Slashdot Mirror


Fingerprint Scanners Fooled By Play-Doh

* * Beatles-Beatles writes to tell us YubaNet is reporting that in recent tests by Stephanie C Schuckers, an associate professor of electrical and computer engineering at Clarkston University, she has shown that, among other things, biometric security measures were fooled 90% of the time by simple attacks like Play-Doh molds. From the article: "Schuckers' biometric research is funded by the National Science Foundation (NSF), the Office of Homeland Security and the Department of Defense. She is currently assessing spoofing vulnerability in fingerprint scanners and designing methods to correct for these as part of a $3.1 million interdisciplinary research project funded through the NSF."

81 of 302 comments (clear)

  1. Is i just me by plaxion · · Score: 5, Funny

    Or is it starting to look like ScuttleMonkey is getting kickbacks from **Beatles-Beatles?

    1. Re:Is i just me by mattwarden · · Score: 3, Funny

      You smell that? Do you smell that? **Beatles-Beatles bullshit, son. Nothing else in the world smells like that. I love the smell of **Beatles-Beatles bullshit in the morning.

    2. Re:Is i just me by Tim+C · · Score: 4, Insightful

      Something funny is going on - two stories in a row? That's not chance, that's not coincidence, that's paid for. The only question is whether slashdot is paying **Beatles-Beatles, or **Beatles-Beatles is paying slashdot.

      Either way guys (and I'm talking to you, editors) it would be nice to be told. Just so we know, y'know? We're mostly intelligent, curious people here, and that sort hates being kept in the dark when there's so obviously something going on.

    3. Re:Is i just me by ndansmith · · Score: 4, Interesting
      What's more odd is that if there is something going on, they seem perfectly intent to be out in the open and obvious about it. Three stories in a row now (two on the front page) all with the same user (* * Beatles-Beatles) and the same link (http://george-harrison.info./ Why is ScuttleMonkey being so blatant about what he is doing? Does he not read anything on the submission at all? Or is he really in cahoots with this Beatles-Beatles fellow? Either way, doesn't he know that he is making an ass of himself and Slashdot by doing what he is doing?

      Here come the -1, Offtopic mods, which I have a feeling will not be meta-moderated.

    4. Re:Is i just me by antifoidulus · · Score: 2, Interesting

      The funny thing is we haven't(as far as I know) seen a Roland article in a long while....hmmm.....

    5. Re:Is i just me by Tim+C · · Score: 5, Interesting

      Out in the open and blatant only in that they're not trying to hide it. On the other hand, they're certainly not telling us, despite numerous comments asking what's going on attached to every **BB story.

      Mind you, it's not like we should be surprised - they acted in exactly the same way about the Roland Piquepaille(sp?) stories, and have acted the same in the past too (anyone else remember the troll report thread and related mod bombing and moderation blacklisting? I *still* can't moderate). The bottom line is that for all slashdot seems to rail against poor customer service, they're quick to ignore their own customers.

    6. Re:Is i just me by ObsessiveMathsFreak · · Score: 3, Insightful

      On the other hand, they're certainly not telling us, despite numerous comments asking what's going on attached to every **BB story.

      What? When have the Slashdot eds ever told us ANYTHING?!

      --
      May the Maths Be with you!
    7. Re:Is i just me by Seumas · · Score: 4, Interesting

      I didn't even realize it until you mentioned it, but what's up with the modding? I used to get mod points on a weekly basis, but I think it's been over a year since I've had any mod points. I sure don't remember participating in any sort of great uncovering of Slashdot secrets that would deserve such a response...?

    8. Re:Is i just me by BarryNorton · · Score: 2, Insightful
      I suddenly stopped getting mod points too, and I can't figure out why.
      Me too, it had better be nothing to do with pointing out what wastes of space BB and CZ are...

      Still, I don't know why I should care - this place has really just descended into noise, and I honestly can't think of anything new I've learned here all year.

    9. Re:Is i just me by TheRaven64 · · Score: 2, Insightful

      Looking at your posting history, you seem to post fairly regularly. I have found that the moderation system seems to avoid giving mod points to people who post in most of the articles they read. I tend to only get mod points after the general standard of /. stories has been low for a week or two and I've not felt the need to post. When I go back to posting, they stop coming for a bit.

      --
      I am TheRaven on Soylent News
    10. Re:Is i just me by dorkygeek · · Score: 4, Informative
      Because * *Beatles-Beatles is a link-farmer and uses the high page rank of slashdot to increase the page rank of the links he's farming on his website.

