Slashdot Mirror


Aussie Kids Foil Finger Scanner With Gummi Bears

mask.of.sanity writes "An Australian high school has installed 'secure' fingerprint scanners for roll call for senior students, which savvy kids may be able to circumvent with sweets from their lunch box. The system replaces the school's traditional sign-in system with biometric readers that require senior students to have their fingerprints read to verify attendance. The school principal says the system is better than swipe cards because it stops truant kids getting their mates to sign-in for them. But using the Gummi Bear attack, students can make replicas of their own fingerprints from gelatin, the ingredient in Gummi Bears, to forge a replica finger. The attack worked against a bunch of scanners that detect electrical charges within the human body, since gelatin has virtually the same capacitance as a finger's skin."

31 of 303 comments (clear)

  1. Next up... by Moryath · · Score: 5, Insightful
    I can just see it now. Next they come up with one to detect "body heat" in the finger.

    And the kids circumvent it by keeping the gummy bears in their pockets on the way to class.

    Once again, a "foolproof" system proves to be only as useful as the fool who invented it.

    1. Re:Next up... by Moryath · · Score: 5, Insightful
      There really aren't.

      As far as the human body goes, there are only a few things that are really "constant." Exposure to allergens or illness change the voice enough that it will fail vocal characteristic matching. Taking biometric readouts of a facial structure fails the moment someone has a serious traffic accident, gets any sort of illness that causes facial swelling, or simply grows out their facial hair.

      Fingerprints? I think we've done that one pretty much to death.

      The best suited is probably retinal or iris scanning, but even those have issues. Retinal scanning fails on any number of degenerative disorders affecting the blood flow, like diabetes and glaucoma. It also fails to properly record and identify on people with moderate to severe cataracts and astigmatism. There are also some pretty hefty privacy issues with retinal scanning, since it can be used to diagnose a number of diseases and conditions - AIDS, syphilis, a number of other STD's, malaria, chicken pox, hereditary diseases like lymphoma and anemia, and even pregnancy.

      Iris scanning will fail to recognize due to tinted glasses or cosmetic contact lenses, and it'd be pretty easy to spoof them with a contact lens "printed" to someone else's pattern that is opaque around the ~750nm wave band that most NIR (Near Infrared) scanners use - and the reason they predominantly use NIR is that if you don't pick that specific band, light reflections from the cornea throw enough noise into your scan image to make it virtually unusable. For the really cheap-ass iris scanners, a suitable high-quality picture of someone's eye may even be sufficient to spoof.

      And of course, both retinal and iris scanners will fail out if they don't have an incredibly controlled environment - stick a retinal or iris scanner in an area with bright sunlight or inconsistent lighting, and you may as well just chuck the thing out the window, because iris contractions to open/close the pupil will make your scan worthless.

      Of course, you could put a hooded structure that people have to stick their eyeball on to look into in order to get scanned. That'll last all of about 2 days before some prankster gets the idea to smear some india ink or something else around the edge of the eyeball viewer...

    2. Re:Next up... by interkin3tic · · Score: 4, Insightful

      I can just see it now. Next they come up with one to detect "body heat" in the finger.

      Or they just try to ban gummi bears. If they're coming up with a stupid fingerprint scanner, these are obviously the typical school administrators, cut from the same cloth as those who gave their students laptops and didn't tell them they'd be watching them through the webcam at all times, adding to the contraband list is probably going to be their first reaction. Maybe if the ban fails miserably, they'll just tattoo barcodes onto their foreheads.

      I suspect the public would not be so willing to accept encroaching police states and governments slowly taking away our rights if schools had to actually justify shit like this to the students.

    3. Re:Next up... by choongiri · · Score: 5, Insightful

      Whether it's technically possible to defeat the system isn't the issue. If you're trying to force kids' presence with technological measures rather than encourage leaning and enthusiasm socially, you're doing something wrong. Especially since this is talking about older kids. Try giving them something fun to do, instead of demanding they bio-retina-dna scan in after recess.

