Skip to main content

Hackers could steal Android users’ fingerprints: HTC and Samsung comment

hackers can steal fingerprints android phones version 1438953211 fingerprint shutterstock 103378850
Shutterstock / Maksim Kabakou
You would think that using your fingerprint to unlock your smartphone is as secure as it gets, but that’s not always the case. If you’re using an Android phone you might want to pay attention to this one.

FireEye researchers Tao Wei and Yulong Zhang demonstrated at the Black Hat conference how hackers can remotely steal fingerprints without the owner of the device ever knowing about it. Even more dangerous, this can be done on a “large scale.”

Recommended Videos

Updated on 08-11-2015 by Robert Nazarian: Added in comments from HTC, Samsung, and Yulong Zhang.

We reached out to both HTC and Samsung to confirm patches were issued for both the HTC One Max and Galaxy S5. We also asked Samsung if the Galaxy S6, Galaxy S6 Edge, or any other devices have the same vulnerability.

“We have already addressed the issue for the HTC One Max, and it doesn’t affect any other HTC devices.”

Based on the following comment from HTC, we feel confident that all carrier versions of the One Max were patched:

“HTC is aware of the FireEye report on fingerprint scanner security. We have already addressed the issue for the HTC One Max in all regions, and it doesn’t affect any other HTC devices. As always, HTC takes security issues very seriously and makes it a top priority.”

Samsung’s comment makes no mention about a patch update, but does indicate that all Galaxy S5 phones are safe:

“Samsung takes fingerprint security very seriously, and we are aware of FireEye’s report on a vulnerability with the fingerprint sensor. After a thorough review with FireEye, it was found that all Galaxy S5 users’ data remain safe.”

Unfortunately, Samsung didn’t mention the status of the Galaxy S6, Galaxy S6 Edge, or any other phones that have fingerprint sensors. We have reached out to the company again, and we will update this post when we hear back.

“After a thorough review with FireEye, it was found that all Galaxy S5 users’ data remain safe.”

We also contacted Yulong Zhang and asked him about the Galaxy S6, Galaxy S6 Edge, or any other phones that might be vulnerable to the Fingerprint Sensor Security Attack. Unfortunately, he could not provide insight into whether it impacts other devices.

Zhang reiterated the iPhone isn’t vulnerable since the fingerprint data is encrypted. Apple purchased AuthenTec in 2012, which provides the fingerprint sensors for the iPhone. Apple’s ownership in the company makes it easier to control the security, whereas Samsung and other Android manufacturers are at the mercy of third-party hardware companies.

HTC’s and Samsung’s fix involves locking down the fingerprint sensors, but the data remains unencrypted because of hardware limitations. Android manufacturers will likely be able to secure hardware that allows them to encrypt fingerprint data in the future.

With all this negativity surrounding fingerprint sensors, Zhang still feels that using them the best way to secure phones and tablets. Fingerprints can’t be guessed, but passwords can, especially for those that use simple PIN codes like 1234.

What is the Fingerprint Sensor Spying Attack?

The “Fingerprint Sensor Spying Attack” works with Samsung, HTC, and Huawei phones. According to Wei and Zhang, some manufacturers fail to lock down the fingerprint sensor. Apparently some are only guarded by system-level privileges instead of root, which makes it easier to hack into. Most security-related software requires root access, making it more complicated for hackers to thwart.

It wasn’t explained how the hacker actually gains access to the fingerprint sensor itself, but the attacker can continue to read fingerprints for the life of the phone once the attack is in place.

It was also shown that through a different attack, “Confused Authorization Attack,” how a hacker could provide a fake lock screen that would actually enable a money transfer in the background once a fingerprint is accepted. The report didn’t indicate if any current phones are actually vulnerable to this type of attack though.

Obtaining a fingerprint could be very serious since they are not only used to unlock the device, but also used to make mobile payments and banking transactions. Fingerprints are also tied to you personally and obviously cannot be altered or changed.

It’s not clear how panicked you need to be on this one. Wei and Zhang demoed the Fingerprint Sensor Spying Attack on the older Samsung Galaxy S5 and HTC One Max, but didn’t mention if the newer Galaxy S6 or Galaxy S6 Edge has the same vulnerability. Furthermore, the report indicates that both Samsung and HTC issued patches after being notified about the vulnerability.

Now, if you happen to be an iPhone user, you will be happy to know that Apple does a better job at encrypting the fingerprint data from the scanner. The good news is that Google is implementing fingerprint security support in Android M, so it’s likely to be more secure on all Android phones moving forward. Speaking of that, Wei and Zhang recommend that consumers always buy the latest phones with the latest software for better protection.

Robert Nazarian
Former Digital Trends Contributor
Robert Nazarian became a technology enthusiast when his parents bought him a Radio Shack TRS-80 Color. Now his biggest…
Hackers nabbed Galaxy source code, Samsung confirms
Taking the S Pen out of the Galaxy S22 Ultra.

Samsung has confirmed it recently suffered a security breach that saw hackers nab important company data.

The data included source code linked to the operation of Samsung’s popular Galaxy phones and tablets, the company confirmed to Bloomberg on Monday, March 7, adding that no customer data was stolen in the incident.

Read more
Samsung’s Galaxy Tab S8 shows why Android 12L isn’t enough
Samsung Galaxy Tab S8 Ultra with keyboard.

Android tablets have usually fallen behind iPads and Windows tablets when it comes to offering good tablet experiences. With Android 12L, Google is taking that particular bull by the horns. The update will roll out to Pixel phones starting next month, but Samsung's recent announcement of the Galaxy Tab S8 casts a shadow over what should be a revival for Google's tablet ambitions because it shows that the problem with Android tablets isn't really with the interface.
What's Android 12L?
To quickly recap, Google last year announced Android 12L, an initiative the company is using to make Android a better experience on tablets and foldables. The company will continue this work through Android 13 and has hopes for app developers to step in line and create apps that would work better with Android going forward. The big issue here is that Android 12L is redundant for the most part -- and the Tab S8 is a reminder of that.

Android 12L, as far as focusing on bigger screen devices goes, amounts to pretty much a user interface revamp. There's a new multi-pane interface for the lock screen and the notification center, and there's support for a dock for productivity scenarios. But none of this actually fixes problems that exist for users. If you've done any shopping for Android tablets recently, you'll notice that companies like Samsung that actually sell Android tablets have pretty much always had their device software competently tablet-optimized.
Android tablets already have optimized interfaces
https://www.youtube.com/watch?v=pPGzX_y8ccM

Read more
Apple finally makes it harder to stalk Android users with its new Tracker Detect app
Apple Airtag in different polyurethane and leather key rings and loops

Apple has announced and released a new AirTags tracker app for Android called Tracker Detect. This has been done to resolve one of the privacy issues inadvertently introduced with AirTags earlier this year -- the ability to track someone without their knowledge. Once it was installed and a scan was initiated, the app was able to highlight unknown AirTag trackers nearby, essentially revealing the location of strangers and opening the door for planting an AirTag on someone without their knowledge to keep tabs on them.

AirTags were released earlier in the year as a rival to Tile and other Bluetooth trackers. They leveraged Apple's Find My network to help users track lost items by communicating with a combination of Bluetooth and Ultra Wideband. Unlike Tile trackers, they could also be used to geolocate lost items. However, AirTags also came with an unintended consequence: They could allow people to be tracked without their knowledge by simply tagging their clothes or personal property. Apple users would be protected against it as an iPhone running iOS 15 would be able to detect that an unknown AirTag was found moving with you, but that was not an option for Android devices.

Read more