Researchers Hack Biometric Faces
yahoi sends in news from a week or so back: "Vietnamese researchers have cracked the facial recognition technology used for authentication in Lenovo, Asus, and Toshiba laptops in lieu of the standard logon/password. The researchers were able to easily bypass the biometric authentication system built into the laptops by using photos of an authorized user, as well as by presenting multiple phony facial images in brute-force attacks. One of the researchers will demonstrate the hack at Black Hat DC this week. He says the laptop makers should remove the facial biometrics feature from their products because the vulnerability of this technology can't be fixed."
He says the laptop makers should remove the facial biometrics feature from their products because the vulnerability of this technology can't be fixed.
If that's the standard, all security features should be removed. Everything is somewhat vulnerable, and a determined intruder with infinite resource will almost always find a way in. The object is to make this unreasonably hard for most applications.
If you get your laptop lifted at the coffee shop, they better lift your wallet too I guess.
=======
Science -- Sealed, Delivered.
The researchers were able to easily bypass the biometric authentication system built into the laptops by using photos of an authorized user [...]
Tragically, sadly obvious. Not even a hack, really.
If it's for-profit but free, you're not the customer -- you're the product (e.g., the Slashdot Beta's "audience").
Even made a point of saying "facial recognition systems aren't all that secure. They can't tell the difference between a person and a photo of the person". Then he proceeded to break into the room by holding up a picture of someone that had access.
Wonder if, when you 'enrolled' your face in the recognition software, you held your hand(s) up in the image forming a symbol -- peace sign, one finger salute, whatever. Then someone would have to capture your image at the instant you authenticated.
It would be customizeable and and changeable, unlike your face, and hard to duplicate blindly.