Slashdot Log In
Researchers Hack Biometric Faces
Posted by
kdawson
on Tue Feb 17, 2009 08:35 PM
from the face-off dept.
from the face-off dept.
yahoi sends in news from a week or so back: "Vietnamese researchers have cracked the facial recognition technology used for authentication in Lenovo, Asus, and Toshiba laptops in lieu of the standard logon/password. The researchers were able to easily bypass the biometric authentication system built into the laptops by using photos of an authorized user, as well as by presenting multiple phony facial images in brute-force attacks. One of the researchers will demonstrate the hack at Black Hat DC this week. He says the laptop makers should remove the facial biometrics feature from their products because the vulnerability of this technology can't be fixed."
Related Stories
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
hacking? (Score:5, Funny)
Re:hacking? Huh? (Score:2, Interesting)
Not for that. But they should be careful because they probably just pissed off a load of laptop and biometrics software manufacturers who will likely lobby for their being arrested if they land in the US, or if they commence their presentation.
Haven't they heard of Russian and other national's programmers being arrested or threatened with arrest if they land here?
But, if they are REALLY good, they've come up with a solution (for however long decent solutions can be expected to last...), and boost Vietnam's
Re: (Score:3, Informative)
Re:hacking? Huh? (Score:5, Insightful)
What planet have you been on for the last couple of years? Seriously.. which one?
This has nothing to do with tin-foil-hat paranoid delusions. The GP may have been referring to Dmitry Sklyarov, which another poster just mentioned to you. That was about Adobe. Adobe did/does have huge flaws in it's software and Mr. Sklyarov came to the U.S to demonstrate that Adobe's representations of security were basically just fluff. He was arrested, and it was a HUGE deal.
This is not the only instance either. Anytime somebody dares to demonstrate how a security technology may be flawed those affected companies are using the DMCA and the corrupt/broken legisilative/judicial system to quash any dissemination of data that would reveal their products are snake oil.
Just awhile back there was a posting here on /. where a group of university kids (MIT) were involved in a lawsuit to suppress information they uncovered involving vulnerabilities in another security system.
There are plenty of examples where security is proven to be worthless and those affected financially have resorted to corrupt influences in the government to suppress the information and punish those involved with arrest.
These things I have mentioned to you are not delusional. I would suggest you educate yourself with the facts before accusing somebody of just being paranoid. Especially, since the GP was referring to something factual.
Parent
Re: (Score:3, Informative)
You want me to get my facts straight? Ummm, OK.
What situation are you referring to in the first place? I also don't understand the difference between reverse engineering code and demonstrating the function of intact code. Both would seem to me to have the same goal, which is to demonstrate that the intended goal of the software is f
Re:hacking? Huh? (Score:5, Informative)
Here's an up-to-date partial list of security researchers who have been threatened with legal action for releasing research on security vulnerabilities:
http://attrition.org/errata/legal_threats/ [attrition.org]
It should give you an idea of why people are concerned.
Parent
Re:hacking? Huh? (Score:5, Insightful)
Parent
Re:hacking? (Score:5, Funny)
Parent
Re:Terrible News! Please read! (Score:4, Insightful)
I can't understand the mindset that people must have to actually post trollish crap like this under their username.
It boggles the mind that we as a society are producing a generation of kids that actually takes pride in being anti-social and disruptive. Yet we have the arrogance to wage wars in an effort to make other nations emulate our social paradigm.
Perhaps it's not them that needs liberating from dictatorial governments, it's us that needs liberating from a downward spiral into social implosion.
Yes, yes I'm ready for the off topic mods now.
Parent
Ok then... (Score:5, Interesting)
If that's the standard, all security features should be removed. Everything is somewhat vulnerable, and a determined intruder with infinite resource will almost always find a way in. The object is to make this unreasonably hard for most applications.
If you get your laptop lifted at the coffee shop, they better lift your wallet too I guess.
Re:Ok then... (Score:5, Funny)
Everything is somewhat vulnerable, and a determined intruder with infinite resource will almost always find a way in.
The point is facial recognition alone is so vulnerable! All you need is a cameraphone and a photo printer - and you can't revoke your face as your password either. At least with fingerprints you can get hacked nearly 10 times (on average) before it becomes a problem.
Parent
Re: (Score:3, Funny)
Ummm... balaclava the headwear, not baklava the tasty Greek pastry! I guess you can still wear bakclava for your wife, if that will help, but maybe not in public.
