Debunking biometric assumptions

digg this!| | Comments (0) | TrackBacks (2)

Chris Hill's biometrics thesis:

This is a very interesting development. It challenges a key assumption that people have made about biometrics:

"that stored biometrics pose no threat to their owner (if they are stolen by another party), because it is not possible to recreate the original biometric from the stored data."

So, attackers can potentially bypass biometric systems in a couple of ways if they can compromise digital representations of biometric data (from storage or by sniffing, e.g. USB sniffer or keyboard sniffer): They can recreate new physical biometrics that will have properties indistinguishable from the original.

"I demonstrated that it is possible to recreate a biometric artefact that is equivalent to the original biometric provided to the system. This means that while a third party will not be able to generate the original biometric, they will be able to generate something that is indistinguishable from it, as far as the biometric software is concerned."

Adam Shostack also had some additional comments on this today, pointing out the privacy implications of such a breach:

The answer is you can reconstruct fingerprints from common systems.

Daniel David Walker referred me to some work by Andy Adler, who pointed
out Ross, Shah and Jain, "Towards Reconstructing Fingerprints from
Minutiae Points."[1]

[1] http://www.csee.wvu.edu/~ross/pubs/RossReconstruct_SPIE05.pdf

Some additional tidbits are on my blog at
http://www.emergentchaos.com/archives/001443.html

Imagine lost biometric passports allowing the creation of counterfeit passports with "real" biometric data on them. And further imagine trying to prove that it wasn't you who bombed that plane in Lebanon. "But we logged you going through security...and biometrics are _unique_ and _unforgeable_". *Shiver*

2 TrackBacks

Listed below are links to blogs that reference this entry: Debunking biometric assumptions.

TrackBack URL for this entry: http://juxtaposition.axley.net/blog-bin/mt-tb.cgi/206

Adam Sah (hi Adam!) has a great page of startup advice I hadn't seen before. Presentations from RECon are now online. The University of Connecticut will be offering a Masters in Homeland Security. That's a database I'd like to... Read More

Most biometric identification systems are worse than worthless. They are not secure, but give the illusion of security. Ask anyone in the crypto world about this: the false belief that you are secure is the greatest and most common weakness in any secu... Read More

Leave a comment

March 2011

Sun Mon Tue Wed Thu Fri Sat
    1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30 31    

«« December 2010

Sun Mon Tue Wed Thu Fri Sat
    1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30 31    

Archives

Contact: Jason Axley

Search Amazon:

Amazon Logo
Powered by Movable Type 4.1