German Defense Minister's Fingerprint Copied by Chaos Computer Club
dw.de
dw.de
http://blog.dustinkirkland.com/2013/10/fingerprints-are-user...
You can change usernames as often as you wish. Kind of hard to do that with your fingerprint.
You can't even do that much with fingerprints.
And you can't reuse a fingerprint if an account that you use a fingerprint as the user account for has been compromised.
Say it worked like this:
You typed in your username, scanned your fingerprint for the rest of the username, and then typed a password / passcode?
That makes it virtually impossible to have username collisions (good) and still uses a password. If you were ultra paranoid, you could use a key fob such as a Yubikey and enter a OTP in addition to the above.
...But given the ease of getting someone's fingerprint I'm not sure if this is actually much better than a standard username+password combination (potentially with 2fa) without a fingerprint at this point, and it's less convenient to boot.
See, this is exactly the problem. It’s not at all useless. It’s a pretty great password that defends excellently against a few common problem points (random strangers just picking up your phone and playing with it, random thieves easily getting access in a way that would be convenient and worth it for them) while being completely invisible to me when using it (and actually making unlocking the device easier).
It’s rubbish against any kind of targeted attack, sure. Thing is, I personally don’t care about that at all. I couldn’t care less, really. So fingerprints are awesome for me and solve all the problems I want them to solve. I don’t care about perfect security. I don’t care about targeted attacks contingent on physical access to the device.
A fingerprint can be cloned and verified (visually) without giving the device a chance to do "defend itself", whereas even the best-case PIN attack* wouldn't necessarily exhaust possibilities before 10 tries.
I personally like the swipe gesture, as it is even somewhat resistant to a shoulder-surfing attack (assuming you're turned off horrendous default of drawing the pattern as you drag over it) and is much faster than typing a PIN.
* Excluding shoulder-surfing attacks. You know the digits (smudges have built up over them), but not the order.
[1] Especially if it is stolen. "I wasn't targeted. Was I targeted? Nah, I wasn't targeted. Just a crime of opportunity. Yes. For sure.".
So for me personally that is irrelevant.
However a finger print is significantly harder for a casual interloper to simulate.
Granted re:casual interloper.
And your friend just shoulder-surfed you, he didn't reverse engineer anything ;)
"Something you have, something you know, something you are".
Fingerprints are neither. As several people mentioned in this thread, the only thing I see a fingerprint suitable for is replacing a username.
It's great work, I hope the fact that you can make a copy from a simple HD photo will bury people's ideas about fingerprints security for good.
In my thinking about this problem from the IoT space lately, I've been thinking about servers assigning credentials to devices, rather than devices telling you their creds. Assign a UUID and let the device generate their password/key, and the pair gives you a multiplicatively large space.
Your notion is interesting. Anything that automates the client-side is good. People are terrible at managing a security contract 'by hand'
{edit} really, this superstitious notion that random numbers are 'not good enough' is embedded in our programmer culture. Folks continue to use lame solutions instead of just buying into the uuid-as-foolproof-identifier. It totally eliminates whole classes of problems and bugs. And you should be more concerned your computer will be hit by lightening, become self-ware and win the lottery 7 times, and molecularly reorganize into a teacup, before that uuid will be duplicated anywhere/anywhen.
Security is always done in layers, though, and while you're correct that it is extremely unlikely, the chance is nonzero. As such you have to prepare for that and design your system to be resilient to these types of things. In castle terms, you trust that no one will ever breach your wall, but that doesn't mean you don't have guards and an armory inside for the unlikely event it does.
EDIT: So does Kinect for Xbox one.
[1] http://support.xbox.com/en-US/xbox-360/kinect/auto-sign-in
[1] http://support.xbox.com/en-US/xbox-360/kinect/auto-sign-in
Biometric passports with fingerprint data are common in many EU countries. The fingerprint is used to verify a person's identity, so in a way it's used as both a username and password.
Allowing the state to capture and store something very private to every individual is not without controversy. A few years ago, a German man called Michael Schwarz had his application for a passport rejected when he refused to have his fingerprints taken. He took the matter to the European Court of Justice (ECJ). In October 2013, the ECJ ruled in favour of fingerprinting for passports. The ECJ agreed that fingerprinting was a privacy intrusion but that this was outweighed by the need for security and protection against fraud. Strictly speaking, the fingerprint data should only be held in the passport, not in a central database.
Whether you agree or not with fingerprint capture will probably be influenced by how much you trust the authorities in your country. And of course, many countries collect fingerprints from visitors entering their country.
I trust that if I had enemies that needed my fingerprint for something, that could get it easily. I touch enough objects on a daily basis that the likelihood is extremely high. I mean, someone could simply lift them from my front door, or follow me waiting for me to drop a coffee cup in the trash.
Therefore fingerprints are not a good tool when there is a lot of time for the attack, and the value is very high. However when the attack value is low, and the time available is short, they are currently a useful check.
One day, we will probably have a portable fingerprint cloner that changes the economics of this, but until we do, fingerprints are useful.
Since you dismiss biometrics as 'useless', what alternative would you suggest?
The barrier to break would be the "liveness check" - ensuring that you aren't presented with a molded prop, but an actual eye. I'm not sure what the state of the art is with respect to this.
The difference I see between fingerprint and retinal scan is that a fingerprint is readily visible - as this hack proves. I don't think you can capture a reliable retinal scan unless you get within centimeters of someone's eyeball with a scanner.
Additionally, since we're essentially talking about a specialized camera, the system could combine gait recognition (distance), face recognition (mid-distance) and finally retinal recognition (face on scanner). Beat that.
As always, authentication is just about authentication - you are who you "say you are". It has nothing to do with duress, etc.
actor plus doesn't allow for injury to the authentic person.
> face recognition (mid-distance)
photograph or prosthetics + makeup
> retinal recognition
photograph or prosthetic model iris built to beat "aliveness" check
None of these are hypothetical, all have been demonstrated (though perhaps not simultaneously)
To my knowledge the only biometric that hasn't yet been fooled or broken would be a scan of your brain whilst you invoke muscle memory of an action which itself is unknown to anyone but you. I wouldn't wager even that couldn't be scanned and copied in some manner.
[1] Which kind of makes the rest of the system moot. Also, good point about gait recognition.
It wouldn't need to be a real iris. Extant aliveness checks typically look for: reflections, pupil dynamics (contractions etc), frequency/resolution - these are all designed to look for digital forgeries (image on screen or paper); this leaves them open to a prosthetic model of an eye mimicking those effects (think a very sophisticated mannequin or doll's eye) backed by a generated retinal image.
Ultimately (if you want to talk absolutes) as long as the scanner can't differentiate between the original and a cloned + transplanted eye, it can never be considered unbeatable :)
As convoluted as all these sound, they're conceivably within the grasp of technology. It's worth remembering that many commercial scanners currently deployed don't implement any aliveness checks.
I was asking if you are aware of such a thing existing.
http://arstechnica.com/apple/2013/09/chaos-computer-club-hac...
Enhance.
From the article.