    4. Re:Next up... by Worthless_Comments · · Score: 5, Insightful

      The teacher could actually, you know, take roll. I guess that would be too much work for a government employee though?

    5. Re:Next up... by russ1337 · · Score: 3, Insightful

      so RFID under the skin it is then....

    6. Re:Next up... by The+Hatchet · · Score: 5, Insightful

      Easy, just scan people as they walk by, record their numbers and get yourself an adjustable implant. You could change identities whenever you please. That is probably the easiest to spoof of all.

      --
      Where is the mod rating for "scary"? Also, ...
    7. Re:Next up... by SharpFang · · Score: 5, Insightful

      There's one, worse problem. Compromised credentials can't be changed. Only revoked. So someone somehow acquired your retina scan... sorry, Your credentials as compromised have been revoked, you're fired, come back when you get new retinas.

      --
      45 5F E1 04 22 CA 29 C4 93 3F 95 05 2B 79 2A B2
    8. Re:Next up... by delinear · · Score: 4, Insightful

      When I was at school there was no need to get on any network. In fact, only two rooms in the entire school had a connection to the network. The teachers had a printed sheet of what we used to call "paper", and they'd use an archaic device called a pen to tick off students in attendance. Of course, back then they also actually knew the students, which was a big help (after a couple of classes they could put names to faces and check off the register in silence while the students got on with some work). It seems schools are falling over themselves to find technical solutions to something that's been trivial to manage for years, I don't see the agenda, are schools subsidised by the companies who provide the technology and welcome real world trials or is it something else?

    9. Re:Next up... by delinear · · Score: 4, Insightful

      You seriously do not want to eat a gummi bear that's touched the same scanner as a couple hundred teenagers - trust me, I used to be one, I know the kinds of things they touch. I wouldn't even want to touch that with my finger, let alone my food. On the plus side, at least when all the kids get sick because they're sharing around their diseases, at least they'll have a legitimate excuse to not be in class.

    10. Re:Next up... by strack · · Score: 4, Insightful

      well, its a effective way to get everyones fingerprints on record, whether theyve commited a crime or not. its basically a way to sqeeze a great big brick over everyones privacy. and it also primes people to be more accepting of giving up biometric data for a government database.

    11. Re:Next up... by ciderbrew · · Score: 5, Insightful

      I don't worry about the average person. It's the above average and people with an imagination that really work the system.

    12. Re:Next up... by Rogerborg · · Score: 2, Insightful

      Actually, what the Mythbusters found was that their high end fingerprint lock, which claimed to check for pulse, heat and capacitance, could be fooled with nothing more than a (moistened) photocopy of a finger.

      Laptop scanners fared better, but the door ones seem to be security theatre.

      --
      If you were blocking sigs, you wouldn't have to read this.
    13. Re:Next up... by TapeCutter · · Score: 2, Insightful

      Just after I started uni, our maths lecturer came up to a group of about 8 of us standing around talking in the hallway, we had not yet had a math lecture but he prceeded to name each and every one of us. Government employee or not, he was a fucking genius with an extrodnary memory.

      --
      And did you exchange a walk on part in the war for a lead role in a cage? - Pink Floyd.
    14. Re:Next up... by Anonymous Coward · · Score: 1, Insightful

      The technology to uniquely identify and authenticate an individual is going to get better, and it is going to become harder for the average person to forge and use an alternative identity.

      I have no intention of "forging" an identity, my aim is anonymity.
      Unfortunately, the same technology that is being developed for authentication will also be applied to identification and tracking.

      Sounds like the time for the IR LED Hat is quickly approaching.

  2. The Future is Secure by lorelorn · · Score: 4, Insightful

    Fuck, YES. I read the original story, about the school introducing this moronic system, and could only shake my head. Attempts at total control are generally the solution proffered by lazy bureaucrats as an alternative to them doing their jobs. Here’s an idea - instead of working out ways of forcing the kids into school and keeping them there - why not work to make it compelling for them to come to school in the first place. I know, hard, right? Idiots. However, the creative (dare I say scientific) solution employed, and so quickly makes me remotely proud of our clever children. It’s nice to see the kids are far more intelligent and creative than their so-called teachers. I will have somewhat less pride when they remotely drain my bank account and I am forced to live on cast off gummi bears, but hey.

  3. Let's see... by kurokame · · Score: 4, Insightful

    * You have to buy a new system and probably sign a support contract for it
    * It ties up personnel with deployment
    * It doesn't work any better than the old system
    * It raises significant privacy issues not present in the old system
    * It raises huge data security and disposal issues not present in the old system
    * Adding a new student is more invasive and time consuming than in the old system
    * Fingerprint biometrics can track an arbitrarily large set of individuals...but they can only distinguish a few hundred

    Yep, that sounds like a textbook example of educational bureaucracy.

  4. The Future is FAR from Secure by sonamchauhan · · Score: 2, Insightful

    I agree that its a stupid and lazy approach. But there is only so much you can do to "make it compelling" until reality sets in that discipline is necessary for children.

    The oldest approach is still the best - have teachers (and not machines) who **recognize** kids conduct roll calls.

    1. Re:The Future is FAR from Secure by The+Hatchet · · Score: 3, Insightful

      Kids in some areas of the world willfully walk miles to school every day. Why? because they are learning. In America, our schools force our students to memorize arbitrary facts in arbitrary order with no regard to context or meaning. This is problematic because the brain is typically terrible at memorizing out of context, out of order, arbitrary information, we have a very small capacity for it. On the other hand, it is possible to cover several weeks of math in a single day, and the students will enjoy and remember it, it is is conceptual, in proper context, and useful. I learned partial fraction decomposition 4 years ago, and just learned a use for it today in differential equations. All you have to do to compel students to attend school is to teach them, instead of screaming at them to memorize totally pointless bullshit while eating shitty food, being told what they are allowed to say and where they have to be every minute of the day, even when they are allowed to go to the bathroom, and they can be arrested for being physically attacked. Of course truancy is a problem in this bullshit hell of a system.

      Support real education reform. Well educated children don't need strict discipline, because they know better, they understand why it is bad to do X action. But if you just scream at them "OBEY ME OR SUFFER!" of course they are going to be angsty and rebellious. What an insensitive clod.

      --
      Where is the mod rating for "scary"? Also, ...
    2. Re:The Future is FAR from Secure by cappp · · Score: 4, Insightful

      What? Kids willingly walk miles to school every day because it's drilled into their heads that the only way off the farm, out of the slums, or whatever their particular disadvantage happens to be, is through education. There's no magical inspirational African/South American/Chinese teaching model that somehow drives these kids out of their beds before dawn and across miles with hungry bellies and an urge to learn. Hell, most of those kids are walking miles to school every day to learn arbitrary information, out of order, and by rote. Teaching kids to be critical learners, to engage with knowledge? That's a privilege that's only found in the rich western educational model, certainly not in the shanty towns.

      That being said, I understand your broader point and agree somewhat. Education has to be relevant, it should be interesting, and it shouldn't be one-size-fits-all. However, if we're honest we have to admit that that kind of system is expensive, demands teaching excellence, is hard to assess, and complicated to run. The US has over 60 million students in primary and secondary schools - that's an enormous population. There are a lot of problems with education in the west - most of them related to broader social issues like violence, poverty, ignorance et al - but it’s not nearly as bad as some of us seem to feel. There is a logic to a lot of the problems you’re complaining about and while matters could possibly be dealt with in better ways it’s going too far to claim the system itself is bullshit hell.

  5. Called me old fashioned by acwebguy · · Score: 2, Insightful

    Called me old fashioned, but whatever happened to teachers actually knowing their kids and simply taking attendance that way?

  6. Matt? "Present Miss" by thegarbz · · Score: 4, Insightful

    "Chris?"
    "Here Miss"
    "Peter?"
    "Present Miss"
    "Well it looks like everyone who's going to be here is here already, let's get started!" She thought knowing full well that a few of the students skipping the class will be reported to the principle yet again.

