2 ms·
IMO the root cause is that the fingerprint sensor is a black box and just sends an "OK" to the OS. So you have to take extra care to authenticate the sensor or
by captainmuon 3y ago
IMO the root cause is that the fingerprint sensor is a black box and just sends an "OK" to the OS. So you have to take extra care to authenticate the sensor or you are open to attacks like this. The developers were trying to be extra clever and to make sure the OS never sees the fingerprint. I think I would have prefered the KISS solution of the sensor sending the fingerprint (or maybe just a digest) to the OS and have the OS compare.
I'll take a solution that is in principle a bit less secure, but easier to understand, write drivers for, and not a cryptographic lockdownfest, over a solution that is theoretically safer but fails when not implemented 100% correctly.