Fingerprints can be hacked
blog.kraken.com
blog.kraken.com
https://blog.dustinkirkland.com/2013/10/fingerprints-are-use...
In Europe there is a regulation (PSD2) that defines a strong authentication as 2 of the 3 listed above.
Edit: To be clear, I don't think this is an argument for biometrics, but rather an argument against them. They can't complement something I have in a two factor scheme, because my biometrics are something I have.
I don't think we have yet good metrics on how to detect specific individuals using a full-body scan. Not to mention the invasiveness of creating your personal initial dataset. Most folks won't stand for it. So right back to parts that are forgeable...
Whelp, your fingerprints have been cloned. Time to go get them burned off and get some new ones. Yeah, that’s not gonna work.
There are no people that have nothing to hide. There are only people that don't know what they should be hiding.
If I'm a company, would I want my employees to give up proprietary data they hold just because they personally "have nothing to hide?" Anyone who thinks that's acceptable is someone who isn't worthy of trust.
Sorry, but that is _way_ off.
I can run through 2 character passwords by hand in a few hours at most, likely faster. (Assuming a qwerty keyboard, 62 alphanumeric, plus roughly 33 other characters makes for 9025 possible passwords.)
To reproduce a fingerprint requires access, money, time, and expertise. It's not _hard_ but it is not trivial either. You need access to a good fingerprint. You need the money to buy the supplies (a laser printer, some acetate, and some wood glue). You need time to both capture the fingerprint, refine it in the photo editor of you choice, and then actually turn it into something that scans. And you need to know that this is all actually doable. And then that all assumes that it actually works; I can assure you this is not a 100% success rate.
Put another way, if you told me you _personally_ had a two character password on a specific account, I could likely log into it _today_. Conversely, if you told me it also required a fingerprint to log into, I'd be out of luck. I'd have to learn who you are, where you lived, and then concoct a way to capture a clean print.
As others have pointed out, biometrics != password. It's an apples to oranges comparison.
No, that is complete absolute shit post that isn't even self coherent. Like, it literally whines about needing something that can be "independently chosen, changed, and rotated", which obviously describes usernames so obviously biometrics can't possibly be usernames by that very post! Why is this dumb meme so fucking persistent? Fingerprints are one of many biometrics. They aren't usernames, which aren't an authentication factor at all. They aren't passwords. They aren't tokens. They are their own thing. They have their own pluses and minuses as part of a comprehensive response to a given threat scenario. That's it. Trying to shoehorn them into something else is the same as trying to shoehorn everything into a car analogy.
All security exists solely in the context of an equation of threat scenario (the word "threat" doesn't even appear in that post), defender vs attacker resources and the value of what is being defended. Real security must work for actual real humans too. For example, rotating passwords every day/week/month is "secure" except that it's also a huge PITA or even outright impossible for many humans and defending against what should be a non-existent threat scenario anyway. So the obvious and inevitable result is that everyone starts to use crappy passwords, write them all down on sticky notes and text files and such everywhere, or both. That is not the fault of the users, it's the fault of a shitty system.
Another word that doesn't appear in that post? "Camera". Biometrics is an enormously rich potential field, fingerprints are about the worst lowest hanging fruit and in no way represent everything particularly as we use more and more wearables (there are bits of entropy to be found in your body's cardiac cycle for example). But even for fingerprints, which is really lower resource for attackers: getting a reproducing a fingerprint, or having AI go through every single networked look-down camera for the obvious obvious pattern of a human pulling out a slab of screen and then entering a PIN or passcode into it then recording that? Are people expected to never ever unlock a device anywhere but a physically secure area? Because see above, that is not realistic for real humans and thus a worthless security response.
As is usually the case, the best answer is hybrid, with multiple levels of factor usage to try to combine the strengths of each. And indeed that is the way things are going.
Edit to add: And if I sound irritated about this I am. This is the same kind of user hostile shallow anti-security thinking that brought us things like "security" questions, password rotation policies, lengthy and baroque "must contain 2 caps 1 number 3 special characters but not those special characters and cannot START with a number" password policies, etc. All of which add aggravation and failure points to no good end. Bad security practices affect our entire industry to the detriment of us all, but "bad security" isn't just a technical thing it's a human UX thing.
