Skip to main content
  1. Home
  2. Phones
  3. Mobile
  4. News

Researchers develop master fingerprints that can break into smartphones

Add as a preferred source on Google

The story goes that no two fingerprints are exactly alike, which makes them an excellent method for authentication. However, as researchers at New York University and Michigan State University have recently found, they’re hardly foolproof.

The team has developed a set of fake fingerprints that are digital composites of common features found in many people’s fingerprints. Through computer simulations, they were able to achieve matches 65 percent of the time, though they estimate the scheme would be less successful in real life, on an actual phone.

Recommended Videos

Nasir Memon, a computer science and engineering professor at New York University, explained the value of the study to The New York Times. Modern smartphones, tablets, and other computing devices that utilize biometric authentication typically only take a snapshots of sections of a user’s finger, to compose a model of one fingerprint. But the chances of faking your way into someone else’s phone are much higher if there are multiple fingerprints recorded on that device.

“It’s as if you have 30 passwords and the attacker only has to match one,” Memon said. The professor, who was one of three authors on the study, theorized that if it were possible to create a glove with five different composite fingerprints, the attacker would likely be successful with about half of their attempts. For the record, Apple reported to the Times that the chance of a false match through the iPhone’s TouchID system is 1 in 50,000 with only one fingerprint recorded.

Although Memon’s team’s findings may not pose a significant, immediate risk, they are the reason why tech companies aren’t satisfied with the status quo. Stephanie Schuckers, a Clarkson University professor, noted that the latest, most advanced systems attempt to detect the presence of a real person through methods like ultrasound and perspiration sensitivity. There are also newer methods of biometric authentication, like iris scanning and facial recognition, which are both featured on Samsung’s new Galaxy S8.

Ultimately, Memon said this didn’t damage his faith in using fingerprints for security too much, although he suggested phone makers consider forcing customers to use a PIN or password after the device is left idle for an hour.

Adam Ismail
Former Contributor
Adam’s obsession with tech began at a young age, with a Sega Dreamcast – and he’s been hooked ever since. Previously…
Vivo X300 FE review: The compact flagship I didn’t expect to like this much
The Vivo X300 FE is the Hawkeye of flagships. It doesn't have superpowers, but somehow gets the job done better than everyone else.
Vivo X300 FE

Why Hawkeye?

Hawkeye was never the strongest Avenger, nor did he have the flashiest suit or superpowers. Yet he consistently proved his worth through precision, reliability, and doing the fundamentals exceptionally well. The Vivo X300 FE follows the same philosophy. It doesn't chase outrageous specifications or marketing gimmicks. Instead, it quietly nails the essentials with a superb display, dependable performance, excellent cameras, and outstanding battery life. It may not grab all the headlines, but when it matters, it's the flagship that gets the job done.

Read more
7 Apple Notes tips to elevate your note-taking experience
A few small tweaks buried in the menus that make Apple Notes feel like a completely different app.
Apple notes on iPhone

Over the years, Apple has turned Apple Notes into one of the best note-taking apps for the iPhone. The problem is that most people use the app just as a place to dump info and do not use it to its full potential. Today, I will share seven of my favorite Apple Notes tips that will elevate your note-taking experience. 

Switch between recently opened notes

Read more
This Android lock screen bug lets anyone text using Gemini without knowing your PIN
Google confirms a fix is coming for this risky Gemini lock screen bug
google-gemini

Your Android lock screen is supposed to keep your messages safe, even if someone gets hold of your phone. But a newly discovered Gemini bug could do the opposite. Since May, The Register has received multiple reports of people bypassing device authentication on Android 16 devices that allow Gemini access straight from the lock screen.

The flaw lets anyone use Gemini to send SMS and even WhatsApp messages without ever entering your PIN. It only works under specific conditions, but it is serious enough that Google has confirmed a fix is already rolling out.

Read more