Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Hackers Claim New Fingerprint Biometric Attack
Ann Harrison, SecurityFocus 2003-08-13

Two German hackers say they have developed a technique to defeat biometric fingerprint scanners used to authenticate electronic purchasing systems. Unlike an earlier fingerprint attack developed by the pair last year, this system creates latex fingertip patches designed to be used while under observation.

Comments Mode:
Hackers Claim New Fingerprint Biometric Attack 2003-08-14
Anonymous (2 replies)
on Superglue 2003-08-18
Trixter
Hackers Claim New Fingerprint Biometric Attack 2003-08-14
Irving Washington (1 replies)
Hackers Claim New Fingerprint Biometric Attack 2003-08-14
Michael (2 replies)
Hackers Claim New Fingerprint Biometric Attack 2003-08-16
Watching (1 replies)
Hackers Claim New Fingerprint Biometric Attack 2003-08-18
Roger
"...technology that is not easily defeated by such techniques..."

Maybe. Bear in mind that Matsumoto's attack (which this just basically replicates) used only $10 worth of materials, a couple of hours work, and an idea they came up with some afternoon with almost no prior knowledge of biometrics. It was NOT a sophisticated, high tech attack.

Nevertheless, it defeated capacative sensors as well as optical ones, and also fooled two "live finger" detectors.

In the past, the biometrics industry has left a bad taste in security professionals' mouths, with frequent extreme exaggerations of the capabilities of biometrics. In my opinion, claiming that a system is "not easily defeated" when no-one has actually tried sails dangerously close to doing so again. It would be more accurate to say "we are working on making these sorts of attacks harder".

Can I ask a question, Watching? Your post seems to me to have a slightly speculative tone. Has your organisation actually tried to replicate Matsumoto's gummy figure attack?

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/6717/21516#21516
Not really earth-shaking... 2003-08-18
Roger (1 replies)
Not really earth-shaking... 2003-08-19
rleroy (at) avantages (dot) com [email concealed]
nothing new 2003-08-18
Anonymous (2 replies)
nothing new 2003-08-20
Karel Mellen
nothing new 2003-08-20
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus