FB pixel

Exponential hacking of biometric authentication reveals some defenses already overwhelmed

Also, dark web tools for criminals spread
Exponential hacking of biometric authentication reveals some defenses already overwhelmed
 

“Motion-based is completely broken,” says Andrew Bud, founder and CEO, iProov, of biometric identity authentication where users are asked to perform actions to guarantee liveness for accessing services. His firm’s global monitoring center finds that attacks involving mobile phone emulators on desktops rose 149 percent and digital injection face swap attacks are up 295 percent. Those figures are for the second half of 2022 compared to the first half.

iProov’s Security Observation Centre (iSOC) is detected up to 200 injection attacks per day. But the evolution of digital injection attacks, where criminals feed images into an authentication process rather than attempt to trick the system by doing something in front of a camera, is proving even more concerning. iProov is detecting three cases a week where simultaneous attacks are launched on a global scale.

“We saw within 24-48 hours an Eastern European attacker invent a new attack method aimed mainly at motion-based liveness and just blitz the entire industry worldwide looking for any kind of system that would show vulnerability,” said Budd speaking at a Westminster eForum.

“And when they found systems that would show vulnerability, they would attack it.”

The digital injection attacks are no longer desktop web browser only, but happening on mobiles.

Also in 2022, iProov, which supplies biometric authentication to large-scale public services worldwide such as the NHS app for the UK public health service, detected a marked improvement in criminals’ ability to spoof metadata and in the quality of images used in attacks. Emulator use is rising in mobile web – across both Android and iOS.

The rise in face swap attacks show how the technology has become simple enough for lower-skilled criminals to use, who acquire tool kits on the dark web.

iProov’s iSOC observes what is happening with biometrics worldwide, says Budd. “Every single time a biometric authentication is made, it is triaged and searched for evidence of fraud,” says the CEO of the system whose process are subject to eIDAS audit.

Related Posts

Article Topics

 |   |   |   |   |   |   |   | 

Latest Biometrics News

 

Adoption of biometric payment cards plateaus with niche applications

Biometric payment cards, once seen to be the belle of the biometric ball, are mired in a rut of stagnated…

 

South Korea’s age assurance policies built on years of systemic, political change

A new paper from two scholars examines South Korea’s approach to age assurance. Published in TechPolicy.press, the paper contrasts global…

 

Zambia obtains World Bank funding support to advance DPI implementation

Zambia has secured funding to the tune of $120 million from the World Bank’s Digital Development Partnership to carry on…

 

Aadhaar enables an ‘epidemic’ of IDs in India

The Aadhaar ecosystem continues to grow, but it’s not all good news. The proliferation of IDs like the “One Nation,…

 

EU AI Act’s impact on businesses inspires simplification efforts

The European Union’s AI Act is already having a wide-reaching impact on business both inside and outside the economic bloc….

 

Chinese biometrics firms settle in Hong Kong for international market access

Chinese biometric recognition companies are eyeing Hong Kong as a springboard for expanding to foreign markets, according to company executives….

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events