Archive for 2009 December

Faked biometrics

In the InfoSec field we have been saying it for years: 

Biometrics are not a magic bullet for security. 

If you make a security check difficult to defeat in one place the attackers will look at weaker points.  Enrollment has always been such a point.  How do you know who’s biometric data you are putting into your system at account creation time?

Then there is biometric theft.  The raw data can be stolen and so can the the biological material — fingers have been done and it’s only a matter of time before hands and eyes are tried.

Finally is the technology that robust?  Apparently not.  A Chinese woman fooled Japan controls by having surgery to alter her fingerprints to get back into Japan.  Clever to swap prints, or portions of prints, from one hand to another.  That gets around the rejection problem if transplanting from a ‘donor’ — both willing and unwilling.  Ironic that the story is about someone trying to get into Japan given that Tsutomu Matsumoto’s work and the resulting gummy finger story came out of Japan.