Re: (Score:3, Funny)
Assuming that's the ONLY place you're wearing it, that is.
The Internet? (Score:5, Insightful)
Just sayin'.
Parent
Re: (Score:3, Funny)
If you've ever posted a photo of yourself on Twitter, Facebook, Myspace, a blog, or your website, people can easily get a high-quality photo of you without you knowing it.
You've seen a high quality photo on Facebook?
Re: (Score:3, Interesting)
http://profile.ak.facebook.com/v224/628/60/s501905303_4113.jpg [facebook.com]
I imagine macraig.homedns.org and vulcan tourist.info had pics too but you can't seem to keep them up. I like the cartoon image of you that you usually use though.
Re:Ok then... (Score:5, Insightful)
I definitely disagree here. While passwords can be brute forced given enough time, your face is almost certainly available to someone who has access to get at your computer.
There is a difference between identification and authentication (your claim of who you are, and your proof of that claim). What you look like is identification.
Parent
Re:Ok then... (Score:4, Insightful)
While passwords can be brute forced given enough time, your face is almost certainly available to someone who has access to get at your computer.
Also, you could say that face recognition is just as secure as writing a reasonably long password on your forehead. Someone takes a picture and boom. Access.
Personally, I refrain from writing my passwords on my forehead - regardless if I can see a suspicious-looking character taking a picture of me square-enough in the face to capture all the digits. And, I also refrain of using or buying face recognition devices...
Parent
Re: (Score:2)
There is no need to take your wallet, most mobile phones have cameras in them that could be used to get a photo of your face.
1. Walk into cafe looking for a target
2. Photograph the target's face
3. Steal the targets laptop
4. Profit
Re: (Score:2)
More to the point, you could use something like an Iphone with a DB of randomly generated photos until it cracked. This is what the researchers here did. This is the real vulnerability. But it's brute force attack, and on any proper 'secured' system it would have to be one of several.
Re:Ok then... (Score:5, Insightful)
Parent
Re: (Score:2)
Everything is somewhat vulnerable, and a determined intruder with infinite resource will almost always find a way in. The object is to make this unreasonably hard for most applications.
With the ubiquity of digital cameras, "determined intruder with infinite resource" no longer includes "scumbag with camera".
As such, this security feature seems particularly useless.
Re:Ok then... (Score:5, Insightful)
If that's the standard, all security features should be removed. Everything is somewhat vulnerable, and a determined intruder with infinite resource will almost always find a way in. The object is to make this unreasonably hard for most applications.
Not quite. Biometrics are horrible for security, because 1. they're not secret, 2. they're not easily replaceable. Once they have a picture of you, facial recognition is broken. Once they have your fingerprint, that's broken as well.
Once they have your password, you choose another one and that's it. I'd like to see you do that with your face.
Parent
Re: (Score:2)
I take your point, but I don't understand the either/or philosophy of security. Besides, in most cases that matter, once they have your 'password', they have you. Period.
To me, security is all about layering anyways. Adding a biometric layer that works well for the user (i.e. effortless) and typically involves a brute force attack to defeat? Why not?
Re:Ok then... (Score:5, Insightful)
Parent
Re: (Score:3, Insightful)
So based on this argument, card + code is just as secure as card + code + fingerprint. The fingerprint step is there to make you feel safe rather than really make you safe.
Re: (Score:3, Insightful)
Biometrics are one part of a good authentication system. But there are always trade-offs: to lower FRR (False Reject Rate, or rate of false negatives) you have to raise FAR (False Accept Rate, or rate of false positives). Iris and fingerprint recognition are mature technologies; they can deliver low false negatives with virtually no false positives. There are well-defined and effective ways of preventing spoofing. But yes, they are only a single component, and should be combined with password and/or phys
Re:Ok then... (Score:5, Insightful)
Iris and fingerprint recognition are mature technologies; they can deliver low false negatives with virtually no false positives.
Passwords deliver 0% false negatives and 0% false positives. If it rejects you, just type it again.
There are well-defined and effective ways of preventing spoofing.
Like what? A hash of my whole eyeball?
Anyway, nice job twisting my point. Let me repeat:
1. Not secret. Unique, but not secret. Which means, if someone gets the technology to spoof one, they can spoof all. What, fingerprints? They use them to catch criminals because we leave them all over the place.