      --
      Windows is like decaf - it tastes like the real thing, but it won't get you through the day.
    11. Re:Is i just me by brunes69 · · Score: 3, Informative
      Mind you, it's not like we should be surprised - they acted in exactly the same way about the Roland Piquepaille(sp?) stories, and have acted the same in the past too (anyone else remember the troll report thread and related mod bombing and moderation blacklisting? I *still* can't moderate). The bottom line is that for all slashdot seems to rail against poor customer service, they're quick to ignore their own customers.

      Actually, far more likely is that they don't have time to read /. comments all day since they are busy doing other stuff and managing the sbumission queue.

      I toally agree this whole ScuttleMonkey thing is BS and the guy should be fired, but if you want to make your point known, you should be emailing OSTG about it, not ranting on here where no one sees you.

    12. Re:Is i just me by hkmwbz · · Score: 2
      Yeah, I did find that if I took a break from Slashdot for a couple of days, I would often get mod points. But I haven't, and I have taken plenty of breaks. And I actually don't comment on most stories I read anyway.

      I think I've been punished for something, whatever that might be. And why should the admins care? They have tousands of potential moderators, so it doesn't matter to them if they kick out those who cross the line even a little, according to them.

      So yeah, it awards mod points if you aren't a rabid and eager Slashdot reader, but the thing is that it's been several months now, and at times I take breaks from Slashdot and only visit it a couple of times a week. That used to give me mod points, but no more.

      --
      Clever signature text goes here.
    13. Re:Is i just me by dorkygeek · · Score: 2, Interesting
      YES, I have do visited his site! See my other comment below.

      --
      Windows is like decaf - it tastes like the real thing, but it won't get you through the day.
    14. Re:Is i just me by jamie · · Score: 4, Informative

      Of course nobody's paying anybody. Seriously, what would make you think that? If there were paid stories, don't you think we would make that blatantly obvious? Since it was created, Slashdot has been one of the best sites on the internet as far as keeping up the wall between advertising and content.

      Apparently this person submits a lot of stories that our editors think our readers want to read. That's all there is to it. Our editors review Beatles-Beatles submissions with the same skepticism (probably more) as any other.

      I normally don't bother responding to paranoid threads like this because there is so much paranoia and no way for us to respond to it all. But lately the comment volume devoted to silly speculation is just out of control. I kind of doubt this response will help stem the tide but it's worth a shot...

    15. Re:Is i just me by That's+Unpossible! · · Score: 2, Insightful

      This BS is precisely why I stopped subscribing. The editors don't give a shit about the abuse and stupidity in the (a) "editing" and (b) moderation system.

      If they clean house, I'll start subscribing again. Until then, there's no incentive.

      --
      Ironically, the word ironically is often used incorrectly.
    16. Re:Is i just me by nametaken · · Score: 2, Interesting

      I'll take the bait.

      Why is it that Scuttlemonkey favors Beatles-Beatles posts so heavily. I mean seriously, some of us are reasonably logical. It is nearly impossible that one person could hit the front page with almost every single article submission, without some kind of favoritism, with great frequency. If someone would just tell us what the deal is, I expect you wouldn't see the entire articles devoted to the "paranoia" you refer to. Obviously people agree that something is wrong, as I haven't seen an on-topic comment yet, and the moderators all agree.

      Otherwise we're talking one hell of a coincidence.

    17. Re:Is i just me by jamie · · Score: 2, Insightful
      Most of the replies to my comment are saying largely the same thing. I'm not sure which to reply to so I'll reply here. I'm probably not going to continue the conversation after this unless someone brings up a really good point, and this is all offtopic anyway, but... here's my commentary for what it's worth...

      I guess if somebody wants to not believe me, that's fine. Everybody has the right to an opinion. But I'm trying to share the facts. Slashdot doesn't take money for posting stories to our front page, and if we did, we would make it obvious that we had. I work with these guys and I know.

      Heck, if Slashdot ever does get to the point where we think it's OK to take money for secretly biasing editorial content, I'll quit. One of the things I like about working for Slashdot is the editorial integrity. That hasn't changed in the six years I've been here. I find the scenario of Slashdot's front page going pay-for-coverage to be highly implausible, but if it does, I have better things to do. And I doubt I'm the only one here who feels that way.

      Plus, if we ever got to the point where we sold that integrity to some random guy who just wants us to link to his George Harrison site... uh, at that point we are obviously so hard up for cash that I probably wouldn't have a job for long anyway ;)

      As for rel=nofollow, yes, we do consider ways to make the submission process less gameable, like we constantly do for almost every part of the site. The policy has been for years that your reward for telling us about a story worth posting is 3 karma and a link to your homepage, and we don't want to change that without careful consideration.

