Other Diversions

security

politics

religion

technology

news

friends

Science / Skepticism


Powered by MT Blogroll

Latest Music

« Washington State Governor's Election Upheld! | Juxtaposition Home | Suspected Steganography lead to raising the terror alert in 2003 »

Debunking biometric assumptions

Chris Hill's biometrics thesis:

This is a very interesting development. It challenges a key assumption that people have made about biometrics:

"that stored biometrics pose no threat to their owner (if they are stolen by another party), because it is not possible to recreate the original biometric from the stored data."

So, attackers can potentially bypass biometric systems in a couple of ways if they can compromise digital representations of biometric data (from storage or by sniffing, e.g. USB sniffer or keyboard sniffer): They can recreate new physical biometrics that will have properties indistinguishable from the original.

"I demonstrated that it is possible to recreate a biometric artefact that is equivalent to the original biometric provided to the system. This means that while a third party will not be able to generate the original biometric, they will be able to generate something that is indistinguishable from it, as far as the biometric software is concerned."

Adam Shostack also had some additional comments on this today, pointing out the privacy implications of such a breach:

The answer is you can reconstruct fingerprints from common systems.

Daniel David Walker referred me to some work by Andy Adler, who pointed
out Ross, Shah and Jain, "Towards Reconstructing Fingerprints from
Minutiae Points."[1]

[1] http://www.csee.wvu.edu/~ross/pubs/RossReconstruct_SPIE05.pdf

Some additional tidbits are on my blog at
http://www.emergentchaos.com/archives/001443.html

Imagine lost biometric passports allowing the creation of counterfeit passports with "real" biometric data on them. And further imagine trying to prove that it wasn't you who bombed that plane in Lebanon. "But we logged you going through security...and biometrics are _unique_ and _unforgeable_". *Shiver*

TrackBack

TrackBack URL for this entry:
https://juxtaposition.axley.net/blog-bin/mt-tb.cgi/206

Listed below are links to weblogs that reference Debunking biometric assumptions:

» Small Bits: Adam Sah on Startups, RECon, Irony and Biometrics from Emergent Chaos
Adam Sah (hi Adam!) has a great page of startup advice I hadn't seen before. Presentations from RECon are now online. The University of Connecticut will be offering a Masters in Homeland Security. That's a database I'd like to... [Read More]

» Biometrics Suck from DRT
Most biometric identification systems are worse than worthless. They are not secure, but give the illusion of security. Ask anyone in the crypto world about this: the false belief that you are secure is the greatest and most common weakness in any secu... [Read More]

Post a comment

«« October 2007

Sun Mon Tue Wed Thu Fri Sat
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30  
Contact: Jason Axley

Search Amazon:

Amazon Logo