Risk
8/28/2013
01:35 PM
Dark Reading
Dark Reading
Slideshows
50%
50%

Iris Scans: Security Technology In Action

Iris-based security scans are the stuff of sci-fi movies, but NIST research shows how the technology can now be used in the real world to reliably identify individuals.
Previous
2 of 6
Next


A traveler uses a check-in system, developed for NEXUS, a joint American-Canadian program designed to expedite border passage by frequent travelers. The traveler begins by entering traveler information on a kiosk before using an iris scanner located to the right of the kiosk.

RECOMMENDED READING:

Eyeball Scans Stay Accurate Over Time, Says NIST

Eye Scans Meet Federal ID Cards

Federal Biometric ID Cards Get Iris Scan Option

Google Glass: Security Risk For Governments?

Federal Government IT Priorities: Vision Vs. Reality

10 Must-Try Travel Apps

Do We Need A U.S. Department Of Technology?

Previous
2 of 6
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
WKash
50%
50%
WKash,
User Rank: Apprentice
9/3/2013 | 5:27:27 PM
re: Iris Scans: Security Technology In Action
The Canadian Border Services Agency and DHS deserve credit for putting iris recognition systems to the test in the field and sharing the data on how reliable the systems are.
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-2184
Published: 2015-03-27
Movable Type before 5.2.6 does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via the comment_state parameter.

CVE-2014-3619
Published: 2015-03-27
The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000000" fragment header.

CVE-2014-8121
Published: 2015-03-27
DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) 2.21 and earlier does not properly check if a file is open, which allows remote attackers to cause a denial of service (infinite loop) by performing a look-up while the database is iterated over...

CVE-2014-9712
Published: 2015-03-27
Websense TRITON V-Series appliances before 7.8.3 Hotfix 03 and 7.8.4 before Hotfix 01 allows remote administrators to read arbitrary files and obtain passwords via a crafted path.

CVE-2015-2157
Published: 2015-03-27
The (1) ssh2_load_userkey and (2) ssh2_save_userkey functions in PuTTY 0.51 through 0.63 do not properly wipe SSH-2 private keys from memory, which allows local users to obtain sensitive information by reading the memory.

Dark Reading Radio
Archived Dark Reading Radio
Good hackers--aka security researchers--are worried about the possible legal and professional ramifications of President Obama's new proposed crackdown on cyber criminals.