FB pixel

Biometric exploits aren’t on the horizon; they’re in the backyard

Biometric exploits aren’t on the horizon; they’re in the backyard
 

The biggest threat to widespread use of biometrics in security is public distrust and the inability of the industry and government to address that distrust.

But that is today. Cybersecurity firm Intel 471 says that cybercriminals — precisely the people biometrics was supposed to put out of business — have already begun defeating systems. Their activity still is in its “infancy,” according to Intel 471.

A missive published by Intel 471 says that criminals “have learned to exploit vulnerabilities in facial and fingerprint recognition software.”

They have gained access to a device and then, of course, explained to their community how to defeat behavior-based anti-fraud software.

In September 2020, the company’s analysts reportedly “observed” a pair of Iranians trying to sell ID documents, some of which held biometric data.

One of the suspects claimed to have 76,000 national codes and biometric national ID cards originating in the United States and 10 other countries, including India, Brazil, Saudi Arabia, South Korea and Spain.

The other person, according to Intel 471, reportedly possessed 72,400 scanned Iranian IDs, at least some of which had biometric data.

It is also known that last fall, a team of United Kingdom scientists spotted a vulnerability in the iPhone’s express transit mode that enabled them to use a replay-and-relay attack to make contactless payments of £1,000 (US$1,350) on Visa cards linked to Apple Pay.

Biometric authorization was simply bypassed. The phone was locked and did not authorize the transaction.

Vulnerabilities also found in Android devices and in Microsoft’s Windows 10 Hello facial recognition software allowed biometric authentication to be skirted.

In a more strained example, a man claimed that he was able to bypass behavior-based anti-fraud systems and two-factor authentication by mimicking the keystrokes and mouse movements of his twin brother, according to the firm.

Article Topics

 |   |   |   |   |   |   |   | 

Latest Biometrics News

 

Türkiye finalizes draft law to require ID verification for social media access

The Turkish government says social media companies have agreed to a move that seeks to require identity verification for users…

 

Switzerland opens Swiyu bug bounty program to public

Switzerland has opened the bug bounty program for its upcoming digital identity wallet Swiyu to the public. The bug bounty…

 

Panasonic adds QR-based biometric onboarding to streamline site access

Panasonic Connect has introduced a new QR‑based face registration feature for its KPAS Cloud access management service. The new feature…

 

SLC Digital, Ideco partner on hardware-backed biometrics for fraud prevention

United States-based identity fraud solution firm SLC Digital and Ideco Biometrics, are combining their technologies and technical capabilities to enhance…

 

Japan moves toward age verification for social media filters and risk labels

Japan’s policymakers are considering their own version of age assurance for social media with content filtering taking the limelight. Nikkei…

 

AVPA plots course for age assurance future based on learnings from Australia

In 2025, few people on Earth logged as many travel miles as Iain Corby, the executive director of the Age…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events