Follow Slashdot blog updates by subscribing to our blog RSS feed

 



Forgot your password?
typodupeerror
×
Security Portables Hardware

Researchers Hack Biometric Faces 244

yahoi sends in news from a week or so back: "Vietnamese researchers have cracked the facial recognition technology used for authentication in Lenovo, Asus, and Toshiba laptops in lieu of the standard logon/password. The researchers were able to easily bypass the biometric authentication system built into the laptops by using photos of an authorized user, as well as by presenting multiple phony facial images in brute-force attacks. One of the researchers will demonstrate the hack at Black Hat DC this week. He says the laptop makers should remove the facial biometrics feature from their products because the vulnerability of this technology can't be fixed."
This discussion has been archived. No new comments can be posted.

Researchers Hack Biometric Faces

Comments Filter:
  • Ok then... (Score:5, Interesting)

    by going_the_2Rpi_way ( 818355 ) on Tuesday February 17, 2009 @09:39PM (#26896881) Homepage
    He says the laptop makers should remove the facial biometrics feature from their products because the vulnerability of this technology can't be fixed.

    If that's the standard, all security features should be removed. Everything is somewhat vulnerable, and a determined intruder with infinite resource will almost always find a way in. The object is to make this unreasonably hard for most applications.

    If you get your laptop lifted at the coffee shop, they better lift your wallet too I guess.
  • ... Wow. (Score:4, Interesting)

    by Valdrax ( 32670 ) on Tuesday February 17, 2009 @09:41PM (#26896905)

    The researchers were able to easily bypass the biometric authentication system built into the laptops by using photos of an authorized user [...]

    Tragically, sadly obvious. Not even a hack, really.

  • by HomerJ ( 11142 ) on Tuesday February 17, 2009 @09:44PM (#26896941)

    Even made a point of saying "facial recognition systems aren't all that secure. They can't tell the difference between a person and a photo of the person". Then he proceeded to break into the room by holding up a picture of someone that had access.

  • Re:Ok then... (Score:5, Interesting)

    by spleen_blender ( 949762 ) on Tuesday February 17, 2009 @09:55PM (#26897057)
    I don't comment that often but does anyone have any idea on the viability of stereoscopic facial recognition? Wouldn't that make a 3d model required to be presented to the input instead just a 2d one? Or two 2d images offset at the right angle for the distance from the cameras?
  • Re:Ummm... (Score:2, Interesting)

    by xwizbt ( 513040 ) on Tuesday February 17, 2009 @09:59PM (#26897111)

    My iPhone locks itself after a minute and demands a four digit passcode.

    It's not the perfect solution, I know, but I don't mind tapping a four digit key out on my keypad after a minute's inactivity on my Mac. Maybe 5. Maybe 10.

    That's enough - once you've stolen my Mac, you need to be with it every ten minutes... forever.

  • Re:hacking? Huh? (Score:2, Interesting)

    by davidsyes ( 765062 ) on Tuesday February 17, 2009 @10:05PM (#26897155) Homepage Journal

    Not for that. But they should be careful because they probably just pissed off a load of laptop and biometrics software manufacturers who will likely lobby for their being arrested if they land in the US, or if they commence their presentation.

    Haven't they heard of Russian and other national's programmers being arrested or threatened with arrest if they land here?

    But, if they are REALLY good, they've come up with a solution (for however long decent solutions can be expected to last...), and boost Vietnam's programmer prominence. They're doing not too shabby in the shipbuilding industry

    Vinashin:

    http://www.vinashin.com.vn/english/Capacity.asp [vinashin.com.vn]

    Hyundai-Vinashin:

    http://www.hyundai-vinashin.com/ [hyundai-vinashin.com]

    Maybe they can help out with the US TSA/TWIC/Port Security algorithms?

    But, if they get arrested, I don't think Vietnam will take this lightly. The US better go light on this one because if the biometric software touted as good enough for consumers is a fraud, or shoddy at best, then these programmers are nothing less and probably a little bit more than responsible whistleblowers in my book. Why stand by and watch vapor/failure/crapware enter the market if it can be headed off?

  • by Anonymous Coward on Tuesday February 17, 2009 @10:06PM (#26897167)

    Wonder if, when you 'enrolled' your face in the recognition software, you held your hand(s) up in the image forming a symbol -- peace sign, one finger salute, whatever. Then someone would have to capture your image at the instant you authenticated.

    It would be customizeable and and changeable, unlike your face, and hard to duplicate blindly.

  • by thethibs ( 882667 ) on Tuesday February 17, 2009 @10:10PM (#26897197) Homepage

    Of course they broke it. "Biometric Authentication" is an oxymoron. The correct phrase is "Biometric Identification". A face or a finger are a claim of identity that still needs authentication with some form of secure credential, e.g. a password.

    No Id and no authentication is "public". Id but no authentication is "public, but stupid about it".

  • one small problem (Score:2, Interesting)

    by westlake ( 615356 ) on Tuesday February 17, 2009 @11:02PM (#26897673)
    Tragically, sadly obvious. Not even a hack, really.

    if it is not an inside job - how does the thief get his photograph of the "authorized user?"

    when the sensor is a webcam - why not include motion or depth perception in the authentication process?

    if the camera is sensitive to infrared why not confirm that the heat signature of a live body is present as well?

  • Re:Ok then... (Score:3, Interesting)

    by Traxton1 ( 154182 ) <Traxton1@noSPAm.yahoo.com> on Wednesday February 18, 2009 @05:08AM (#26899845)
    Here's a high quality image of your face from your Facebook page. I mean, I'd have to join the Sacramento network, but its pretty easy if I wanted to.

    http://profile.ak.facebook.com/v224/628/60/s501905303_4113.jpg [facebook.com]

    I imagine macraig.homedns.org and vulcan tourist.info had pics too but you can't seem to keep them up. I like the cartoon image of you that you usually use though.

"Gravitation cannot be held responsible for people falling in love." -- Albert Einstein

Working...