Bizarrely, my organization limits passwords to a length of 12 characters or shorter. I agree with you, I don't want a password the size of a paragraph, but c'mon... 12 characters?
But I recognize in reality when using archaic systems at businesses with no budget sometimes hacks are just the best that can be done, and that's how it is. I mean, obviously best of all is no shared password, use proper key via hardware token instead and the password/PIN or (gasp :)) biometrics is purely something the user uses to activate the token. Unfortunately it'll probably be awhile until we get there. But the general use of baroque password policies, particular when interfacing with the general public, is still an anti-feature for security which has finally started to fade away.
This model is how a fingerprint can be used as a shortcut to deliver certain privileges. The user must first pass security by entering their password, and then later numerous safety triggers are in place to require that password again. Meaning that once a person is validated a stand-in can be suitable rather than fully evaluating each and every time.
Back to fingerprints: copying a fingerprint has numerous barriers that these exploits frequently ignore. First it needs to be the correct finger, it must be clear and complete enough to copy and finally it must be used at a time when the device will accept it. While such barriers may be insufficient for a secure environment, this approach provides more security than, for example, a person repeatedly entering a pincode into their phone through the day - something that is both easily observed and remembered (and worse too if it's a gestural passcode.)
To relegate fingerprints as only this or that throws the baby out with the bathwater - appropriate rules and context can make it a useful security improvement over the status quo. That doesn't mean it's perfect or that it has to be.
* Usernames can be changed. Fingerprints can't.
* Usernames can be denied. Fingerprints can't.
* Usernames are zero effort to copy. Fingerprints require some skill and effort (if you have a decent fingerprint reader).
* People are happy to share usernames online. Fingerprints are considered much more private.
Biometrics should be considered as part of the indication of an entity before its own accounts.
- Virtual
- Physical
In the virtual threat model, difficulty needs to be insane, since any of 7 billion people can launch automated attacks on my server.
In the physical threat model, difficulty can be moderate, since the only people who can attack are ones physically here. My front door has a pickable lock, and my windows are breakable. My key threat is my crazy stalker ex.
Fingerprints are usually in the latter category, and provide pretty good security.
If you're already being personally targeted by an organization professional enough to follow you around, take a photo of your fingerprint on something you touched, then painstakingly reproduce said fingerprint through highly technical means and then gain physical access to your personal device that uses a fingerprint reader to use said fingerprint, you should be aware of your position and have multi-factor authentication set up for everything anyway.
For your average everyday person fingerprint security is fine. The thief who snatches your phone when you step away from your table in the mall food court isn't going to be able to crack it via this method.
>Think this is still overestimating the threat. It's kinda like saying you can hack someone's password by watching video of them typing. True, but also non-trivial.
Isn't that genuinely getting pretty trivial in public though? And in turn I think that is a real argument for biometrics too. The amount of over-the-shoulder camera surveillance in business and urban areas is pretty scary at this point, as are the concealability and cheapness of even very tiny spy cams. There have been plenty of scandals around it even in things like AirBNBs or hotels, historically from the context of sex, but not a stretch to imagine that passwords could be a much bigger and more lucrative target. And ML/AI is getting ever more sophisticated, and humans entering PINs/passwords is pretty repetitive behavior with a high degree of uniformity in how it's done, at least the device-unlock level. Seems very amenable to highly reliable automated analysis, to the extent I'd be genuinely surprised if that's not secretly deployed already in surveillance states.
I don't enter PINs/passwords in public anymore if I can possibly help it. It just seems scalable in a way that physical attacks aren't.
In the wild I imagine it's one of those things that's simple in concept but difficult in execution due to all the edge cases. Even if you get 80% of a password, if you're not at the perfect angle to catch those last few key-strokes you haven't accomplished much.
But the whole point is that it's easier than you describe as people make photos with fingerprints themself accidentally, and technical means to reproduce fingerprints are not highly technical.
Could an enterprising criminal master this technique? Sure, but I'm not convinced it's reliable or lucrative enough to make the time/risk investment worth it for someone with that skill-set.
However, having some experience with biometric sensors the False Accept/Reject ratio both for matching the fingerprint and detecting "liveness/spoof" is a BIG DEAL. Matching many prints or to many people is also MUCH HARDER (combinatorically). At high SNR (more expensive, higher resolution, larger sensor, higher power, longer latency) these problems can be largely mitigated with accurate recognition and very difficult to spoof systems. Those aren't the ones people attack for online fame.
