Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Mobile

9/13/2013
01:12 PM
50%
50%

Apple Touch ID Fingerprint Scanner Unlocks Biometrics Debate

Apple's new fingerprint scanner may help biometrics gain popularity, but challenges mean passwords aren't going anywhere any time soon

Giving the finger -- so to speak -- to Apple's Touch ID feature may unlock the iPhone 5s and allow users to authorize purchases on iTunes, but whether the fingerprint scanning technology will push biometrics deep into the mainstream remains to be seen.

"Fingerprint readers, or biometrics, will not replace passwords in the near future for two reasons," says Gene Meltser, technical director of security services firm Neohapsis. "First, fingerprints are not secret or even private -- an average person leaves hundreds of fingerprints on various surfaces throughout the day. Second, count your fingers -- if you’re like the 99.9 percent of the world, you have a total of 10 biometric passwords at your disposal for the rest of your life. A compromised fingerprint can never be effectively replaced like you can replace a password, and therefore cannot be relied on as future-proof authentication on its own."

In Apple's defense, the company has told the media that the iPhone does not store actual fingerprints -- just "fingerprint data" in the iPhone's processor. Also, users interested in using Touch ID must choose a password as a backup, and third-party applications are currently banned from using the scanner altogether.

On top of this, the most commonly mentioned attack, where someone steals a phone and lifts the fingerprints off of the device to unlock it, is not all that likely for the typical user, says Sebastien Taveau, founding board member of Fast IDentity Online Alliance (FIDO Alliance). Today's sensors have multiple mechanisms built in to protect from fake fingers, template dissociation, and authentication replay, he says.

"It is misinformed to assume that the industry hasn't developed and overcome the past vulnerabilities with extensive R&D, making these fears a thing of the past," he says. "That being said, even if someone were able to lift a fingerprint, odds are they have one-tenth of a chance to get the correct finger. If they were to be so lucky to capture an enrolled fingerprint, then they would have to have a 'clean' fingerprint to proceed at all."

Meltser agrees, acknowledging the practicality of an attacker getting a clean fingerprint and duplicating that print on a polymer model of a human fingerprint with enough detail to account for skin pores and other features. Still, biometric technology should be viewed as only part of the solution to the challenge of authentication.

"It's a third component to a well-known authentication adage: A good authentication solution must provide several of the following in addition to the username -- something you have (a physical token), something you know (a password) and something you are (a retina scan, or a fingerprint). Biometrics is a great enhancement to a good authentication strategy, but counting on biometrics as a standalone authentication panacea is premature," he says.

Apple is far from the only vendor to make recent announcements tied to biometrics. McAfee, for example, announced that its LiveSafe service would feature voice and face recognition. The same goes for the mobile space; two years ago, Motorola -- now owned by Google -- also released its Atrix phone with fingerprint-scanning technology of its own.

Even as weak passwords are often cited as a weak link in security, this has not, however, led to passwords falling off in use. Laptops have featured fingerprint scanners for years, but passwords are still the primary authenticator used by consumers, notes Neohapsis security consultant Joe Schumacher.

"The password is easier to accept by third parties without the worry of collaborating with other parties," he says. "For example, if one website is using fingerprint identification, then it would need to store that information in a secure manner that is the same as website number two. Also, many fingerprint readers used for authentication still require a password."

Still, Jamie Cowper, senior director at authentication solution provider Nok Nok Labs, says he expects there to be a significant growth in biometrics, particularly on mobile devices.

"This will be a combination of an improvement in sensor capability -- voice, face, fingerprint, and others, plus the enhanced functions coming into the smartphone market -- such as secure elements and operating systems that can be used to create and store biometric secrets," he says. "We are also seeing a shift toward multifactor authentication by large-scale Web services, and biometrics represents a simple, user-friendly way of implementing multifactor. This growth may well occur in the consumer sector first, as enterprise IT will take their time to consider different security models."

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Brian Prince is a freelance writer for a number of IT security-focused publications. Prior to becoming a freelance reporter, he worked at eWEEK for five years covering not only security, but also a variety of other subjects in the tech industry. Before that, he worked as a ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
bkmiller101
50%
50%
bkmiller101,
User Rank: Apprentice
9/19/2013 | 6:55:56 PM
re: Apple Touch ID Fingerprint Scanner Unlocks Biometrics Debate
I know nothing about this technology, but (it seems to me) that behind every scanned fingerprint is a digitized file that is used in pattern matching. Steal this file and who needs the finger? Breaking a print code must be more difficult than that, right?
Zero-Factor Authentication: Owning Our Data
Nick Selby, Chief Security Officer at Paxos Trust Company,  2/19/2020
44% of Security Threats Start in the Cloud
Kelly Sheridan, Staff Editor, Dark Reading,  2/19/2020
Firms Improve Threat Detection but Face Increasingly Disruptive Attacks
Robert Lemos, Contributing Writer,  2/20/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
How Enterprises Are Developing and Maintaining Secure Applications
How Enterprises Are Developing and Maintaining Secure Applications
The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-8860
PUBLISHED: 2020-02-22
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung Galaxy S10 Firmware G973FXXS3ASJA, O(8.x), P(9.0), Q(10.0) devices with Exynos chipsets. User interaction is required to exploit this vulnerability in that the target must answer a phone call. ...
CVE-2020-8861
PUBLISHED: 2020-02-22
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-1330 1.10B01 BETA Wi-Fi range extenders. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP login requests. The issue...
CVE-2020-8862
PUBLISHED: 2020-02-22
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-2610 Firmware v2.01RC067 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of passwords. The issue results from the...
CVE-2020-9330
PUBLISHED: 2020-02-21
Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind credentials when changing the LDAP connector IP address. A malicious actor who gains access to affected devices (e.g., by using default credentials) can change the LDAP connection IP a...
CVE-2020-9327
PUBLISHED: 2020-02-21
In SQLite 3.31.1, isAuxiliaryVtabOperator allows attackers to trigger a NULL pointer dereference and segmentation fault because of generated column optimizations.