As soon as the iPhone 5S hit the market, the first thing some security experts did was hack the Touch ID protection system, based on recognition of fingerprints. If applied correctly, biometrics can be a strong security layer. However, members of the Chaos Computer Club have managed to reproduce the fingerprints of the German defense minister using some photographs and software available on the market.

Biometrics at Risk? Hackers Reproduce Fingerprints with Images
Fingerprints

Replacing Passwords with Fingerprints

Replacing passwords with fingerprints is something anyone can do today with the help of a simple dedicated reader. In fact, there are laptop models that already include this reader from the factory, and with a bit of extra software it is possible to program multiple fingerprints at once. With the launch of the iPhone 5S and the integration of Touch ID, fingerprints became the center of attention... until the Chaos Computer Club developed a method to clone fingerprints and fool the sensor. Now, the Chaos Computer Club strikes again with a new method that reproduces fingerprints using nothing more than a couple of photographs and an application called VeriFinger.

Biometrics at Risk? Hackers Reproduce Fingerprints with Images
Starbug spoke for an hour at the conference

The New Attack Method

At the 31st conference organized by the Chaos Computer Club, Jan Krissler, better known as Starbug, explained how he managed to develop an exact copy of the fingerprints of the German defense minister, Ursula von der Leyen. Apparently, the most complicated part of the process is obtaining the images. During a conference last October, the group captured a high-resolution image of the minister's thumb, and then combined it with other images captured from different angles. The result is a reproduction accurate enough to bypass any authentication system that requires the official's thumb.

Is Biometrics Dead?

Are we witnessing the end of biometrics? Of course not. The Chaos Computer Club's methods must be independently verified, and this security "breach" can be fixed with something as small as a pair of gloves. Still, it would be much more worrying if a secret government system actually used fingerprint recognition as its primary identity verification...

Source: