An interesting article on fingerprint reader hack

Questions on how we spend our money and our time - consumer goods and services, home and vehicle, leisure and recreational activities
Post Reply
Topic Author
gavinsiu
Posts: 2187
Joined: Sun Nov 14, 2021 11:42 am

An interesting article on fingerprint reader hack

Post by gavinsiu »

I just saw this article:
https://arstechnica.com/information-tec ... d-devices/

The system apparently use a stolen databases of fingerprint to attempt to hack into phones.
User avatar
StevieG72
Posts: 1870
Joined: Wed Feb 05, 2014 8:00 pm

Re: An interesting article on fingerprint reader hack

Post by StevieG72 »

Interesting, apparently Face ID can be hacked as well.

https://www.techrepublic.com/article/ap ... 0at%20risk.
Fools think their own way is right, but the wise listen to others.
adamthesmythe
Posts: 5356
Joined: Mon Sep 22, 2014 4:47 pm

Re: An interesting article on fingerprint reader hack

Post by adamthesmythe »

Interesting, but not very interesting, because it requires that you (1) do something with bare chips and (2) wire something into the cell phone.
Topic Author
gavinsiu
Posts: 2187
Joined: Sun Nov 14, 2021 11:42 am

Re: An interesting article on fingerprint reader hack

Post by gavinsiu »

adamthesmythe wrote: Wed May 24, 2023 6:34 pm Interesting, but not very interesting, because it requires that you (1) do something with bare chips and (2) wire something into the cell phone.
Part of encryption is to prevent someone from accessing the content of your device should it be lost or stolen, so being able to bypass that without a large degree of investment is the problem.
Doctor Rhythm
Posts: 2146
Joined: Mon Jan 22, 2018 2:55 am

Re: An interesting article on fingerprint reader hack

Post by Doctor Rhythm »

For me, this fortunately fits nicely into the Venn diagram of “things I don’t worry about” and “things that are non-actionable.” Article also said that iPhones were basically immune because:

The ability of BrutePrint to successfully hijack fingerprints stored on Android devices but not iPhones is the result of one simple design difference: iOS encrypts the data, and Android does not.

Also, seems the mitigation strategy (disabling biometrics) is at odds with last month’s freak out about shoulder-surfing iPhone users when they enter a passcode, stealing the phone, and changing iCloud credentials.
Topic Author
gavinsiu
Posts: 2187
Joined: Sun Nov 14, 2021 11:42 am

Re: An interesting article on fingerprint reader hack

Post by gavinsiu »

Doctor Rhythm wrote: Thu May 25, 2023 6:10 pm For me, this fortunately fits nicely into the Venn diagram of “things I don’t worry about” and “things that are non-actionable.” Article also said that iPhones were basically immune because:

The ability of BrutePrint to successfully hijack fingerprints stored on Android devices but not iPhones is the result of one simple design difference: iOS encrypts the data, and Android does not.

Also, seems the mitigation strategy (disabling biometrics) is at odds with last month’s freak out about shoulder-surfing iPhone users when they enter a passcode, stealing the phone, and changing iCloud credentials.
Like other article I posted, this is more of information so you can prepare and evaluate what the risk is to you. I rather that people see what vulnerability are there and then make the decision to just ignore it because it is an unlikely event than to no know it and get surprised.

My thought is that this vulnerability is low. I rarely get into a crowd situation and then socialize much. I am currently not concern about it. However, the cost of hacking equipment is rather low, so I will be keeping an eye out to see if hacking fingerprint reader become a thing.
Post Reply