FB pixel

Exponential hacking of biometric authentication reveals some defenses already overwhelmed

Also, dark web tools for criminals spread
Exponential hacking of biometric authentication reveals some defenses already overwhelmed
 

“Motion-based is completely broken,” says Andrew Bud, founder and CEO, iProov, of biometric identity authentication where users are asked to perform actions to guarantee liveness for accessing services. His firm’s global monitoring center finds that attacks involving mobile phone emulators on desktops rose 149 percent and digital injection face swap attacks are up 295 percent. Those figures are for the second half of 2022 compared to the first half.

iProov’s Security Observation Centre (iSOC) is detected up to 200 injection attacks per day. But the evolution of digital injection attacks, where criminals feed images into an authentication process rather than attempt to trick the system by doing something in front of a camera, is proving even more concerning. iProov is detecting three cases a week where simultaneous attacks are launched on a global scale.

“We saw within 24-48 hours an Eastern European attacker invent a new attack method aimed mainly at motion-based liveness and just blitz the entire industry worldwide looking for any kind of system that would show vulnerability,” said Budd speaking at a Westminster eForum.

“And when they found systems that would show vulnerability, they would attack it.”

The digital injection attacks are no longer desktop web browser only, but happening on mobiles.

Also in 2022, iProov, which supplies biometric authentication to large-scale public services worldwide such as the NHS app for the UK public health service, detected a marked improvement in criminals’ ability to spoof metadata and in the quality of images used in attacks. Emulator use is rising in mobile web – across both Android and iOS.

The rise in face swap attacks show how the technology has become simple enough for lower-skilled criminals to use, who acquire tool kits on the dark web.

iProov’s iSOC observes what is happening with biometrics worldwide, says Budd. “Every single time a biometric authentication is made, it is triaged and searched for evidence of fraud,” says the CEO of the system whose process are subject to eIDAS audit.

Related Posts

Article Topics

 |   |   |   |   |   |   |   | 

Latest Biometrics News

 

Hawaii ID issue shows interoperability matters as digital IDs scale

By Albert Roux, EVP Product for Microblink Travelers at Hawaii airports recently experienced delays because valid state-issued IDs could not…

 

State Department moves to buy Clearview AI licenses for Colombia police

The U.S. State Department’s Bureau of International Narcotics and Law Enforcement (INL) at the U.S. Embassy in Bogotá, Colombia is…

 

Meta licensed ROC facial recognition, liveness for smart glasses project

Meta’s development of facial recognition for its smart glasses is drawing sharper scrutiny after reporting that the company licensed technology…

 

UK aims to lead the world with new age restrictions for social media, AI chatbots

After months of promises, the UK government has pulled the trigger on regulations to restrict social media sites for children…

 

Germany moves to allow police facial recognition searches of online images

Europe’s largest internet industry association, eco, has warned against Germany’s plan to allow its law enforcement agencies to run automated…

 

US senators propose curbs on AI-generated election deception

A group of Senate Democrats Thursday renewed a push to regulate the use of AI in federal elections, targeting both…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events