However, when display integrated ultra-thin low cost very convenient matching is required... it will trade off for False Accept/Reject ratios and make the system significantly (orders of magnitude) less accurate. Unfortunately, it appears that the old MacBook touchbar integrated sensor has sacrificed significantly in this area.
Time of Flight 3D sensors make spoofing Face ID with easily carried biometrics significantly more challenging (they tend to be head sized).
Having a 12 character alphanumeric passphrase you enter each time you want to unlock is not something most users want to do.
See e.g.: https://www.businesstoday.in/technology/news/story/what-kick...
Only about 49 per cent of the users were setting a passcode, which meant that the remaining 51 per cent were not benefiting from the data protection mechanism. When Apple dug in to understand the reason, the findings revealed that users unlock their devices a lot - on an average about 80 times a day. And about half of its users simply didn't want the inconvenience of having to enter their passcode into their device, at times. At that time, in 2012-2013, the default passcode length for iPhone was four digits, which happens to be six today.
Apple realised that it needed to come up with a mechanism that's fast and secure, and doesn't involve typing in the passcode. That's when Apple introduced Touch ID, which was easy, fast and secure. The way that biometric authentication worked on Apple platforms was that the user must set a passcode to be able to use the biometrics. And just as Apple thought, there was a much higher adoption of biometric-based TouchID. Apple says over 92 per cent chose to use Touch ID and had therefore set the passcode, which in turn meant users were able to use Apple's data protection encryption system.
This does not prevent involuntary unlocking - it actually can allow for eased against-will unlocking.
«Ease» and security may sometimes not be friends.
Yes I still run the risk of my device being unlocked against my will if I'm caught by surprise. But I'm able to disable this functionality in places where I think the risk of that may be higher, e.g. while traveling.
I'll still take the trade off of longer password (not just a few numbers) on my phone while using a biometric test for normal access.
Of course not everyone may have the same threats to consider and others may make different choices. Doesn't make either of our choices wrong.
You also risk the accidental activation of an SOS call.
Yes this is kinda buried and not clear at all that this function also disables FaceID but it does.
On my iPhone 13, just now, I rapidly clicked the power button 5x.
The phone immediately made a loud sound and put up a screen that said "Emergency SOS". There was an option to "cancel" it, but I assume that the phone would have contacted 911 in short order unless I quickly cancelled.
So the correct description is probably "it depends".
In Settings go to Emergency SOS. Uncheck Auto Call
However, you are correct that a fingerprint is faster than even a 4 digit pin. And even a TPM does not solve the problem of pin/password reuse and being easy to guess, it just makes it harder by giving you much fewer guesses.
Ideally, I should be able to unlock the phone and take photos using just my fingerprint. In my case I would also like to be able to call, message, play games and similar. But to access the 2fa app, cryptoasset app or similar, I must further authenticate in a way that I only reveal parts of my secret ("Enter 3rd, 8th and 11th character of your password:"). The assumption here is that I will mostly authenticate in a private setting, but sometimes I might not have that luxury.
It made me realize this is the purpose of PINs for some apps (eg Signal)
I've fallen to the laziness of using fingerprints on my devices as well, but they still require a password to decrypt the contents of the storage device on boot. For many, if not most, threat models, this is perfectly fine.
I lock my phone to prevent people with messing with my contacts and scrolling through my messages. It's an inconvenience to bypass that requires preparation. A motivated attacker would just as easily spy over my shoulder if I were to use a password, either on my phone or on my laptop.
I look at these mechanisms like the lock on a teenager's bedroom door. Those things aren't impenetrable and anyone with just a little lockpicking experience or access to some automated tools can open them in a minute. Unlike the locks on our front doors, built to keep intruders that don't want to risk physical damage to our windows out, they're a message: please don't violate my privacy. Violating that privacy is made moderately difficult by the mechanism itself, but it's hardly impossible.
Unless you carry a password-protected authentication and key management token with you at all times, you're at risk of having your system broken into. Most of us don't need to worry about those kinds of things.
What does that mean? Unlocking your MacBook gives access to your RSA keys and all is lost.
So it's not useful for authentication but could be used for identification.
I dunno, I have psoriasis on my hands bad enough that sometimes i dont properly speaking have skin on some fingertips, so my experiences aren't normal.
