to get robbed?" likely goes out the window.
I like fingerprint scanner as a quick way to unlock my phone, it's at least more secure than the 4 digit passcodes or patterns I used before that, and more convenient than that or face recognition. But I wouldn't want to use fingerprint to replace entering a password for making payments or accessing any secure data.
First of all because they cannot be revoked. Unless you count cutting tools and torches. Just as well as they can be easily used without the user's consent (e.g. sleeping) without them being aware of it. Note: this does not require stealing anything as in the passphrase case.
Additional problems are the high false positive rate.
They just identify the user, not an action of authentication/authorization; i.e. a mental action like remembering a password and actively approving something.
See it this way: Your bank card identifies you, you pin number authorizes the payment. These are distinct differences. If you ignore authorization you get nfc payments which are very convenient but far less secure and easier to manipulate. Note: your pin can be revoked, your fingerprint can't.
It's awkward, but I think if you care about security that's still really the most practical solid option. Fingerprints were only ever "better than nothing" here and should not have been sold as more than that (Biometrics _can_ be very secure but they need human supervision, e.g. when police take a DNA sample you can't give them somebody else's DNA but nobody is supervising you when you press what may or may not be your actual finger up against the sensor on a stolen phone).
I have a passphrase and a relatively short screen timeout for my phone, it certainly is less convenient than most people's zero authentication strategy, I noticed this when my closest place to buy groceries announced I could use the phone instead of needing a cashier.
For a regular person you just wander around, bagging anything you want and scanning it with the phone, then obviously you pay at the end. But for any time I spent more than 30 seconds or so browsing the phone locked and I needed to re-enter my passphrase to scan an item, cumbersome. There are tweaks I could do to let the scanning app stay active when the screen locks, but ultimately I just won't bother, there are hand scanners for people who don't have a phone or don't want to use it like me. I'll only use the phone if I pop in to get a single item so that unlocking the phone is faster than swiping to get a scanner.
Which is the most secure? It depends on the threat model. With an NFC sensor, I suppose it should be possible to unlock a phone from a physical key, but is it really convenient?
The only downside of a fingerprint is that there is no key rotating. If your fingerprint pattern is compromised, you are screwed. This doesn't have to be a security vuln in the device itself. A determined attacker can take your fingerprints off the screen surface or back fit eh phone.
It's not perfect, (and my Yubikey doesn't support it so I don't do it) but what is?
Like a folder? Probably noticeable with a utility like WinDirStat.
Like a separate user? Can the other one install apps? If so, you're likely done for if someone gets access to the one account. Also there's this [1] to consider, as well.
I hate shooting privacy ideas down. Unfortunately, that's all I have to contribute this time.
After using it I like the idea with Huawei Private Space. You need to unlock the phone with a different biometric/password to get notifications even. So separate storage / user / app store.
Samsung Knox is a bit more seamless, you can choose how much you share (like copy & paste).
In case you are made to do it both can fool goverment to accept that you phone is clean with the correct setup.
Both have separated contacts / app store etc and are separated with support from the hardware.
In other words, a screen protector is not a "master key" for any S10!
Please correct me if I am wrong.]]
Edit: On second reading of the article it looks like a screen protector might actually be a master key for any S10 phone. That's a really big design flaw! (Thanks to computerex for making me read the article more critically.)
> After buying a £2.70 gel screen protector on eBay, Lisa Neilson found her left thumbprint, which was not registered, could unlock the phone.
This suggests that the issue started happening after putting on the screen protector, and after recording the fingerprint.
It's clear that Samsung and Google are scrabbling to catch up with Apple, and I don't see why tbh. I don't think the general public dislike traditional fingerprint readers nearly as much as they do finding out the unlock mechanisms aren't secure.
As repeated here in HN, a good password is nothing like biometrics. A good password should
- be frequently changeable
- not be left lying around
- not be easily visible in public
- if discovered, not be obviously associated with the user
- have lots of entropy
Biometrics fails all of these tests
Perhaps the fingerprint reader returns a result of 0 for "valid print and not matched", result 1 for "valid print and matched", and result -1 for "not valid print". If the phone vendor code simply tests for a non-zero result code and treats this as "matched", then the situation described would occur.
It would be interesting to test with other smooth objects that might activate the reader.
What is suspected here is that registering the finger with the screen protector on is masking the shape of the finger while still registering the touch action. As a result, it's enrolling a blank print. Then anyone else can unlock it afterwards with the screen protector still on.
Consider that screen protectors are designed and tested only to make sure touch actions work correctly, but this ultrasonic fingerprint ridge-shape detection technology is new, so they're probably not mutually compatible.
I don't know what was wrong with the swipe sensor. They're discreet, easy to keep clean, and hard to screw up. Maybe the only downside is they would keep them too close to the camera lens for accidentally lens smudging.
if (screencover) return true;