FB pixel

Hack of Samsung Galaxy S10 ultrasonic fingerprint sensor suggests no liveness detection

 

The ultrasonic biometric fingerprint scanner on a Samsung Galaxy S10 has been hacked with a 3D-printed copy of the phone owner’s thumbprint taken from a photograph of a latent print on a wine glass, Forbes reports. A security researcher going by the handle darkshark on Imgur says the technique could be replicated to steal latent prints from a distance and break into a stolen smartphone, as well as biometrically-secured accounts.

The researcher used the photograph to create an alpha mask in Photoshop, and then rendered it into 3D using 3ds Max software. The fake print was printed with an AnyCubic Photon LCD resin printer with 10 micron-accuracy in 13 minutes, and with three attempts to set the correct ridge height, a fake was generated which consistently opens the flagship Samsung smartphone.

The ultrasonic sensor is supposed to detect liveness by sensing blood flow, which darkshark points out seems not to be the case, perhaps due to changes made when Samsung updated the software for the in-display sensor to deal with performance issues a few weeks ago. The face authentication system of the Samsung Galaxy S10 has also been criticized as too easy to hack after images from the web or of siblings were found to unlock the device.

“The whole biometric authentication movement at consumer level of electronics is never going to be very secure” Ian Thornton-Trump, head of cybersecurity at AmTrust Europe told Forbes. “I’m not a fan of facial recognition, voice recognition or fingerprint authentication but consumers are and that’s not a bad thing.”

The same researcher said in a Reddit thread that the ultrasonic scanner is probably safer than other sensor types, and noted that some optical sensors can be spoofed with a paper printout.

Article Topics

 |   |   |   | 

Latest Biometrics News

 

WTTC puts biometrics, digital identity at center of travel agenda

The World Travel & Tourism Council (WTTC) has laid out eight strategic priorities to guide its decision making for the…

 

Humanity Protocol key storage error, malware infection lead to massive token breach

There is no indication that the palm biometrics “Proof-of-Trust” nee “Proof-of-Humanity” startup Humanity Protocol uses for identity verification have failed….

 

Digital trust under threat from advanced fraud, AI agents: BioCatch

The digital world has consumed us; “being online” is no longer optional. As such, the importance of digital trust has…

 

Ireland body camera bill prompts debate over use of recorded footage

Gardaí are preparing a €150 million nationwide rollout of body-worn cameras as the use of biometric data in day-to-day policing…

 

Wrongful arrest based on false FRT match sparks lawsuit from Florida man

Another case of wrongful arrest after a false match by facial recognition software has given more ammo to those fighting…

 

Report finds synthetic identity fraud becoming biggest fraud threat in 2026

Synthetic identity fraud is fast becoming one of the biggest threats facing financial institutions, according to new research from Mitek…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events