3 ms·
https://www.schneier.com/crypto-gram/archives/2002/0515.html#5 https://www.schneier.com/crypto-gram/archives/2002/0515.html... "He used $10 of ingredients you
by zwp 10y ago
https://www.schneier.com/crypto-gram/archives/2002/0515.html#5 https://www.schneier.com/crypto-gram/archives/2002/0515.html...
"He used $10 of ingredients you could buy, and whipped up his gummy fingers in the equivalent of a home kitchen. And he defeated eleven different commercial fingerprint readers, with both optical and capacitive sensors, and some with "live finger detection" features."
That article's a little old now and the tech may well have improved since but I wouldn't put too much faith in fingerprint readers. (Also: other attack vectors exist).
- dogma1138 10y agoThe sensor is pretty good at detecting real finger since it's tuned to the capacitance of human skin, possible to fake but not particularly easy. If they'll move to the new optical sensors the the refracted IR ones can sense the flow of blood in the veins of your finger.
- vog 10y agoThey (including Apple) told us once too often that their new fingerprint sensor will now really, really, finally solve all issues. With every new generation they tell us that all flaws of all previous generations have been solved. And once too often, they we proven to be wrong. So I agree with zwp (not sure why he was downvoted): I wouldn't put too much faith in fingerprint readers.
- arnarbi 10y agoMy point is that this is still more expensive than harvesting knowledge factors with phishing and stealing dbs where people use the same factors.