      Oh, and a number of people have pointed out (and I haven't checked this) that ScuttleMonkey has posted most of the Beatles-Beatles stories. Do y'all realize that this works against your theory? If we were getting paid wouldn't every editor be doing it? Just asking :)

  2. LOL by Red+Samurai · · Score: 5, Funny

    Better not install it in a kindergarten then.

  3. Wow by antikarma · · Score: 3, Insightful

    Wow, two in a row for Beatles. This is getting ridiculous...

    1. Re:Wow by sam_paris · · Score: 3, Informative

      Its actually three in a row. IT: Fingerprint Scanners Fooled By Play-Doh

      Science: Nano Tech. Spurs Continued Health Concerns

      NewsWeek Looks at Search Engine Optimization

    2. Re:Wow by shri · · Score: 5, Interesting

      Today's submissions that were rejected include a new digital imaging chip from the folks at Univ of Rochester and the Gnope.Org release (PHP GTK Toolkit).

    3. Re:Wow by ObsessiveMathsFreak · · Score: 3, Insightful

      Today's submissions that were rejected include a new digital imaging chip from the folks at Univ of Rochester and the Gnope.Org release (PHP GTK Toolkit).

      Are the editors, trying to bury the site?! I'm a geek. I want to read about stuff like this? Those writeups have better have been awful.

      --
      May the Maths Be with you!
  4. Redundancy... by Cherita+Chen · · Score: 5, Insightful
    Which is exactly why Biometrics, i.e, "Fingerprint readers", should only be one small part of a much more robust security infrustructure. Redundancy is key...

    --
    I'm not fat, just big boned...
    1. Re:Redundancy... by this+great+guy · · Score: 5, Funny
      Redundancy is key...

      That's why we all have 10 fingers.

    2. Re:Redundancy... by close_wait · · Score: 2, Funny
      That's why we all have 10 fingers.

      Speak for yourself. I only have 9 fingers, and of them, only 5 have useful fingerprints. Which is why I always have great amusement at immigration whenever I visit the US these days. "Please place your left index finger on the glass. Oh. Er, your left thumb then. Oh, you haven't got a left thumb. Well, your second finger then. Now your right index finger. Oh. Your right thumb - er no, make that your second finger - er okay, so perhaps your thumb after all". And because the pointless (*) DHS fingerprint system at immigration doesn't actually do anything useful, I go through the same rigamarole each time I enter.

      (*) nearly as pointess as the questions on the green visa waiver form, eg "have you been involved in genocide between 1933 and 1945 in nazi germany?".

  5. Good security by ReformedExCon · · Score: 5, Interesting

    It's one thing to fool fingerprint scanners. The ones described in the article use a photo system that takes a picture of the full print and detects similarities with prints on file. It does sound pretty easy to fool. However, what about swipe-based scanners? Or retinal scanners? Surely Play-Doh isn't durable enough to drag over a fingerprint swipe-scanner and it's probably difficult to make a good replica of an eye with the stuff.

    But the real security comes with a Marine standing guard. If you can get passed that guy, the biggest problem is already solved.

    --
    Jesus saved me from my past. He can save you as well.
    1. Re:Good security by ArsenneLupin · · Score: 5, Funny
      What is he supposed to do, remember all two hundred peoples faces that pass him in a day?

      He stands near the scanner. And if he sees that anybody puts something else than his finger on the scanner, he shoots ;-)

    2. Re:Good security by mwvdlee · · Score: 2, Insightful

      And now you have to trust the Marine guard.

      --
      Slashdot social media options: AIM, ICQ, Yahoo, Jabber and Mobile Text. Why no MySpace?
    3. Re:Good security by lars_stefan_axelsson · · Score: 4, Interesting
      But the real security comes with a Marine standing guard. If you can get passed that guy, the biggest problem is already solved.

      Then you're in trouble (scroll to near the bottom where they just drive through the main gate). The red team Red Cell were notorious in the eighties for getting into any base they set their sights on, in fact they were so successful that it played no small part in being shut down, they were just too much of an embarassement.

      In fact, human security guards are notoriously unreliable, they'll get a few, but also let quite a few through. So I'm not sure that's necessarily the "biggest problem." It's a problem, but a combination of guard relying on technology that he's been assured is "foolproof" when in fact it is not, doesn't make for much in the way of security.

      --
      Stefan Axelsson
    4. Re:Good security by lars_stefan_axelsson · · Score: 4, Insightful
      While you are correct, the main purpose of guards next to biometrics devices is to ensure that users can not tamper with the devices.