2. Not replaceable. If you find out someone can spoof your iris, what do you do? Grow new ones?
Just because the technology isn't available yet, don't assume it never will be.
There is only one thing that biometrics add to security: noone has to tell the Big Boss he can't juse his initials as password anymore. Apparently it's worth it.
Parent
Re:Ok then... (Score:4, Funny)
Maybe its time I got in touch with that bully I knew in kindergarten. He seemed to have a natural gift in that area.
He had two faces?
Parent
Re: (Score:2)
Now do you see how this could be a real problem? And yes, C-level's love biometric stuff because they don't have to remember passwords.
Re: (Score:2)
Instead of thinking about this in the sense of some random hacker trying to get into your computer, think about the more probable situation of your office. Do you have, or could you easily get a good face shot of the CEO of your organization?
A picture of the CEO? Like the picture of the CEO that's on just about any company's website?
Nearly impossible to get at is my guess.
Re: (Score:3, Funny)
And yes, C-level's love biometric stuff because they don't have to remember passwords.
They should just all get Ident-i-Eeze cards.
Re:Ok then... (Score:5, Interesting)
Parent
Re: (Score:2)
You see kids, this is just another reason why you need *layered* security. Biometrics, PKI, keyfobs, enryption, uids/passwords, alone they all suck. When you start using them in combination, *then* you start putting up reasonable barriers to would be adversaries.
Ummm... (Score:4, Insightful)
Re:Ummm... (Score:4, Funny)
Heh, if you have physical access the game is over. "Lock your terminal" is merely a poor defense against bored pranksters (beating their head in if they touch your machine is the only effective deterrent).
Parent
Re: (Score:2)
Heh, if you have physical access the game is over. "Lock your terminal" is merely a poor defense against bored pranksters (beating their head in if they touch your machine is the only effective deterrent).
Lets say that the terminal only gives you a remote desktop on a secure remote system, and your credentials are required to authenticate.
Re: (Score:3, Insightful)
Re: (Score:2, Interesting)
My iPhone locks itself after a minute and demands a four digit passcode.
It's not the perfect solution, I know, but I don't mind tapping a four digit key out on my keypad after a minute's inactivity on my Mac. Maybe 5. Maybe 10.
That's enough - once you've stolen my Mac, you need to be with it every ten minutes... forever.
... Wow. (Score:4, Interesting)
The researchers were able to easily bypass the biometric authentication system built into the laptops by using photos of an authorized user [...]
Tragically, sadly obvious. Not even a hack, really.
Last season in Burn Notice (Score:4, Interesting)
Even made a point of saying "facial recognition systems aren't all that secure. They can't tell the difference between a person and a photo of the person". Then he proceeded to break into the room by holding up a picture of someone that had access.
Re:Last season in Burn Notice (Score:4, Insightful)
Parent
I'm against facial recognition because... (Score:3, Insightful)
Gesture + facial recognition (Score:4, Interesting)
Wonder if, when you 'enrolled' your face in the recognition software, you held your hand(s) up in the image forming a symbol -- peace sign, one finger salute, whatever. Then someone would have to capture your image at the instant you authenticated.
It would be customizeable and and changeable, unlike your face, and hard to duplicate blindly.
Re:Gesture + facial recognition (Score:5, Insightful)
...and carries the same level of security as speaking your password every time you type it.
Seriously, biometrics are a bad idea, unless also combined with other methods of authentication.
Parent
Stereo cameras and multiple pictures (Score:2)
You expect us to be surprised? (Score:3, Interesting)
Of course they broke it. "Biometric Authentication" is an oxymoron. The correct phrase is "Biometric Identification". A face or a finger are a claim of identity that still needs authentication with some form of secure credential, e.g. a password.
No Id and no authentication is "public". Id but no authentication is "public, but stupid about it".
Mythbusters & fingerprint recognition (Score:3, Insightful)
Well, Mythbusters got past fingerprint recognition systems with a Xerox and a Sharpie (after getting the fingerprint off of a can or glass, IIRC). My comment at the time to the group I was watching it with was approximately "I hope their stocks drop hugely tomorrow".
well sure (Score:3, Insightful)
Re: (Score:3, Insightful)
> If it can be defeated with a 2D picture, why not up the ante and ensure that the target
> is 3d by scanning it with a cheap laser?
Because the whole point was to offer biometric identification without spending any money on hardware. The camera was already there.