    Fingerprints? Really? Whatever is wrong, it's not the fault of the system that has served us for hundreds of years, and doesn't need some stupid technology to fix it.

    1. Re:Matt? "Present Miss" by wrook · · Score: 5, Insightful

      Actually, it's even easier than this. At the school I work for the teachers know what the students look like and what their names are. If one of the seats in the classroom is empty, usually it means a student is missing. If another student tries to impersonate someone you can tell by looking at them. So far this system is working pretty well. I'm pretty sure it's cheaper than a fingerprint scanner too.

  7. Is it really that difficult? by Anaerin · · Score: 1, Insightful

    Several teachers that I had relied on the class staying pretty constant, and gave each student a number in alphabetical order. To "Call roll", you would listen for the number before yours, and after that was said by the student in question, you would say yours. Any absences were immediately obvious, and it took no more than a minute to finish it.

  8. How about "education"? by Joce640k · · Score: 4, Insightful

    If the problem with cards was that people were swiping their friend's cards, and the problem with fingerprints is that they're faking them, then the problem seems to be a social one.

    As noted, there's no technical solution that will keep motivated teenagers at bay.

    --
    No sig today...
    1. Re:How about "education"? by xaxa · · Score: 4, Insightful

      If the problem with cards was that people were swiping their friend's cards, and the problem with fingerprints is that they're faking them, then the problem seems to be a social one.

      As noted, there's no technical solution that will keep motivated teenagers at bay.

      Yes there is -- at least, if your goal is that they be in class: have the teacher check who's there in the first minute of the lesson. Loads of schools in Britain use some kind of electronic system to do this (there are various manufacturers). Of course, it takes some time at the start of the lesson, so why not combine the two systems? Have the swipe card system, and then a message to tell the teacher "22 students have registered for this class". She can then verify this.

      (I had a friend at a different school back in 2002 with the swipe card system. He made money by charging other students to swipe their cards before class. Many of these students could afford this since they were paid to go to school.)

    2. Re:How about "education"? by nosferatu1001 · · Score: 2, Insightful

      In that case the system has failed to meet the stated requirements: ensuring attendance.

      UK schools dont rely on this, they rely on teachers actually recognising who they are teaching. Simple method, requires a bit of brainpower from the teacher though.

    3. Re:How about "education"? by Lumpy · · Score: 4, Insightful

      Agreed.

      Honestly what is it with all this concern about truancy.

      Just let the idiot kids skip a lot and fail. They can enjoy working as a lower class minimum wage bum. Stop making life a Pain in the Arse for the others that actually care about their education.

      MY 18 year old was floored when she said, "Dad will be upset with my grades this semester"... and I responded with, "You are in college on student loans. I'm not the one that needs to be upset. In fact I don't care if you blow off school. You will be the one that cant get a job and have a nice big debt over your head. I'll be disappointed, but you are an adult, if you want to screw up your own life... feel free to do so!"

      It changed her attitude overnight. Suddenly stopped partying with friends all the time and now is paying attention. Nothing like smacking your kid in the face with the carp of reality to wake them up.

      Honestly, let the loser kids that do not want to learn to skip or drop out. The world needs septic tank cleaners.

      --
      Do not look at laser with remaining good eye.
    4. Re:How about "education"? by eyrieowl · · Score: 3, Insightful

      takes even less time if the kids have assigned seats. Not difficult to see that Bobby's desk is empty. Not a big hit with the kids, but effective.

  9. Kids Are Alright by mbstone · · Score: 3, Insightful

    While school kids may yet learn to scam extra lunches and play hooky through the use of gummi candy biometrics, the headline is bogus. None of the linked articles reported that any kids anywhere are doing anything with gummi bears except fucking up their teeth.

  10. Perfect Solution by lee1 · · Score: 2, Insightful

    If students don't want to attend school then there is something wrong with the school. Fix the school so that the students want to go there; then you don't need a fancy biometric scanner.