      Yes, that's what I was trying to get to in my last sentence, i.e. that that won't work either. As the guard will have a tendency to become complacent given that the e.g. fingerprint scanner is "foolproof" and not even bother to look at it as the person scans his finger. Compare if you will the absymal successrates of photo id:s when put to the test. The guard there is actually required to look at it as a part of the procedure (i.e. it's not incidental to the procedure as it is here), but anything usually goes. Even cartoon pictures (I know of one instance of Donald Duck) have gotten people into military bases. If I was a betting man, I'd bet that just holding the severed finger between the thumb and forefinger on the hand (in effect presenting a six fingered hand) would let you in more often than not, even with a fairly "vigilant" guard.

      A guard beside a finger print scanner will probably prevent someone walking up carrying a dead body, or taking a crowbar to the gate, but beyond that I wouldn't bet my life on it. People without technological support just aren't that good at routine surveillance (at a reasonable cost that is).

      --
      Stefan Axelsson
    5. Re:Good security by cvd6262 · · Score: 2, Funny

      From my experience (and that of a friend of mine who was in pharm sales) the easiest way to get on *any* military base is to put a Dominos Pizza sign on the top of your car.

      Seriously, I was picking up a cousin at Travis AFB, and they put me through ten minutes of questions, even though I had all the passes, paperwork, etc. While they had me standing outside my car, they waived a pizza guys through without even stopping him.

      --

      I'd rather have someone respond than be modded up.

  6. Welcome to Slashdot by Motherfucking+Shit · · Score: 5, Funny

    "News for financial partners of the editors, bank balances that matter."

    --
    "BSD: Free as in speech. Linux: Free as in beer. Windows 10: Free as in herpes." --Man On Pink Corner in #52607549.
  7. Gummy bears by MillionthMonkey · · Score: 4, Funny

    A guy at work was always talking about using gummy bears to commit the perfect crime. You somehow make a mold of someone's fingerprint using that gummy bear material. Then you use it on a fingerprint scanner, which gets fooled by it, and it lets you in. Then, get this- you eat the gummy bear fingerprint mold, and permanently destroy the evidence of your intrusion.

    I always thought that was a little disgusting. You mean you're just going to eat that thing right after you pressed it against a disgusting fingerprint scanner?

    1. Re:Gummy bears by frankmu · · Score: 4, Funny

      i think the 5 second rule would apply, so it would be safe to eat.

      --
      Supreme executive power derives from a mandate from the masses, not from some farcical aquatic ceremony.
    2. Re:Gummy bears by Incadenza · · Score: 2, Funny

      The 2004 Ig Nobel Prize Winners

      PUBLIC HEALTH
      Jillian Clarke of the Chicago High School for Agricultural Sciences, and then Howard University, for investigating the scientific validity of the Five-Second Rule about whether it's safe to eat food that's been dropped on the floor.

  8. Old Hat by TheAcousticMotrbiker · · Score: 4, Informative

    This is old hat, sortof.
    German computer magazine C'T defeated fingerprint scanners a few years ago using gummibears. Im sure www.heise.de should ahve a (german) copy of that still online somewhere

  9. And? by Bacon+Bits · · Score: 5, Interesting

    There are three flavors of a security pass:
    1. Something you have, like badge or actual key.
    2. Something you know, like a password or pass phrase.
    3. Something you are, like a General, Doctor, or American citizen.

    Two-form authentication (where you use two of the three above forms) is quickly becoming regconized as being much more secure. Numerous security professionals were hoping biometrics would fit into the "something you are" category, but increasingly that category is being replaced by "something you have". You can have a General's uniform or forged passport... or a playdough impression from an authenticated finger. All this study does is confirm that migration.

    --
    The road to tyranny has always been paved with claims of necessity.
    1. Re:And? by Anonymous Coward · · Score: 5, Insightful

      1. Something you have, like badge or actual key.
      2. Something you know, like a password or pass phrase.
      3. Something you are, like a General, Doctor, or American citizen.

      This gets interesting in the overlaps that refute the categoricals. What you know and what you have both define what you are. For example what makes you a General or a Doctor other than the correct uniform? A detailed knowledge of military or medical matters. So let's take two twins, one a doctor and one a general and get them to spend a month teaching each other everything they know about each others subject. The doctor twin puts on his brothers uniform and walks right into the base. Now, can he spend an entire day bluffing his way through a tactical conference, while his brother does a bit of impromptu brain surgery? Unlikely but not impossible. So is it what we know that defines us as who we are? Not with 100% certainty. Is it what we have that defines what we are? No, not definitely. Keys, passwords, biometric features, money, any facet of physical acuality can be forged, stolen or substituted. So where does that leave us? It leaves us with the uncomfortable philosophical annoyance that identity does not exist. We have to step back and look at the question again. What are we trying to achieve through assigning identity? We are trying to map INTENTION. The guy getting on the plane may look like, smell like, sound like, walk like... the person the computer says is good ole regular Joe Citizen 101, but what if his _intention_ is to blow up the plane and not ride peacefully? Joe could have been brainwashed/blackmailed/replaced by an android. Identity isn't the thing that governments and identity researchers _want_ it to be and so we have to start tackling the more difficult issue of stopping people needing or wanting to steal money or blow up planes.

