Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Mobile

9/13/2013
01:12 PM
50%
50%

Apple Touch ID Fingerprint Scanner Unlocks Biometrics Debate

Apple's new fingerprint scanner may help biometrics gain popularity, but challenges mean passwords aren't going anywhere any time soon

Giving the finger -- so to speak -- to Apple's Touch ID feature may unlock the iPhone 5s and allow users to authorize purchases on iTunes, but whether the fingerprint scanning technology will push biometrics deep into the mainstream remains to be seen.

"Fingerprint readers, or biometrics, will not replace passwords in the near future for two reasons," says Gene Meltser, technical director of security services firm Neohapsis. "First, fingerprints are not secret or even private -- an average person leaves hundreds of fingerprints on various surfaces throughout the day. Second, count your fingers -- if you’re like the 99.9 percent of the world, you have a total of 10 biometric passwords at your disposal for the rest of your life. A compromised fingerprint can never be effectively replaced like you can replace a password, and therefore cannot be relied on as future-proof authentication on its own."

In Apple's defense, the company has told the media that the iPhone does not store actual fingerprints -- just "fingerprint data" in the iPhone's processor. Also, users interested in using Touch ID must choose a password as a backup, and third-party applications are currently banned from using the scanner altogether.

On top of this, the most commonly mentioned attack, where someone steals a phone and lifts the fingerprints off of the device to unlock it, is not all that likely for the typical user, says Sebastien Taveau, founding board member of Fast IDentity Online Alliance (FIDO Alliance). Today's sensors have multiple mechanisms built in to protect from fake fingers, template dissociation, and authentication replay, he says.

"It is misinformed to assume that the industry hasn't developed and overcome the past vulnerabilities with extensive R&D, making these fears a thing of the past," he says. "That being said, even if someone were able to lift a fingerprint, odds are they have one-tenth of a chance to get the correct finger. If they were to be so lucky to capture an enrolled fingerprint, then they would have to have a 'clean' fingerprint to proceed at all."

Meltser agrees, acknowledging the practicality of an attacker getting a clean fingerprint and duplicating that print on a polymer model of a human fingerprint with enough detail to account for skin pores and other features. Still, biometric technology should be viewed as only part of the solution to the challenge of authentication.

"It's a third component to a well-known authentication adage: A good authentication solution must provide several of the following in addition to the username -- something you have (a physical token), something you know (a password) and something you are (a retina scan, or a fingerprint). Biometrics is a great enhancement to a good authentication strategy, but counting on biometrics as a standalone authentication panacea is premature," he says.

Apple is far from the only vendor to make recent announcements tied to biometrics. McAfee, for example, announced that its LiveSafe service would feature voice and face recognition. The same goes for the mobile space; two years ago, Motorola -- now owned by Google -- also released its Atrix phone with fingerprint-scanning technology of its own.

Even as weak passwords are often cited as a weak link in security, this has not, however, led to passwords falling off in use. Laptops have featured fingerprint scanners for years, but passwords are still the primary authenticator used by consumers, notes Neohapsis security consultant Joe Schumacher.

"The password is easier to accept by third parties without the worry of collaborating with other parties," he says. "For example, if one website is using fingerprint identification, then it would need to store that information in a secure manner that is the same as website number two. Also, many fingerprint readers used for authentication still require a password."

Still, Jamie Cowper, senior director at authentication solution provider Nok Nok Labs, says he expects there to be a significant growth in biometrics, particularly on mobile devices.

"This will be a combination of an improvement in sensor capability -- voice, face, fingerprint, and others, plus the enhanced functions coming into the smartphone market -- such as secure elements and operating systems that can be used to create and store biometric secrets," he says. "We are also seeing a shift toward multifactor authentication by large-scale Web services, and biometrics represents a simple, user-friendly way of implementing multifactor. This growth may well occur in the consumer sector first, as enterprise IT will take their time to consider different security models."

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Brian Prince is a freelance writer for a number of IT security-focused publications. Prior to becoming a freelance reporter, he worked at eWEEK for five years covering not only security, but also a variety of other subjects in the tech industry. Before that, he worked as a ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
bkmiller101
50%
50%
bkmiller101,
User Rank: Apprentice
9/19/2013 | 6:55:56 PM
re: Apple Touch ID Fingerprint Scanner Unlocks Biometrics Debate
I know nothing about this technology, but (it seems to me) that behind every scanned fingerprint is a digitized file that is used in pattern matching. Steal this file and who needs the finger? Breaking a print code must be more difficult than that, right?
Major Brazilian Bank Tests Homomorphic Encryption on Financial Data
Kelly Sheridan, Staff Editor, Dark Reading,  1/10/2020
Exploits Released for As-Yet Unpatched Critical Citrix Flaw
Jai Vijayan, Contributing Writer,  1/13/2020
Microsoft Patches Windows Vuln Discovered by the NSA
Kelly Sheridan, Staff Editor, Dark Reading,  1/14/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Post a Comment
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
[Just Released] How Enterprises are Attacking the Cybersecurity Problem
[Just Released] How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-3686
PUBLISHED: 2020-01-17
openQA before commit c172e8883d8f32fced5e02f9b6faaacc913df27b was vulnerable to XSS in the distri and version parameter. This was reported through the bug bounty program of Offensive Security
CVE-2019-3683
PUBLISHED: 2020-01-17
The keystone-json-assignment package in SUSE Openstack Cloud 8 before commit d7888c75505465490250c00cc0ef4bb1af662f9f every user listed in the /etc/keystone/user-project-map.json was assigned full "member" role access to every project. This allowed these users to access, modify, create and...
CVE-2019-3682
PUBLISHED: 2020-01-17
The docker-kubic package in SUSE CaaS Platform 3.0 before 17.09.1_ce-7.6.1 provided access to an insecure API locally on the Kubernetes master node.
CVE-2019-17361
PUBLISHED: 2020-01-17
In SaltStack Salt through 2019.2.0, the salt-api NEST API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticated attacker with network access to the API endpoint to execute arbitrary code on the salt-api host.
CVE-2019-19142
PUBLISHED: 2020-01-17
Intelbras WRN240 devices do not require authentication to replace the firmware via a POST request to the incoming/Firmware.cfg URI.