FB pixel

Pen testing beats iris biometric USB data storage device via backup password

 

Iris biometrics-secured USB flash drive eyeDisk is not “unhackable” as it is claimed to be, as UK cybersecurity firm Pen Test Partners have discovered a way to break into the device without a spoof attack, according to a blog post.

Startup eyeDisk raised more than $21,000 in a successful Kickstarter campaign last year, promising data encryption. The soft spot, security-wise, however, turns out to be the backup password. Pen Test Partners researcher David Lodge says the device matched his iris biometrics about two-thirds of the time, and was not fooled by attempts to unlock it with his children’s eyes or a picture of his own. However, he discovered he could obtain the password in plain text with a traffic-sniffing software tool. The data is passed from the host and the device during the unlocking procedure, regardless of whether the user enters the correct password or an incorrect one. The same snapshot of sniffed data also contains a string which Lodge says may be the iris hash.

“The software collects the password first, then validates the user-entered password BEFORE sending the unlock password,” according to Lodge. “This is a very poor approach given the unhackable claims and fundamentally undermines the security of the device.”

Lodge disclosed the vulnerability on April 4, and eyeDisk responded immediately. The company acknowledged the communication and said it would provide a fix on April 9, but no further response was forthcoming, and Lodge publicly disclosed the information on May 9.

Lodge advises device users to stop relying on it for data security, or at least to further encrypt their data. He also says no technology is unhackable, though Infinity Optics developed a Biometric Cryptography platform earlier this year that it says has no error rate and, while revocable, cannot be hacked.

Article Topics

 |   |   |   |   |   |   | 

Latest Biometrics News

 

Stop treating identity as a compliance step. It’s infrastructure now

By Harry Varatharasan, Chief Product Officer, ComplyCube The UK governmentʼs digital identity consultation is closing, and for most commentators, this…

 

If you build it, they will leave: experts warn UK gov’t on digital ID approach

The UK Cabinet Office’s consultation on digital identity closed on Tuesday, Digital systems built by governments tend to decline over…

 

Shufti biometric PAD clears iBeta Level 3 with 0 errors across iOS, Android

London-based global identity verification and fraud prevention provider Shufti has passed a Level 3 evaluation of its biometric Presentation Attack…

 

OpenID draft spec for extended identity claims assurance up for approval

Voting is open for approval of a draft specification to extend OpenID Connect to cover new features for requesting and…

 

EES troubles ignite speculation of further suspensions

Crowds, chaos and cranky travelers: The EU’s biometric border management scheme, the Entry-Exit System (EES), continues to fill headlines as…

 

UK Home Office eyes suppliers for SCBP biometrics platform

The Home Office is hosting a preliminary market engagement event to engage with potential suppliers for two not-yet-guaranteed future procurements…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events