    2. Re:And? by 16K+Ram+Pack · · Score: 2, Insightful
      I think that biometrics are dangerous because they give people the false belief in a perfect security system, an extension of when I've heard people in a company tell me that "the computer says so".

      People will trust these systems to the point that they will disengage their critical faculties, because they have been told how reliable they are.

      When biometric ID cards come in to the UK, I believe we will see more fraud because of this. Once someone works out how to break it (by gummi bear, play-doh) or whatever, they will pass and be able to pull off bigger frauds.

  10. Play-Doh is... by TorKlingberg · · Score: 5, Informative

    For all us not not from the same cultural sphere as the submitter, Play-Doh is a clay-like compound used by children to form various things. http://en.wikipedia.org/wiki/Play-Doh

    1. Re:Play-Doh is... by meringuoid · · Score: 3, Interesting
      Play-Doh is a clay-like compound used by children to form various things.

      'When I was a little man
      Playdoh came in a little can
      I was Star Wars' biggest fan
      Now I'm stuck without a plan
      G. I. Joe was an action man
      Shaggy drove the mystery van
      Devo was my favourite band
      Take me back to my happy land!'

      -- The Aquabats, Playdoh. A wonderful song of geek nostalgia...

      --
      Real Daleks don't climb stairs - they level the building.
    2. Re:Play-Doh is... by Gadzinka · · Score: 4, Interesting

      There's something I don't understand. From the article on Wikipedia:

      Its exact makeup is a secret [...] Play-Doh was invented by Noah McVicker and Joseph McVicker in 1956 and awarded U.S. Patent 3,167,440 in 1965.

      So, is its formula secret, or was it patented? If the patent was granted in 1965, shouldn't it expire already?

      Robert

      --
      Bastard Operator From 193.219.28.162
  11. Next: man on terrorist watch list after buying Doh by Anonymous Coward · · Score: 5, Funny

    If you have no children and buy PLay-doh you might be added to the terrorist watching list as a security risk.

  12. Capacitance? by Omicron32 · · Score: 5, Interesting

    I may be using the wrong term here, but why not have some sort of capicitance measuring device on the fingerprint scanner? Something a bit less sensitive than your iPod wheel or a normal laptop touchpad so it has to detect a current on the persons finger before it will even begin to scan?

    Not that I've tried it, but I'm pretty sure you can use Playdoh to navigate around your iPod.

    1. Re:Capacitance? by anzev · · Score: 2, Interesting

      You could fool this by using balistics gel. It has almost the same properties as the human body, including conductivity. Although it's tougher to make, but you could use play-doh to create the first mold, than harden it, put it in a vacuuform and create the perfect finger mold.

  13. This is unacceptable. by c0dedude · · Score: 3, Interesting

    Fingerprints are now part of our total security strategy and a first-line screening technique for inprocessing of mass police events. When groups are processed after WTO rallies and other such large police events, processing uses fingerprint ID. Imagine a case in which 500 were arrested and all could be terror suspects, and the terrorist, who would have been ID'd, got away because of a fingerprint error. Fingerprints are used by banks to cash out-of-state checks. It's time to verify fingerprints and begin associating them with a biometric less modifiable, such as retinal ID. Of course, concerns about the coercivity of this approach are justified, but the security benefit outweighs. If we're going to use biometrics, let's use effective ones. Of course, the merits of mass arrest are questionable, but if we are going to do it, let's do it right.

    --
    Since when has this country used intellectual elite as a pejorative term?
    1. Re:This is unacceptable. by ScentCone · · Score: 2, Insightful

      The people being picked up are patriots

      Categorically saying they are patriots is just as silly as saying, categorically, that they are not.

      --
      Don't disappoint your bird dog. Go to the range.
  14. They are also annoying in other ways by siddesu · · Score: 5, Interesting

    I for one have a problem logging on via the scanner after a longer bath. The damned thing won't recongize the fingerprint and won't let me logon until the skin dries and the wrinkles on the fingers go away.

    It is not bad, as I give up on the computer in the evening, just don't wash your hands before a presentation :-)

    1. Re:They are also annoying in other ways by Anonymous Coward · · Score: 4, Funny

      I for one have a problem logging on via the scanner after a longer bath

      I don't think that is a concern for most of the people who read this site.

