Skip to main content

Researchers develop master fingerprints that can break into smartphones

researchers fool fingerprint sensor scanning feat
The story goes that no two fingerprints are exactly alike, which makes them an excellent method for authentication. However, as researchers at New York University and Michigan State University have recently found, they’re hardly foolproof.

The team has developed a set of fake fingerprints that are digital composites of common features found in many people’s fingerprints. Through computer simulations, they were able to achieve matches 65 percent of the time, though they estimate the scheme would be less successful in real life, on an actual phone.

Recommended Videos

Nasir Memon, a computer science and engineering professor at New York University, explained the value of the study to The New York Times. Modern smartphones, tablets, and other computing devices that utilize biometric authentication typically only take a snapshots of sections of a user’s finger, to compose a model of one fingerprint. But the chances of faking your way into someone else’s phone are much higher if there are multiple fingerprints recorded on that device.

“It’s as if you have 30 passwords and the attacker only has to match one,” Memon said. The professor, who was one of three authors on the study, theorized that if it were possible to create a glove with five different composite fingerprints, the attacker would likely be successful with about half of their attempts. For the record, Apple reported to the Times that the chance of a false match through the iPhone’s TouchID system is 1 in 50,000 with only one fingerprint recorded.

Although Memon’s team’s findings may not pose a significant, immediate risk, they are the reason why tech companies aren’t satisfied with the status quo. Stephanie Schuckers, a Clarkson University professor, noted that the latest, most advanced systems attempt to detect the presence of a real person through methods like ultrasound and perspiration sensitivity. There are also newer methods of biometric authentication, like iris scanning and facial recognition, which are both featured on Samsung’s new Galaxy S8.

Ultimately, Memon said this didn’t damage his faith in using fingerprints for security too much, although he suggested phone makers consider forcing customers to use a PIN or password after the device is left idle for an hour.

Adam Ismail
Former Digital Trends Contributor
Adam’s obsession with tech began at a young age, with a Sega Dreamcast – and he’s been hooked ever since. Previously…
Researchers find a scary data vulnerability in Apple’s AirDrop
AirDrop options on an iPhone.

Hackers can tap into AirDrop data and pull your phone number or your email address. This issue has been known since 2019 and has yet to be patched or acknowledged by Apple, though it impacts almost 1.5 billion Apple devices today.

According to a report from security researchers at Germany's Technical University of Darmstadt, the core of this issue is the way in which AirDrop shares files between Apple devices using the address book and contacts list as an option by default. Per the researchers, since AirDrop leverages "a mutual authentication mechanism," to compare phone numbers, as well as email addresses, a hacker can easily intercept this information using "a Wi-Fi-capable device" that is nearby to an Apple user sharing through MacOS, iOS, or iPadOS via AirDrop. A proof of concept attack can be found on GitHub.

Read more
I hope the iPhone 13 has a fingerprint sensor as good as the Galaxy S21’s
Fingerprint technology. Credits: Samsung official.

When Apple removed Touch ID from the iPhone, it was considered a bold move. Users soon got used to it, though, and even began preferring Face ID as a replacement. But the last year has proven that there's room in the world for multiple forms of biometric authentication. Sometimes it just makes sense to scan a fingerprint -- and to that end, some rumors indicate that Apple may include a fingerprint sensor in the iPhone 13.

I hope that's true. To be clear, I love Face ID. When I'm not reviewing an Android phone, I normally use an iPhone as my daily driver, and it just feels easier to use Face ID. In fact, I love Face ID so much that I don't really mind having a notch. But it's a pain to have to punch in my PIN code every time I want to use my phone with a mask -- which these days, obviously, is a lot. A fingerprint sensor, on top of Face ID, would solve this.

Read more
I hate that the best cameras can only be found in the biggest smartphones
hate only gigantic phones have great cameras iphone 12 pro max galaxy s21 ultra 1

Smartphone cameras, across the board, have reached incredible quality levels. Even a relatively affordable smartphone today has a camera that can destroy the ones used on a flagship phone from a few years ago. But one thing hasn't changed: The best and most versatile camera systems are still reserved for the biggest phones — literally.

Yes the Pixel 5's camera is great. So is the iPhone 12 Pro's. But they aren't the best out there. That crown is a toss-up between the Galaxy S21 Ultra and the iPhone 12 Pro Max. Unsurprisingly, these are two of the biggest smartphones you can buy today. Even though "small" phones aren't really small anymore, you're still required to get an even bigger phone in order to get the best camera.

Read more