7 ms·
Fake fingerprints can imitate real ones in biometric systems
- AstralStorm 8y agoWhat I don't like about the abstract is that it does not say what this is good for. This thing is designed to fool ANN and adaptive systems as used in certain kinds of biometrics e.g. pictures.
- tree_of_item 8y agoIt seems to be pretty clear that it is related to fingerprint recognition systems. I'm not sure what you mean.
- Phemist 8y agoThe usual approach to spoofing fingerprints is by somehow acquiring a latent fingerprint from a "genuine" user, creating a mold from this latent fingerprint through e.g. [1], and then applying the mold to the fingerprint sensor. What these authors previously showed is that you can create a "masterprint" on a representation (feature vector) level that "averages" a lot of fingerprints together, creating something that is usually quite close to any individual's fingerprint, and thus is able to fool recognition software quite often. In practice, this would require an attacker to by-pass the sensor and feature extractor parts of a biometric system, and inject their masterprint feature vectors directly into the biometric comparator (one that compares the current sample, to a template derived from previously enrolled samples). Considering these systems are usually tightly integrated, this is quite a hard attack to do. What the authors now present is a way to generate "DeepMasterprints". These are actual images that can be used to create molds such as [1], and can be applied to any fingerprint sensor that doesn't have a sufficient Presentation Attack Detection(PAD) mechanism (Hint: supposedly most PADs on smart phones are easy to by-pass, same thing for older fingerprint sensors). For these spoofs attacks, the difficult part was actually getting a high quality print off the genuine user.. but now it turns out this isn't really necessary and you can use a "deepmasterprint" to get a high enough chance of being mistaken for _any_ genuine user. [1] http://www2.washjeff.edu/users/ahollandminkley/Biometric/index.html http://www2.washjeff.edu/users/ahollandminkley/Biometric/ind...
- baalimago 8y agoYou only get one set of fingerprints. If you use this as a master key, and someone else gets a hold of your fingerprints, you're vulnerable for the rest of your life. Not very secure.
- xoa 8y agoNo, that is just not how "secure" works, you need to take into account all the details of the system in question and the threat model. Usually biometrics is not being used alone, there is an actual master password and the biometric authentication is being combined with a physical token as a shortcut/proxy. Someone "getting ahold of your [fingerprints|eyeballs|face|internal chip|whatever]" and the physical "token" (smartphone being the most common) amounts to a targeted physical attack, which is a very difficult class to deal with but also not scalable. Don't count on any naive or technical only method to defeat this: passwords may well be worse because in any non-physically secure setting it's far more trivial to shoulder surf a passcode entry then to grab biometrics and seize the token. Furthermore most people are simply unwilling (with good reason) to deal with an appropriately complex passcode in constant usage on the go, so it's a case of biometrics+complex password taking the place of say a 6 digit PIN. It seems like every single HN thread on biometrics somebody comes in to proclaim for the nth time that "finger prints aren't passwords!!" or something of that nature, as if "something you know/something you have/something you are" haven't long been known and considered as basic building blocks of authentication with various tradeoffs vs different threat scenarios. Your kind of oversimplification is not helpful given that it can actively harm real world security, which requires amongst other things actually working with how actual humans really are and making the right economic tradeoffs.
- wlesieutre 8y agoI would say biometrics is “usually” used in phones where it’s used completely on its own to unlock them. You might still need a PIN to install an OS update, but that won’t keep someone from going through all of your photos and emails.
- xoa 8y ago
- mulle_nat 8y agoI used to have stacks of these yellow sticky notes with my password printed on it. I ensured, that whereever I went, I would stick one of them to anything I touched, so I'd have it ready just in case. Thanks to fingerprint biometrics I can do this now just as well without even having to buy sticky notes.
- xoa 8y ago>I ensured, that whereever I went, I would stick one of them to anything I touched, so I'd have it ready just in case. Indeed, sticky notes with a password printed on them stuck around where they'd be needed is exactly what my very intelligent grandmother, doctor, and likely tens if not hundreds of millions of other people do worldwide. Often to comply with "good password policies" passed down from on high by thoughtless "security" technical people with zero appreciation or empathy for the actual humans they exist to serve and thus with minimal understanding of what "good security" actually means. Said sticky notes are quite trivial for any random passerby who possesses mildly functioning Mark 1 Eyeball(s) (only a single one is required!) to note. Turns out it's even easier then pulling a fingerprint or face/retina scan and turning it into something workable that can beat a good PAD and then stealing the device it's used with. Who'd have thought? Oh wait, maybe you were trying to be sarcastic there and make some point? I think you might in fact have made a point, but perhaps not quite the one you intended.
- Fnoord 8y agoYour grandmother, doctor, etc are not aware they can use a password manager with a master password such as "dandy-pencil-colonist-precise-populate-stardom" which would be more difficult to crack than finding and copying a fingerprint on your device. Its only a matter of time until one of these is cracked, and with touchID and faceID they're going to get cracked before said password is cracked. PS: Just a piece of advice, your tone throughout this thread isn't going to convince anyone. On the contrary.
- xoa 8y ago>Your grandmother, doctor, etc are not aware they can use a password manager with a master password such as "dandy-pencil-colonist-precise-populate-stardom" They are. My grandmother in particular cannot handle such a thing. At all. This exactly the sort of dismissive tech myopia that comes from people who get too deep into the tech trenches and lose sight of huge swaths of the general population. It's very easy to take for granted the huge amounts of meta knowledge and mental models of abstract systems people like us possess. With those as frameworks lots of things make total sense that are utterly confusing to those without them, even ignoring sensory trouble. >which would be more difficult to crack than finding and copying a fingerprint on your device. Really? Seems a lot easier: there that person is hunting and pecking (you don't think touch typing even is universal do you?) in public, hard of hearing and totally focused on that, while someone else stands behind them and just watches. Even assuming there are no cameras looking down of any kind around of course. Using words like you suggest makes it even easier, if you know each section is a real word then even missing parts will make it easy to fill in the blanks, heck just hearing it would be plenty to narrow the search space. Or how about using WiFi transmissions directly to recognize keystrokes ("Keystroke Recognition Using WiFi Signals": https://www.sigmobile.org/mobicom/2015/papers/p90-aliA.pdf https://www.sigmobile.org/mobicom/2015/papers/p90-aliA.pdf )? >Its only a matter of time until one of these is cracked, and with touchID and faceID they're going to get cracked before said password is cracked. Uh-huh, sure thing. That's why we read all the time about the vast gangs using harvested finger prints and 3D face scans to unlock iPhones, but have never read about shitty PINs getting brute forced or people reusing passwords or password reset mechanisms getting abused because people forget them all the time or password databases getting leaked or...? Yeah, passwords are certainly the best! >PS: Just a piece of advice, your tone throughout this thread isn't going to convince anyone. On the contrary. Right back at you. Your comment comes across as a typically dismissive, smug put down of the needs and requirements of large portions of the our fellow humans who do amazing things but just not in our specialty. And it's an attitude that has actively harmed security.
- loourr 8y agoThis seems pretty obvious. Anything static is forageable and hence vulnerable. Bio can add complications (is this fingerprint warm and pulsing?) but ultimately all will be overcome.
- pvaldes 8y agoHum, about fingerprints as keys to store valuable and personal things. What happens if tomorrow I would suffer a car accident and 'lost' my key? or have a new scar hiding a part of my key? Would be locked out forever? Or how to explain a machine that will keep asking for my 'real key', the concept of a wasp's sting for example?