I recall hitting someones' demo of the "first PAM integrated fingerprint ID system" in '98 and crashing their machine repeatedly with my thumb. It couldn't even scan me.
This is why multi-factor authentication is a thing. Generally, pick two: something you have, something you know, or something you are.
If the scanner doesn't like your fingerprint this morning, just use your proximity badge instead, and if someone takes a photo of your fingerprint, it's still useless unless they also know your PIN.
The issue is that a lot of our hardware, particularly phones and laptops, is single-factor authentication. And on top of that, this hardware knows the login to a bunch of other very sensitive material, like your bank accounts.
There's of course nothing wrong with pointing out already known security flaws, but it's good practice to mention when this is a well known thing and reference prior work - which the post by kraken does not do.
And if we're talking about authenticating people in truly secure environments, my gut tells me that adding a couple more factors to even a simple fingerprint reader ought to be more secure and robust than making a super-complicated fingerprint reader and leaving it as the only factor.
https://deepblue.lib.umich.edu/bitstream/handle/2027.42/3819...
At the moment, humans are still necessary for situational awareness, but probably machines can get there pretty soon. A phone, for example, that monitors its surroundings continuously and has enough intelligence to reliably distinguish normal access by its owner from duress or the presentation of fake biometrics seems like it's within reach of current technology (though it doesn't actually exist).
Would that help make FP authentication more robust?
DNA is similar - you leave hairs in taxis, public toilets, etc.
https://m.youtube.com/watch?v=MAfAVGES-Yc
?13? Years ago?
Fingerprints and biometrics in general are not a secret. Consider your fingerprint like your face. Anyone can reproduce your face, there are cameras everywhere, and it is probably already easy to find on the internet. "Hacking" your face by taking a picture is the most boring "hack" ever.
Now, if I print your face on a piece of paper, wear it as a mask and try to say to a security guard that I am you, normally, he won't let me in. If he does, the problem is not that I managed to make a paper mask with a picture of you, this will always be possible, the problem is that your guard is stupid and you need a better one.
And if your fingerprint scanner can be fooled by a dab of glue and a laser printer, you probably need a better scanner, something that Apple should be able to do. Smartphone manufacturers like Apple are usually good at bringing fancy tech to the masses, and they could work on defeating these old attacks.
Possible ways of detecting a fake fingerprint (beside warmth):
- Blood (we could use one of these cheap SpO2 sensors)
- Capacitance
- Perspiration and related skin resistance
- Microscopic skin details
And the usual machine learning solution of feeding thousands of real and fake fingerprints to a neural network and letting it decide.
As all living things, fingers are far from simple, there are plenty of details beyond the obvious pattern. It is a bit like a banknote, you can photocopy a banknote and it is very east to identify the banknote you copied. But it is very hard to pass it off as a real one to someone who knows where to look.
Good security design is as much about asking, from first principles, "what conditions need to be met to open this?" as about considering how it might be attacked.
For example, the condition to be met for a pad lock to open is not "when the proper key is inserted" or "the key pins are raised to the appropriate level". It's something more basic-- like "when the locking bar no longer blocks the shackle from rising."
From that perspective, attacking the key hole and pins is only one of multiple vectors.
In any case, the bolt cutters approach is also why I stipulated "putting aside brute force". Because in the context of computer security as with this article, something a bit more subtle seems to be effective more often, especially against higher end security.
As someone who doesn’t specialize in security, one claim that has stood out to me for not using fingerprints is that you can't run bcrypt (or some other salting algorithm) on fingerprints [1].
I don’t see any discussion of that here thus far. Is that still the case? I feel like I would have heard about developments in this area if something had changed. But perhaps I've always misunderstood the criticism?
[1] https://www.rsaweb.co.za/fingerprint-security-fingerprints-a...
This can protect you against this "attack vector".
They should add at least a 2nd layer (that doesn’t reduce the convenience too much).
For example, people could probably remember a simple Morse-code-like sequence of finger presses, e.g. your extra token is that you set it up to use “tap, tap, longpress, longpress, tap”.
https://external-content.duckduckgo.com/iu/?u=https%3A%2F%2F...
Has this been proven to some degree or is it merely a conjecture.
