Researchers develop master fingerprints that can break into smartphones

researchers fool fingerprint sensor scanning feat
Image used with permission by copyright holder
The story goes that no two fingerprints are exactly alike, which makes them an excellent method for authentication. However, as researchers at New York University and Michigan State University have recently found, they’re hardly foolproof.

The team has developed a set of fake fingerprints that are digital composites of common features found in many people’s fingerprints. Through computer simulations, they were able to achieve matches 65 percent of the time, though they estimate the scheme would be less successful in real life, on an actual phone.

Recommended Videos

Nasir Memon, a computer science and engineering professor at New York University, explained the value of the study to The New York Times. Modern smartphones, tablets, and other computing devices that utilize biometric authentication typically only take a snapshots of sections of a user’s finger, to compose a model of one fingerprint. But the chances of faking your way into someone else’s phone are much higher if there are multiple fingerprints recorded on that device.

“It’s as if you have 30 passwords and the attacker only has to match one,” Memon said. The professor, who was one of three authors on the study, theorized that if it were possible to create a glove with five different composite fingerprints, the attacker would likely be successful with about half of their attempts. For the record, Apple reported to the Times that the chance of a false match through the iPhone’s TouchID system is 1 in 50,000 with only one fingerprint recorded.

Although Memon’s team’s findings may not pose a significant, immediate risk, they are the reason why tech companies aren’t satisfied with the status quo. Stephanie Schuckers, a Clarkson University professor, noted that the latest, most advanced systems attempt to detect the presence of a real person through methods like ultrasound and perspiration sensitivity. There are also newer methods of biometric authentication, like iris scanning and facial recognition, which are both featured on Samsung’s new Galaxy S8.

Ultimately, Memon said this didn’t damage his faith in using fingerprints for security too much, although he suggested phone makers consider forcing customers to use a PIN or password after the device is left idle for an hour.

Editors' Recommendations

Former Digital Trends Contributor
Adam’s obsession with tech began at a young age, with a Sega Dreamcast – and he’s been hooked ever since. Previously…
Google responds to complaints about Pixel 6 fingerprint sensor

Owners of Google’s new Pixel 6 smartphone have been complaining about the slow response time of its in-screen fingerprint sensor, or its failure to work at all.

That’s a real pain in the neck (or finger) when you’re left prodding the display in an increasingly desperate bid to access your new Google handset, with many owners ending up having to tap in their PIN.

Read more
How Apple’s tight ecosystem of products can undermine its own security

There’s an old belief that you can’t have both security and convenience, and that’s seen as especially true in your digital life. I’m sure Apple would dispute that assertion, pointing to things like Face ID as evidence it can do both.

Yet, as we've seen in recent months, there are actually times when Apple’s ecosystem, so tightly linked across its platforms, can actually undermine its own security. If your dwelling only has one locked door, it only takes one key to have access to the whole house.
Face ID, the iPhone, and the Apple Watch

Read more
Buying a quirky Asus phone can be tough. Here’s why it deserves a break

Asus hasn’t conformed to following market trends for several years now. It has embraced the niche, becoming master of gaming smartphones with the ROG Phone line, producing the most versatile selfie phone on the market with the Zenfone Flip phones, and has eschewed the big-screen trend to make a compact, high performance smartphone this year with the Zenfone 8.

Yet it still sometimes feels under appreciated, and its efforts to do things differently don’t always get the attention they deserve. Why? Despite being incredibly transparent about some aspects of its phone business, it’s not at all in one of the most important — when you can actually buy one. There is a good reason though, and understanding it will help understand Asus better.
Doing things differently
Asus spokesperson ChihHao Kung explained to Digital Trends in an email about Asus’s reasoning for doing things differently with its phones:

Read more