  15. Conspiracy. by Jaruzel · · Score: 4, Funny

    ScuttleMonkey IS ... * * Beatles-Beatles ?

    -Jar.
    (Who is so happy now he can join in with the Beatles-Beatles thing)

    --
    Together, We Can Make Slashdot Better. I Do NOT Mod ACs. - Check Me Out
  16. I Don't Know About You Guys But... by Niraj59 · · Score: 5, Funny

    ... I, for one, enjoy * * Beatles-Beatles's articles. Everything he posts is news to me and the content is stuff that matters to me. I especially love his well-designed, non-sketchy website. If Slashdot would implement his wonderful CSS styles (when you hover over text, it all becomes italicized and underlined with a box drawn around it) my experience here would be great. Is there any way we can make * * Beatles-Beatles a moderator, or better yet, an administrator on Slashdot? That would be excellent. Keep up the great work ScuttleMonkey and * * Beatles-Beatles!

    1. Re:I Don't Know About You Guys But... by identity0 · · Score: 2, Insightful

      The sad thing is, that would be an improvement, as I've yet to notice BB or SM make a dupe post or obvious grammar error.

  17. Pulse Oximetry by Detritus · · Score: 4, Interesting

    Why not add a little hardware and check for a living finger? When I was in the hospital, they put a noninvasive sensor on my finger that measured my pulse and blood oxygen level. It uses two frequencies of light to measure oxygenated haemoglobin.

    --
    Mea navis aericumbens anguillis abundat
    1. Re:Pulse Oximetry by Fred_A · · Score: 2, Funny

      Or simply needles that shoot out and a microphone listening for screams.
      It would be cheaper to implement.

      --

      May contain traces of nut.
      Made from the freshest electrons.
    2. Re:Pulse Oximetry by permaculture · · Score: 2, Interesting

      Perhaps you didn't read the article. It mentions that the researcher in question has added extra hardware to get around the problem. The new hardware checks for sweat flow from the finger, and can distinguish between cadaver and living fingers.

      --
      Environmentalism is the new Victorianism. Everyone ties on a green corset and pretends we're virtuous.
  18. Wait a minute... by coopaq · · Score: 2, Funny
    You mean you can use Play-Doh for something other than sex?

    1. Re:Wait a minute... by dagr8tim · · Score: 2, Funny
      [i]You mean you can use Play-Doh for something other than sex?[/i]


      I call BS on this. Every knows slashdoter's don't have sex. Unless you are attempting to reproduce female organs. Which in that case, you would have had to of seen one in real 3. And that comes back to my original point.

      --
      "Does your computer have IP on it?"
  19. Boycott by arthur5005 · · Score: 3, Insightful

    Wow, two in a row for Beatles. This is getting ridiculous...

    I think as a collective we've got to get around to doing something about this. Criticisms that Slashdot content, and the overall quality of the website are merrited. I think a boycott is in order here.

    Lets make it clear to the editors that these kind of submissions shouldn't be tolerated, and will recieve no attention. These kind of posts should recieve no replies regardless of importance. After which we should all carry out the task of resubmitting the article for discussions on the topic to resume.

    After this post I intend to disregard any submission by '**Beatles-Beatles' and refuse to contribute or mod any of this Sponsorship Scandal(for those who don't live in Canada) like material. (Not a perfect analogy, but someone's getting a payoff it seems)

    ending transmission....

  20. You would think Beatles-Beatles could at least by antifoidulus · · Score: 2, Informative

    spell the name of the University correctly if he is going to spam slashdot. It's CLARKSON, there is no T in there!

  21. More fingerprint spoofing techniques by BeermanAtCampus · · Score: 5, Informative

    Last summer on WTH: Spoofing fingerprints in 10 minutes shown at WTH last summer. The guy on the video also says that he never encountered a fingerprint reader which couldn't be fooled. Interesting is also to see is that he does not make a fake finger, but only a thin acryl layer placed over ones real finger. And also on the CCC website: A image gallery with text (EN) how to copy a finger print. So it's not all about the Play-Doh

  22. The thing is... by 91degrees · · Score: 3, Insightful

    Fingerprint scanners are rubbish. They're simply not that reliable. Even if they sound reliable - if you have a scanner that's 99.9% accurate, that means that one person in 1000 has a close enough fingerprint to pretend to be you. Or to put it another way, 10000 Belgians share your fingerprint.

    And the best scanners are nowhere near that accurate.

  23. Omission in the FP by StateOfTheUnion · · Score: 4, Insightful
    As is typical, the editors leave out crucial information in their first post so as to make the article more interesting and attempt to gain more posts (Which I assume is used as a metric for advertisement pricing).