I suppose by now, governments have collected enough fingerprints to pretty much confirm this, but I haven’t seen any studies.
i suspect biometrics like fingerprints may play a role in the future, but the role they would play is more convenience in cases where the device knows its in a trusted environment. (that is, there will be more attention on devices tracking whether they've been separated from their owner, or if their owner is not behaving like their owner, and if so, requiring additional challenge)
either that or we'll all be carrying keys. there are some cool wearables i've seen out there that i think talk nfc.
I've been telling my friends for a couple years now that unlocking via fingerprint is a convenience feature, not a security feature.
Same method but 21 years ago.
Plus the good thing about fingerprints is that most people have learned from movies+tv that fingerprints are not secret and can be faked
At best the biometric locks are like locks on your house. Stops most people but not someone really determined.
https://www.dw.com/en/german-defense-minister-von-der-leyens...
-
The core problems with biometrics are that:
1) Not revokable (unlike compromised credentials)
2) Not a secret
3) Usually trivial to reproduce and spoof (even "liveliness" tests)
The only place where you should be using your biometrics is to unlock devices you carry with you, like the iPhone.
Nonetheless, we still lock our doors and thieves often break in, even though picking the lock is both safer and less likely to arouse suspicion.
Your argument makes sense, but we humans aren't really rational
On the rationality of having locks when criminals can very easily break a window, the old saying that locks keep honest people out rings true. Locks do serve a purpose even if they do very little to slow criminals down. To bring the analogy full circle fingerprint readers always seemed like windows to me in how easy they are to bypass, luckily they're more of a luxury than a necessity. :-)
That is why they aren't carried around any more.
And that is not taking into account that most locks can be defeated without lockpicks, a steel ruler will do.
It's just sad when people that don't know a bit about the trade boast about "regulations" and how they are relevant. They are not.
Four hours have gone by without comment on this and I feel the offense should be recognized.
Law enforcement can force you to use biometrics to unlock a phone. They have used dead bodies to unlock phones.[0] What they can’t do is make you remember a code/password which you have “forgotten.”
[0] https://www.forbes.com/sites/thomasbrewster/2018/03/22/yes-c...
2. Nobody claimed to then want to withhold the feature "from the masses"... so this is a strawman.
3. "hypothetical actions of an agency"... I think it's pretty clear that these types of methods are not hypothetical, and are being used already
4. "will stop short of torture"... I also think it's clear that many LEO's, especially the closer to federal ones, have been found to torture already.
I agree with gp, biometrics on phones are a bad idea all around, for a lot more reasons that have been said. I don't know why you are protesting this idea as you do.
They might be able to with an FMRI machine.
TLA person: Give us the code or we put you the MRI machine!!
Victim: Can't you just use a $5 wrench instead?
There are still plenty of places where polygraph examinations are used legally.
But they can lock you up for not supplying it.
From your https://www.forbes.com/sites/thomasbrewster/2018/03/22/yes-c...
I wonder if you could use CRISPR or “lab-grown meat” techniques to do the same with DNA evidence…might be something that would get you a contract with the CIA/NSA.
Didn't a woman in France already have a face transplant?
I'd like to see Mission: Impossible type transplants, or even masks like the ones they use, for that matter.
Of course that's not really surprising when you look at the kind of Halloween masks you can get if you are willing to pay [2]. I imagine if you could special order them to perfectly fit your head they would be very convincing to the casual observer and to software.
For all of those outraged by the media storm, it is free advertising to those actually interested in the service. All of the pearl clutchers feigning shock and outrage over shady service mean nothing to the company providing the service, as these were never going to be their customers in the first place.
> Using several close-range photos in order to capture every angle, Krissler used a commercially available software called VeriFinger to create an image of the minister's fingerprint.
The tests also have varying accuracy rates, but people misunderstand what it means. If the test is 99.99% accurate, that doesn't mean that there is a 99.99% chance that the defendant is the perpetrator. It means that in a region with ten million people, you've whittled your suspect list down to a thousand people. If you pick one of them at random there is only a tenth of a percent chance it was them.
This especially problematic when dealing with "DNA databases" because then with a large database you have a high probability of finding a false positive match and the true perpetrator might not even be in the database.
But even then, people use percentages as if everyone's DNA was independent. Which it isn't. Blood relatives have similar DNA.
The one thing DNA is really good for is excluding people. If you have the rapist's DNA and you accurately test it against the suspect's DNA and it doesn't match, it's not them.
The law has to operate within a practical compromise and err heavily on the side of reducing false convictions.
This is antithetical to the concept of serving one’s time. Guilty people deserve to go free once their debt to society has been fulfilled.
https://en.wikipedia.org/wiki/Blackstone%27s_ratio
Does a law system let some guilty people got free to avoid incarcerating the innocent, or does it incarcerate the innocent to avoid letting some guilty people go free?
My opinion is to lean towards letting the guilty go to avoid incarcerating the innocent, but other people in other places can lean the other direction.
That is an article I was reading today. I don't know what is wrong with America.
(On a side note, the state of biotechnology and life science knowledge on HN is utterly deplorable, repeating buzz words does not reality make.)
In the context...
It's already trivial - $500 consumer grade resin printers have sufficient resolution, and creating the model from photographs is super easy.
Same for facial recognition - you can do Mission Impossible style masks, and the most significant investment is in time spent learning makeup and wig work.
Biometrics are not secure, just like a vast majority of locks. All it takes is tools, knowledge, and motive to bypass them.
https://www.dw.com/en/german-defense-minister-von-der-leyens...
I just don't follow the timeline and geometry. Seems theoretical only maybe.
It is like a highly distributed backup of that fingerprint.
In which states? The only thing I have been fingerprinted for is in the US is The Global Entry program.
One state I lived in gave me the option of not having a RealID-compliant license if I wanted to. Another didn't, so fingerprints were compulsory.
[0] https://www.biometricupdate.com/202101/real-id-law-quietly-p...
https://duckduckgo.com/?q=which+states+require+thumb+print+f...
Fingerprints are not required as a part of Real ID implementation. Real ID seems like it would be the main driver for feature parity between licenses of different states. If fingerprints aren't required by Real ID, then it seems like it would be incorrect to assume that all states require fingerprints - and thus also incorrect to assume that driver licenses in the USA are used as honeypots for fingerprints.
Perhaps landemva should have specified which states are using driver licenses as honeypots for collecting fingerprints?
A few years ago I had top tier frequent flier status, and the airline kept offering to pay the Global Entry fee for me. Sit for a lame interview and provide a bunch of info to power-starved snooping Karens? No thanks.
However, they are showing their attack working on a Macbook Pro with touchid, which uses this sort of reader. So it's easier to fake in practice than it is in theory. Whatever material you lift the print off of should have to mimic the capacitive behavior of the finger and this looks like it busts Apple's claim that it can read the lower layers (or it tells us their default sensitivity is set too low for convenience)
https://media.ccc.de/v/31c3_-_6450_-_de_-_saal_1_-_201412272...
The strength of a security system based on biometrics is exactly how well that system can detect that it's reading from an living breathing human.
- Perfect: A human guard manually taking a fingerprint reading. Can't be beat because the guard can obviously see that it's not really your hand.
- Shit: A camera that compares pictures.
The entire industry is about making an autonomous system that gets as close as possible to perfect. It's fine to say that you don't think it's good enough right now but "oh no I lifted a fingerprint from a photo" isn't some security breach.
And yet, it can be reproduced. So it seems like the entire point is... invalid.
Your phone should probably be a little loose but the retina scanner at the datacenter of the dod will be a lot stricter.
Well, the argument some people are making is that this might be no better than a human checking your ID. Yes, there the guard can verify that there is some real human there, but both the ID and the fingerprint could be faked (e.g. a fake fingertip mold which matches the victim's "known" fingerprint).
Anyone who has had their fingerprints taken by the FBI knows that there is a solid procedure that will detect fakes. The idea is to replicate this near perfection, not bolt on some revocation system for fingerprints (ouch!)
If that's the point, the effort is doomed. All biometrics will be able to be reproduced sooner or later. There's no way around that.
So, like all other identifiers, revocation is an important trait. Even if successful reproduction is difficult and rare, it would be utterly devastating to those affected unless there's a way to revoke.
> Perfect: A human guard manually taking a fingerprint reading. Can't be beat because the guard can obviously see that it's not really your hand.
Not at all perfect. Can that human guard really see if you're wearing a fake fingerprint? I doubt it, unless he's closely examining everyone's fingerprints first. And even then...
