FB pixel

Biometric exploits aren’t on the horizon; they’re in the backyard

Biometric exploits aren’t on the horizon; they’re in the backyard
 

The biggest threat to widespread use of biometrics in security is public distrust and the inability of the industry and government to address that distrust.

But that is today. Cybersecurity firm Intel 471 says that cybercriminals — precisely the people biometrics was supposed to put out of business — have already begun defeating systems. Their activity still is in its “infancy,” according to Intel 471.

A missive published by Intel 471 says that criminals “have learned to exploit vulnerabilities in facial and fingerprint recognition software.”

They have gained access to a device and then, of course, explained to their community how to defeat behavior-based anti-fraud software.

In September 2020, the company’s analysts reportedly “observed” a pair of Iranians trying to sell ID documents, some of which held biometric data.

One of the suspects claimed to have 76,000 national codes and biometric national ID cards originating in the United States and 10 other countries, including India, Brazil, Saudi Arabia, South Korea and Spain.

The other person, according to Intel 471, reportedly possessed 72,400 scanned Iranian IDs, at least some of which had biometric data.

It is also known that last fall, a team of United Kingdom scientists spotted a vulnerability in the iPhone’s express transit mode that enabled them to use a replay-and-relay attack to make contactless payments of £1,000 (US$1,350) on Visa cards linked to Apple Pay.

Biometric authorization was simply bypassed. The phone was locked and did not authorize the transaction.

Vulnerabilities also found in Android devices and in Microsoft’s Windows 10 Hello facial recognition software allowed biometric authentication to be skirted.

In a more strained example, a man claimed that he was able to bypass behavior-based anti-fraud systems and two-factor authentication by mimicking the keystrokes and mouse movements of his twin brother, according to the firm.

Article Topics

 |   |   |   |   |   |   |   | 

Latest Biometrics News

 

Hawaii ID issue shows interoperability matters as digital IDs scale

By Albert Roux, EVP Product for Microblink Travelers at Hawaii airports recently experienced delays because valid state-issued IDs could not…

 

State Department moves to buy Clearview AI licenses for Colombia police

The U.S. State Department’s Bureau of International Narcotics and Law Enforcement (INL) at the U.S. Embassy in Bogotá, Colombia is…

 

Meta licensed ROC facial recognition, liveness for smart glasses project

Meta’s development of facial recognition for its smart glasses is drawing sharper scrutiny after reporting that the company licensed technology…

 

UK aims to lead the world with new age restrictions for social media, AI chatbots

After months of promises, the UK government has pulled the trigger on regulations to restrict social media sites for children…

 

Germany moves to allow police facial recognition searches of online images

Europe’s largest internet industry association, eco, has warned against Germany’s plan to allow its law enforcement agencies to run automated…

 

US senators propose curbs on AI-generated election deception

A group of Senate Democrats Thursday renewed a push to regulate the use of AI in federal elections, targeting both…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events