thewayne: (Default)
The Wayne ([personal profile] thewayne) wrote2023-05-24 04:55 pm

Interesting attack on smartphone fingerprint locks

This works against both Android and iPhone devices. However, Apple went to facial recognition a few generations ago, so you've got a much older iPhone if you're still using a finger print reader.

The attack is not quick and straightforward. It requires the attacker to have physical control of the devices and can take up to hours to execute. But it is quite clever!

The phone is partially disassembled and a chip is mounted onto the system board. A memory card with a database of fingerprint data is part of this attack system. The basics of the attack is quite simple: while you and I may not have identical fingerprints as far as a fingerprint expert is concerned, they might be similar. This attack exploits a vulnerability in the system and "...manipulates the false acceptance rate (FAR) to increase the threshold so fewer approximate images are accepted."

Meaning that if your fingerprint is similar to mine, and yours is in this fingerprint database, through this system your fingerprint might unlock my phone!

Now, one thing the manufacturers did to prevent multiple attempts at unlocking phones was to code in a hard limit as to how many unlock attempts that you get. This system TRIPLES that limit!

Pretty darn clever.

Now here's the killer: the parts to make this are about $15.

And the database of fingerprints? Biometric database breaches. Not difficult to obtain.

https://arstechnica.com/information-technology/2023/05/hackers-can-brute-force-fingerprint-authentication-of-android-devices/

https://it.slashdot.org/story/23/05/24/0435205/brute-force-test-attack-bypasses-android-biometric-defense
devilc: Go Like Hell (Default)

[personal profile] devilc 2023-05-24 11:42 pm (UTC)(link)
Gorrramnit.
There are reasons I avoid fingerprint readers, but I do have an older iPhone SE that I will be using as an iPod (no sim card) when I am forced to upgrade. It wants a 6 digit passcode and that's annoying and awkward to type in at times, so it's the only device I have a fingerprint on.

Sigh.
disneydream06: (Disney Shocked)

[personal profile] disneydream06 2023-05-25 12:12 am (UTC)(link)
The take away?
Keep hold of your phone. :o
Hugs, Jon
disneydream06: (Disney Shocked)

[personal profile] disneydream06 2023-05-25 12:12 am (UTC)(link)
The take away?
Keep hold of your phone. :o
Hugs, Jon
disneydream06: (Disney Shocked)

[personal profile] disneydream06 2023-05-25 09:12 pm (UTC)(link)
UGH!!!!!!!!!!!!!!!!!
disneydream06: (Disney Shocked)

[personal profile] disneydream06 2023-05-25 11:11 pm (UTC)(link)
WOWZA!!!!!!!!!!!!!!!!!!!!!!
That's crazy, but doesn't surprise me at all that China would do that. :o
bibliofile: Fan & papers in a stack (from my own photo) (Default)

[personal profile] bibliofile 2023-05-25 12:36 am (UTC)(link)
Reading the Ars story, I wonder how the difficulty it compares to faking the fingerprint? I recall stories about how easy that was to do using (of all things) gummy bears.

Still, a hack is a hack, and this is all very interesting.
gingeriana: (Default)

[personal profile] gingeriana 2023-05-25 05:58 pm (UTC)(link)
gummy bears?? whaat? 0_0
kaishin108: waves by hwm (Default)

[personal profile] kaishin108 2023-05-25 05:47 pm (UTC)(link)
How awful that it seems everything can be hacked, sigh.

I use facial ID and I know that could be problematic too. Argh!
gingeriana: (tankian chewing)

[personal profile] gingeriana 2023-05-25 06:03 pm (UTC)(link)
never used neither facial id, nor the fingerprint thing

i know at least three (not connected with each other) people who got dosed in bar (or beaten), and then those facial/finger identifications were used with their phones
and one of those guys, imagine that, had a mobile banking app which did not require ANY additional logins! so he lost all of his money in a matter of 5 minutes

NAAAH! you'd have to torture me the old-school way to get my password, sir! :)
captainsblog: (Lawyers)

[personal profile] captainsblog 2023-05-26 01:15 pm (UTC)(link)
I know you follow cryptoshit but couldn't find anything recent about it. I know nothing about it and stay away from it, but increasingly, bankruptcy clients have bitcoin assets (surprise! they're bankrupt) and I have to make sure they're disclosed. This item came across one of my BK news feeds this morning.


The jokes just write themselves: Bankruptcy Court approved the bid after subtracting 32 million from it and multiplying it by five-ninths.
silveradept: A kodama with a trombone. The trombone is playing music, even though it is held in a rest position (Default)

[personal profile] silveradept 2023-05-26 06:54 pm (UTC)(link)
Yet more reason not to use biometrics, I guess. Not that other methods also don't have their issues, but I suppose it's good practice of mine that I don't have any banking or payment apps or methods stored on my devices that can get stolen from me. There's still potentially sensitive information on it, and there are insecure 2FA methods that use my phone, so there's still potential risk.