All encryption will eventually be broken therefore what’s the point is a pretty bad security posture. But like no it won’t. Even if you can fake every other metric (good luck with eyes) a fresh blood sample taken by a guard with hypothetical futuristic instant DNA sequencing will never be broken. If your threat model is someone cloning you, the you have bigger problems and they still can’t clone your fingerprints!
You’ve got revocation completely ass-backwards. If someone successfully tricks a biometric system you don’t need to revoke someone’s fingerprint, you revoke the reader! That’s the thing that actually provides all the security.
The point of the guard is that a human has absolutely no trouble determining whether they’re taking a reading of a real hand, scanning a real eyeball, to taking a real blood sample. Maybe in mission impossible movies but you’re really really overstating the resources required to make a convincing hand to someone specifically looking for fakes. Yes social engineering is a problem which is why an autonomous system with the detection quality of a human would be nigh unbeatable.
When a given crypto scheme is broken, you can change to one that isn't. When your physicality is compromised, you can't change to a new body.
The procedure at the USCIS to get my green card was remarkably thorough. The guard manually and visually checked each of my fingertips carefully to ensure I had no fake print overlayed on top of my real print and I had to keep my hands within a small area with a camera on it for the entire process or they would restart everything.
Lost/stolen cryptographic keys or ID cards could be revoked and would require a trip to your a certified biometric verification facility where a thorough in-person inspection would confirm that your fingerprints are real, you aren't using a fake eye, etc. Then you'd be issued new keys/cards at that location. Loss of ID is inconvenient, but not catastrophic. Leaking your biometrics is irrelevant.
Is it an infallible system? Certainly not, but it should be able to uniquely identify someone and not allow faking biometrics.
> biometric verification facility
sounds expensive.
"Perfect" is too strong a statement. This is only true if the guard very carefully checks every fingertip to ensure nothing is glued over your normal fingertips, and even then it's possible to distract the guard or rush them with a socially-engineered premise. Or just bribe or blackmail them.
Biometrics are not the weakness. Current implementations are.
Someone can use their smartphone to film other person as they type stuff in, no need for printing fake print. They can steal phone/laptop as soon as they are done filming.
This is the case that fingerprint sensors are preventing.
Pointing out problems is useless - as people don't have alternative that would be "all-mighty secure without flaws".
It should be defense in depth not - and that is already there for example banking apps - you need fingerprint to unlock the phone and banking app requires its own specific PIN. Getting those 2 things makes it much harder for bad guys to do something like money transfer. Yeah they might get your photos and other stuff - but probably there are secure store apps that would encrypt your photos if you have ones that you really want to protect.
They aren't. Your parent post already mentioned that they were extracted by filming.
Passwords don't have the other 2 problems, and I'm not really sure what is gained by not talking about them.
1) did not write what are needed parameters of the photo or quality of left fingerprint
2) it does not look like they used photo from an angle of the screen as in article but some other closeup
3) somehow unlock stuff with thumb where most people use index finger
4) then they use index finger to operate "thumb" print
5) who touches screen like that with thumb, who touches back of the phone like that
In the end with PIN I can look over someones shoulder and not even have to make a video.
I agree with the premise of what they say that people might think fingerprint is "super secure" while it is not...
But it is secure enough for most of the people and more secure that typing in PIN or short password or for people using 0000 or 1234 as PIN.
… is that they're treated as passwords instead of usernames. The three problems you list all have the biometric=password assumption in them.
See also using the American SSN usage: it's treated like a (secret) token, and so when it leaks it can be used to access sensitive information. Using it as 'just' a username would probably reduce a lot of problems as well.
Nothing like a secret token that can be reliably guessed using only your birth month+year and place of birth!
- The first set of three digits is called the Area Number
- The second set of two digits is called the Group Number
- The final set of four digits is the Serial Number
Certain geographic areas get certain "Areas Numbers", then Group Numbers are assigned consecutively, then Serial Numbers are assigned consecutively. This entire system of consecutive assignment makes it trivial to guess pretty well, or even exactly, what someone's SSN is.
From a security professional perspective, this is at least somewhat of an improvement, even if the entire thing feels like it's held together with a wish and a prayer. I would really like if there were a means to just institute an entirely new system. Essentially having one's entire life ruined, on the chance a bad actor can guess a four digit number is...not great.
