Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Mobile

9/13/2013
01:12 PM
50%
50%

Apple Touch ID Fingerprint Scanner Unlocks Biometrics Debate

Apple's new fingerprint scanner may help biometrics gain popularity, but challenges mean passwords aren't going anywhere any time soon

Giving the finger -- so to speak -- to Apple's Touch ID feature may unlock the iPhone 5s and allow users to authorize purchases on iTunes, but whether the fingerprint scanning technology will push biometrics deep into the mainstream remains to be seen.

"Fingerprint readers, or biometrics, will not replace passwords in the near future for two reasons," says Gene Meltser, technical director of security services firm Neohapsis. "First, fingerprints are not secret or even private -- an average person leaves hundreds of fingerprints on various surfaces throughout the day. Second, count your fingers -- if you’re like the 99.9 percent of the world, you have a total of 10 biometric passwords at your disposal for the rest of your life. A compromised fingerprint can never be effectively replaced like you can replace a password, and therefore cannot be relied on as future-proof authentication on its own."

In Apple's defense, the company has told the media that the iPhone does not store actual fingerprints -- just "fingerprint data" in the iPhone's processor. Also, users interested in using Touch ID must choose a password as a backup, and third-party applications are currently banned from using the scanner altogether.

On top of this, the most commonly mentioned attack, where someone steals a phone and lifts the fingerprints off of the device to unlock it, is not all that likely for the typical user, says Sebastien Taveau, founding board member of Fast IDentity Online Alliance (FIDO Alliance). Today's sensors have multiple mechanisms built in to protect from fake fingers, template dissociation, and authentication replay, he says.

"It is misinformed to assume that the industry hasn't developed and overcome the past vulnerabilities with extensive R&D, making these fears a thing of the past," he says. "That being said, even if someone were able to lift a fingerprint, odds are they have one-tenth of a chance to get the correct finger. If they were to be so lucky to capture an enrolled fingerprint, then they would have to have a 'clean' fingerprint to proceed at all."

Meltser agrees, acknowledging the practicality of an attacker getting a clean fingerprint and duplicating that print on a polymer model of a human fingerprint with enough detail to account for skin pores and other features. Still, biometric technology should be viewed as only part of the solution to the challenge of authentication.

"It's a third component to a well-known authentication adage: A good authentication solution must provide several of the following in addition to the username -- something you have (a physical token), something you know (a password) and something you are (a retina scan, or a fingerprint). Biometrics is a great enhancement to a good authentication strategy, but counting on biometrics as a standalone authentication panacea is premature," he says.

Apple is far from the only vendor to make recent announcements tied to biometrics. McAfee, for example, announced that its LiveSafe service would feature voice and face recognition. The same goes for the mobile space; two years ago, Motorola -- now owned by Google -- also released its Atrix phone with fingerprint-scanning technology of its own.

Even as weak passwords are often cited as a weak link in security, this has not, however, led to passwords falling off in use. Laptops have featured fingerprint scanners for years, but passwords are still the primary authenticator used by consumers, notes Neohapsis security consultant Joe Schumacher.

"The password is easier to accept by third parties without the worry of collaborating with other parties," he says. "For example, if one website is using fingerprint identification, then it would need to store that information in a secure manner that is the same as website number two. Also, many fingerprint readers used for authentication still require a password."

Still, Jamie Cowper, senior director at authentication solution provider Nok Nok Labs, says he expects there to be a significant growth in biometrics, particularly on mobile devices.

"This will be a combination of an improvement in sensor capability -- voice, face, fingerprint, and others, plus the enhanced functions coming into the smartphone market -- such as secure elements and operating systems that can be used to create and store biometric secrets," he says. "We are also seeing a shift toward multifactor authentication by large-scale Web services, and biometrics represents a simple, user-friendly way of implementing multifactor. This growth may well occur in the consumer sector first, as enterprise IT will take their time to consider different security models."

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Brian Prince is a freelance writer for a number of IT security-focused publications. Prior to becoming a freelance reporter, he worked at eWEEK for five years covering not only security, but also a variety of other subjects in the tech industry. Before that, he worked as a ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
bkmiller101
50%
50%
bkmiller101,
User Rank: Apprentice
9/19/2013 | 6:55:56 PM
re: Apple Touch ID Fingerprint Scanner Unlocks Biometrics Debate
I know nothing about this technology, but (it seems to me) that behind every scanned fingerprint is a digitized file that is used in pattern matching. Steal this file and who needs the finger? Breaking a print code must be more difficult than that, right?
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/25/2020
9 Tips to Prepare for the Future of Cloud & Network Security
Kelly Sheridan, Staff Editor, Dark Reading,  9/28/2020
Vulnerability Disclosure Programs See Signups & Payouts Surge
Kelly Sheridan, Staff Editor, Dark Reading,  9/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15216
PUBLISHED: 2020-09-29
In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one. A patch is available, all users of goxmldsig should upgrade to at least revisio...
CVE-2020-4607
PUBLISHED: 2020-09-29
IBM Security Secret Server (IBM Security Verify Privilege Vault Remote 1.2 ) could allow a local user to bypass security restrictions due to improper input validation. IBM X-Force ID: 184884.
CVE-2020-24565
PUBLISHED: 2020-09-29
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability to execute low-privileged code on the ...
CVE-2020-25770
PUBLISHED: 2020-09-29
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability to execute low-privileged code on the ...
CVE-2020-25771
PUBLISHED: 2020-09-29
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability to execute low-privileged code on the ...