    Quoted from FP:

    University, she has shown that, among other things, biometric security measures were fooled 90% of the time by simple attacks like Play-Doh molds.

    Quoted from TFA:

    Schuckers and her research team made casts from live fingers using dental materials and used Play-Doh to create molds. They also assembled a collection of cadaver fingers. In the laboratory, the researchers then systematically tested more than 60 of the faked samples. The results were a 90 percent false verification rate.

    The crucial piece of missing information: The need for dental materials; the same stuff used to make casting for denture, false teeth, etc. To do what the researchers did, one needs more than play-doh. But of course ignoring this makes the FP much more dramatic becuase it implies that a preschool toy is sufficent for fooling biometric scanners.

    For the record the quote from the FP is the part written by the editors, not by the submitter (unitalicized portion of FP), so the error (or omission) was made by a /. editor, not by the submitter.

    I find it frustrating that what I once thought was a useful and interesting source of infomation and lively discussion seems to have become what it once seemed to differentiate itself from. Slashdot editors seems to be adopting the playbook of big media and skewed news to drive up user posts.

    I find this sad because I thought that Slashdot was a site with an alternative playbook, that treated its readers as more saavy. Now it seems to be on the slippery slope to USA Today style reporting. I can only assume that this change is an attempt to drive up ad revenue. But I am afraid it will alienate many of the readers.

  24. It's way worse than they think!! by Jeff_at_RAD · · Score: 5, Interesting

    I got a laptop with fingerprint identification and thought it was ultra-cool to just stick my index finger on there to log in (this was to XP tablet edition).

    Then I wondered if you could trick it, so I looked at my index finger, and saw that it was a loop, and then had someone else in the office try with one of their fingers that also was a loop. Nothing just by pressing down.

    But, because the login software takes continuous readings (which they display!), my buddy was able to keep sliding and mashing and rotating his finger around until after 4 or 5 seconds, Bong, logged in!! We were laughing, so we tried with with three other guys here, and they all logged on. Some of them had to rotate their hand all the way around, but *everyone* got on. THIS SOFTWARE DOES NOT WORK! DO NOT TRUST IT!

    I reported this to the fingerprint software people (sorry, don't remember their name), but they never responded. I just turned it off completely - it's a joke.

  25. Re:It's sad "fake news" keeps appearing on Slashdo by wraith0x29a · · Score: 2, Informative

    1. Get some sort of funding/investment for a start-up business or a research project of some sort.
    2. Generate traffic to a site to improve ad revenue or subscribers.
    3. Sell a product or service of some sort.
    4. ???
    5. Profit.

    --
    ~ Better a freak than a sheep. ~
  26. Understandable Frustration by ObsessiveMathsFreak · · Score: 4, Informative

    Now ordinarily the parent would simply be regarded as a troll, but all you have to do is look through a few Slashdot journals to see examples of quality submissions that have been rejected. The fact that a search engine spammer's articles get preference really explains this kind of frustration.

    I'd like to hear some kind of explanation from the editor(s). I'd like to think that this is simply some kind of failure of process rather than something fundamentally wrong with Slashdot itself. It would be nice if the next Slashback dealt with these issues in some way.

    --
    May the Maths Be with you!
  27. I got one here, and they may not be practical by EMIce · · Score: 4, Interesting

    I have a portable pulse oximeter sitting right next to me. It is pricey and is about 2.5" x 1.5" x 1.5". It clamps lightly around one's finger and has a numerical LED display for oxygen level and beats per minute. It's as accurate as a bedside hospital unit from what I have read. Adding one of these though would really drive up costs. Here is a pic of the unit I am talking about. $675, ouch.

    Incorporating them would also require a major redesign. They clamp around an inserted finger, and this would make them harder to clean and maintain, and also make them more prone to breakage.

    The non-invasive principle of operation of these is pretty neat, and might interest slashdoters. They work by shooting dual wavelengths of light through the finger, namely infra-red and a visible red color. On the other side of the finger, a sensor relays readings to a signal processor, which distinguishes between flesh, bone, and what-not based on the absorption differential between the two wavelengths, so it can isolate out variables between different kinds of fingers. The result is incredibly precise, and the LED on the front flashes in precise sync with one's pulse. I'm guessing the signal processor is a major cost, so maybe in time these will come down in price.

  28. So does this mean... by Burb · · Score: 2, Funny

    ... that Wallace (of Wallace and Gromit fame) can fool any fingerprint detector?

    --

  29. The truth about * *Beatles-Beatles by dorkygeek · · Score: 3, Informative

    Looks like ScuttleMoney^H^Hkey still doesn't get. Interesting thing is, ScittleMonkey seems to use some standard template for * *Beatles-Beatles submissions, since ALL of them start by: "* * Beatles-Beatles writes to tell us ...".

