Fingerprints can be recreated from the sounds made when you swipe a screen
tomshardware.com
tomshardware.com
"Entropy is a bitch"
Information's radiation speed is variable. Lightspeed is its upper limit.
Though yes, some leakage occurs at lightspeed. Fingerprint sound should be somewhat slower in most instances.
1: https://en.wikipedia.org/wiki/Electrical_network_frequency_a...
I'm wondering about this part though:
> The source of the finger-swiping sounds can be popular apps like Discord, Skype, WeChat, FaceTime, etc. Any chatty app where users carelessly perform swiping actions on the screen while the device mic is live.
Is there really enough information left for this method after the sound has been lossily compressed by any of those apps?
Biometrics are form of (dubious) in-person identification, and their use for access control belongs in the all-time stupidest ideas in computing list.
If you refuse to give them your password, there's virtually no limit to the possible extent of the torture. You can't prove that further torture is pointless.
/s
If you're browing with javascript on and without text-only, you're missing a lot on the web ;)
Like most security measures, biometrics are typically ‘good enough.’
True. Today. Tomorrow you will still have the same fingerprints.
Even if you cut large enough to create a scar, you'd just re-register the new print and you're (allegedly) vulnerable to this attack again.
Most of those require being loated in the same area and generally even at a similar time (for high use areas). This would be more like the photo attack where you can be located far away.
Can you imagine how much it costs to pick fingerprints from millions of users by your method?
Sound can be recorded over the internet. This enables web sites to identify users in a very cheap way by simply adding a slider and sound recording on a web page overlay: "Slide to unlock contents".
Smartphone security is not going to get better any time in the next decade.
All of which lends weight to my argument that biometrics as access control is the single most ignorant idea in the history of computing. I am genuinely hard pressed to think of anything dumber.
I'll also add that even if true, it's probably not a huge practical issue. Fingerprints are mostly used to secure personal devices: phones, sometimes computers. If I were to have your full fingerprints then that would be mostly useless because I don't have access to your physical device. Even things like "purchase on App Store with fingerprints" usually works by having the fingerprint only secure a key on the device itself (rather than sending the fingerprint data over the network).
And if you have access to your physical devices, then I almost certainly also have access to your fingerprints via the good ol' "dust for prints" technique.
There was a "fingerprints for everything!" push a decade or so ago, and that was harshly criticized because you leave fingerprints everywhere, and you can even lift them from photographs.
Certainly the "enormous economic and personnel losses, and even a potential compromise of national security" claim at the start of the paper seems rather exaggerated, even hysterical.
1 The low FAR (False Accept Rate) is unbelievably high at 0.01%
2 The "partial prints" are described as single or "mixed" minutia
The FAR is 1-2 orders of magnitude off of even cheap mobile device authentication.The described size of the partial prints imply that the relative location of partials is not extractable.
Since most fingerprint matchers rely on multiple (3-4) minutiae at a minimum and their relative location along with ridge orientation and pitch correlations it seems like this doesn't provide necessary information. More importantly, even with more information it can't construct that relative information, because it can't resolve symmetries (certainly not without knowing the direction of motion for the swipes and the orientation of the finger) correlated with those sounds. That requires other out of band information.
It's interesting work, but there's probably a reason that you don't see fingerprint matchers with decent FAR/FRR using only the microphone on a mobile device and some software. There are a $B reasons to develop that every year, and yet there hasn't been one developed for 15-20 years.
Then there's the fact that there are more than 20 minutia per finger so when referring to orientation, this means the angles and what portion of the finger is in contact with the touch surface... and thus which of those minutia (swirl, end, fork, etc) are in generating any sound.
Most people use their forefinger or a thumb to swipe, and their thumbs to match/type, and multiple fingers or both thumbs to scroll/zoom.
More interesting is that if one had full knowledge of a persons prints then perhaps with microphone, touch tracing, and wide angle video, one could compare expected vs measured sounds. This is a one-one confirmation rather than one-many match. Perhaps it could prevent long term usage after a person had unlocked their device and another was using it.
Some seem to be saying its not that bad from a personal credit card or phone unlocking thief perspective. However, my main concern is with large nation state groups that have access to pre-existing fingerprint database files.
There's something here that feels like the NSA, FBI, FSO/Spetssvyaz, 3/4PLA, Unit 8200, GCHQ, BfV, DGSE, CSE, TERM, and ISI would probably all have their "figurative" ears perk up.
E.g. Perhaps the toothbrush has a connectivity check to OralB servers that triggers once per hour, but you can change it to check a victim webpage once a millisecond.
Smart toothbrushes (and/or their docks) have little computers inside of them. Oral B smart toothbrushes offered an API eight years ago https://github.com/dukescript/dukebrush as well as a real-time web API: https://web.archive.org/web/20160310121235/https://developer...
All there would need to be is an exploit that allows someone to (1) identify and talk to the toothbrushes, (2) coerce the toothbrush to ping an arbitrary IP, and (3) cause step 2 to happen many times for just one trigger.
Of course. A good lie is defined by it being relatively believable. Re: the viability of the exploit, my understanding is that most smart toothbrushes do not connect to the Internet, and even if they did, the huge numbers originally presented in the story (3 million toothbrushes) are astronomically high.
See the second link, the "Web API" section. This is the part tells me that it's on the internet.
> WEB API
> The Oral-B cloud service offers fast and reliable real-time access to Oral-B brushing activity. Fetch brushing data ranging from session frequency and duration to activity stats, achievements and more. Integrate brushing activity data* with health or lifestyle applications.
I don't know about all the older models, but I know the latest Oral-B smartbrush connects directly to the internet using Wi-Fi.
In the end, the story's spread can be explained by a journalist's simple misunderstanding that made the story much more virulent.
In this case, the journalist probably also doesn't understand the technical details, but we have a link to the researchers' own write-up right there in the article, which makes it much easier to rule out simple misunderstandings. So the situation is completely different.
That said, they're not reconstructing the fingerprint ridges from the sound the way you're probably imagining. Instead, they build on an existing attack exploiting fingerprint readers' error tolerance with a set of "masterprints" that are unusually likely to be accepted as a match, and the sound is used to determine which masterprint to use first.
Bollocks, you're letting the "journalist" off way too easily. That toothbrush story was simply "a story too good to vet", meaning, sure, the author had a convenient excuse blaming it on a "misunderstanding", and while I don't believe the author was necessarily lying, I do believe they had no incentive to dig any more deeply because the toothbrush bot army story was already clickbait enough.
tl;dr: It was Fortinet's fault and they tried to cover it up: https://securityboulevard.com/2024/02/toothbrush-ddos-botnet...
Edit:why disagree? I bet you could even create textured screen protectors with randomized patterns to obfuscate they swipe.
I wonder how "partial" is defined.
But anyway, the fact that you can even hear any sounds of swiping feels odd to me. Is this just something Apple could filter out of the audio data it provides to applications? I know nothing about audio processing.
https://medium.com/@tomasreimers/axolotl-a-keylogger-for-iph...
I wonder if I'm in the lucky majority, and my fingerprints sound secure