From a genealogist perspective though, this is horrible news. Being able to trackdown people based off of rough geographic assumptions can help narrow down if someone is "lucky" enough to have a common name in a specific region. Of course, this change to SSN isn't nearly as disastrous as the death of paper - especially newspapers - but I really do not envy anyone who is going to try and do historical family research in two to three hundred years. It makes me cringe just to think about how much valuable information, how many life changing moments, are going to be lost to encryption, bit rot, and the constantly changing standards of software and hardware.
https://www.popsci.com/social-security-number-equifax-leak/ https://www.forbes.com/sites/suzannerowankelleher/2019/08/01...
I think the current crusade against passwords is primarily motivated by different providers to advertise their ID schemes. Even needing a cert for something like Github is too much for me. I have no high profile repos and it might be reasonable in those cases, but I hope MS doesn't repeat the mistakes they made with their API access. The logistics of authentication is far too complex.
Aside from that I have seen people handling their keys that make you wish they would just use a password and cert logistics isn't trivial at all. No, you should not copy your key to our corporate file server... This is just the nerd way of gluing your password under your keyboard.
In 2008. "fingerprint of then interior minister and current Finance Minister Wolfgang Schäuble" was sourced from a glass:
https://freerepublic.com/focus/f-news/1995935/posts
In 2014. "A speaker at the yearly conference of the Chaos Computer Club has shown how fingerprints can be faked using only a few photographs. To demonstrate, he copied the thumbprint of the German defense minister" Ursula von der Leyen
https://m.dw.com/en/german-defense-minister-von-der-leyens-f...
I don’t think this was intentional but they managed to demonstrate (or at least for-shadow) the incompetent police force of the future this way.
Can biometrics be spoofed? Absolutely. Is it likely to happen to the average person? Not at all. For a typical everyday user, a fingerprint or face scan is probably more secure than the common alternatives of "sticky note" passwords, easily guessed PINs, or no authentication at all.
Biometrics are a compromise between security and convenience. Before iPhones got Touch ID, it was not uncommon for people to just not put a lock on their phone out of convenience. Now it is impossible to find an iPhone out in the wild that is not fully encrypted. The average level of security on consumer devices that hold sensitive information has increased dramatically thanks to biometrics.
I believe biometrics aren't necessary to establish security and in the worst case reveal unnecessary information.
Isn't that what Cancelable Biometrics e.g. [0] is about [0] https://ieeexplore.ieee.org/document/7192838
You assume 'old' strictly implies outdated, or bad, which isn't true. E.g. good passwords are still undefeated. And security protocol redundancies surely can make intrusion impractical, even if individual components fail.
I assume, military hard- and software to be made meticulously, double checking everything, on literally battle tested chips and gear. I mean, I really had no contact with anything military ever, so that's a guess based on aircraft and space development, pictures of überfunctional UIs and the ridiculous finances of the US military.
I don't mean to diss W2k in general, Its an OS that is well understood by now - weaknesses, mitigations, etc. Slowmoving entities like the government accrue so much cruft that it makes it exceedingly difficult to move to newer (and possibly better) platforms to take advantage of newer security tech.
And for W2k, I wasn't merely suggesting it's well-tested, but also a different, better thing than say WindowsXP. At least, I got the impression operating systems folks reference it for a "many good ideas" kinda thing.
Sorry, I don't have any expertise in any of this and talk mostly out of my ass.
This obviously not as secure as a system when you must use your credentials frequently to maintain access, but it seems entirely appropriate for the level of security needed by most individuals on their phones. Especially as the alternative is often a super simple password or even no password at all. TouchID makes a moderate level of security palatable enough for people to actually use.
So far I haven't encountered a device where a fingerprint was used to unlock disk encryption, so your objection is actually implied, I think. Especially, with the increasing uptime of Apple's new hardware, a running session is what you more often than not got these days.
No matter how you twist it, biometrics are fundamentally flawed and not even Apple can magically fix that. At least one component of access needs to be a secret, which cannot be extracted without cooperation, or "cooperation".
- no shit, use public keys
- your 2FA can also be hacked
- your company forcing 2FA is insufferable like all modern web
- your KYC is literally pointless since i already gave those same ID photos to 100 different companies, few to none of which are competent enough to keep them secret
EDIT: huh, this is actually a good article. but it's still ironic since it's coming from a company that follows all the standard snake oil