    So, let me repost some earlier post of mine:

    Ok, let's have a look at his george-harrison.info website. Aha, maybe the links at the bottom of the page? Yes, I see: http://george-harrison.info/reciprocal-links.html.

    Sooo, what may be on that page? Quoting:

    Our reciprocal links page. These links are useful for website promotion, link trades, and generating traffic to your site. There are many sites with useful products, services, programs, business opportunities, information, and free stuff.

    All reciprocal links have been manually screened before getting on this page. Webmasters that post links on this page, also promote this Links Page on their site too. If you want to add your link and become a member of this reciprocal links page, just click on the top link for details. It's free to join.

    Looking at the link list (just a small excerpt):

    Guaranteed Dropship Wholesalers business directory source

    Good Vibrations for Singles - Free Dating, Love, Romance, and Friendship

    Collection Agency - Williams, Cohen & Gray

    Trade Links - Link Swap Page

    Personals Dating Affiliate Program - Instant Sign-Up

    ProfitsRup2U For Successful Internet Marketing

    Trade links page - reciprocal links page

    HTH!

    --
    Windows is like decaf - it tastes like the real thing, but it won't get you through the day.
  30. Re:Fight back against this Beatles Beatles spammer by dorkygeek · · Score: 3, Interesting
    Or simply report abuse to CmdrTaco (malda@slashdot.org) every time a story by * *Beatles-Beatles gets posted!

    --
    Windows is like decaf - it tastes like the real thing, but it won't get you through the day.
  31. play-doh by big_scary_robot · · Score: 3, Funny

    I went to a friend's house the other day. He told me he was looking through a box of important papers and he found the recipe for play-doh. It seemed a bit weird at first but now it just seems suspicious.

  32. fingerprints not needed to find the terrorist... by jesterpilot · · Score: 2

    Just pick the guy who ordered to arrest 500 anti-WTO protesters.

    --
    Trust me, I work for the government.
  33. Spelling by penguinoid · · Score: 2, Funny

    Schuckers' biometric research is funded by the National Science Foundation (NSF), the Office of Homeland Security and the Department of Defense.

    They misspelled "suckers". After all, it can be fooled by play-doh.

    --
    Don't waste your vote! Vote for whoever you want, unless you live in a swing state it won't matter anyways
  34. Keep The Robust Stuff, Then by Lagged2Death · · Score: 3, Insightful

    Supposing there exists a "much more robust security infrastructure" - how is it going to be improved by the addition of a Play-Doh, uh, I mean a fingerprint scanner? Why not just stick with the robust stuff, and forget the shiny newfangled contraptions?

    This isn't the first demonstration that fingerprint scanners are useless. A few years ago, a Japanese university professor showed that it was possible to make a gelatin mold from a latent print (i.e., without direct access to the authorized finger in question) that would fool the readers most of the time! What is a fingerprint scanner adding but a false sense of security?

  35. thats nothing new by jaimz22 · · Score: 2, Interesting

    the screensavers on tech tv showed how to do this with a gummy bear, that's nothing new.

  36. Mr. Bill arrested for Conspiracy & ID theft by digitaldc · · Score: 2, Funny

    In other news, Mr. Bill was arrested Saturday for suspicion of ID Theft and Conspiracy when it was found he was unlawfully trying to enter a secure location with a fingerprint scanner.

    The police said his only words after getting caught were "DOH!" and then "Ohhh noooooooo!"

    --
    He who knows best knows how little he knows. - Thomas Jefferson
  37. Re:The fickle ways of moderation by welsh+git · · Score: 2, Insightful

    > (google doesn't AFAIK have the option to non-googlify a link, if it did and /. used it, how many stories would beatles post?)

    >rel=nofollow

    --
    Sig out of date
  38. The downside of biometrics by markdj · · Score: 2, Insightful

    I've said this before on slashdot: the biggest problem with biometrics is that once compromised they cannot be easily changed. You can always change your password if someone discovers it, but you can't easily change your retinal pattern. So if someone has a fake eyeball with your pattern you can't keep them from using it by using another pattern. The naive have assumed that biometrics are much harder to steal than passwords and would be too closely tied to the person to whom they belong to be compromised. For every type of authentication, there is a surprisingly easy and clever way to compromise it.

  39. MacGyver & A-Team by pr0digy25 · · Score: 2, Funny

    MacGyver + A-Team = UNSTOPPABLE.

  40. This also works. by theendlessnow · · Score: 2

    You can do the Play-Doh thing to fake retinal scanners too. But man does it hurt.