Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Fun With Fingerprint Readers
Crypto-Gram Newsletter ^ | 05/15/2002 | Bruce Schneier

Posted on 05/16/2002 10:36:19 PM PDT by general_re

Fun with Fingerprint Readers

Tsutomu Matsumoto, a Japanese cryptographer, recently decided to look at biometric fingerprint devices. These are security systems that attempt to identify people based on their fingerprint. For years the companies selling these devices have claimed that they are very secure, and that it is almost impossible to fool them into accepting a fake finger as genuine. Matsumoto, along with his students at the Yokohama National University, showed that they can be reliably fooled with a little ingenuity and $10 worth of household supplies.

Matsumoto uses gelatin, the stuff that Gummi Bears are made out of. First he takes a live finger and makes a plastic mold. (He uses a free-molding plastic used to make plastic molds, and is sold at hobby shops.) Then he pours liquid gelatin into the mold and lets it harden. (The gelatin comes in solid sheets, and is used to make jellied meats, soups, and candies, and is sold in grocery stores.) This gelatin fake finger fools fingerprint detectors about 80% of the time.

His more interesting experiment involves latent fingerprints. He takes a fingerprint left on a piece of glass, enhances it with a cyanoacrylate adhesive, and then photographs it with a digital camera. Using PhotoShop, he improves the contrast and prints the fingerprint onto a transparency sheet. Then, he takes a photo-sensitive printed-circuit board (PCB) and uses the fingerprint transparency to etch the fingerprint into the copper, making it three-dimensional. (You can find photo-sensitive PCBs, along with instructions for use, in most electronics hobby shops.) Finally, he makes a gelatin finger using the print on the PCB. This also fools fingerprint detectors about 80% of the time.

Gummy fingers can even fool sensors being watched by guards. Simply form the clear gelatin finger over your own. This lets you hide it as you press your own finger onto the sensor. After it lets you in, eat the evidence.

Matsumoto tried these attacks against eleven commercially available fingerprint biometric systems, and was able to reliably fool all of them. The results are enough to scrap the systems completely, and to send the various fingerprint biometric companies packing. Impressive is an understatement.

There's both a specific and a general moral to take away from this result. Matsumoto is not a professional fake-finger scientist; he's a mathematician. He didn't use expensive equipment or a specialized laboratory. He used $10 of ingredients you could buy, and whipped up his gummy fingers in the equivalent of a home kitchen. And he defeated eleven different commercial fingerprint readers, with both optical and capacitive sensors, and some with "live finger detection" features. (Moistening the gummy finger helps defeat sensors that measure moisture or electrical resistance; it takes some practice to get it right.) If he could do this, then any semi-professional can almost certainly do much much more.

More generally, be very careful before believing claims from security companies. All the fingerprint companies have claimed for years that this kind of thing is impossible. When they read Matsumoto's results, they're going to claim that they don't really work, or that they don't apply to them, or that they've fixed the problem. Think twice before believing them.

Matsumoto's paper is not on the Web. You can get a copy by asking: Tsutomu Matsumoto - tsutomu@mlab.jks.ynu.ac.jp

Here's the reference: T. Matsumoto, H. Matsumoto, K. Yamada, S. Hoshino, "Impact of Artificial Gummy Fingers on Fingerprint Systems," Proceedings of SPIE Vol. #4677, Optical Security and Counterfeit Deterrence Techniques IV, 2002.

Some slides from the presentation are here: http://www.itu.int/itudoc/itu-t/workshop/security/present/s5p4.pdf

My previous essay on the uses and abuses of biometrics: http://www.counterpane.com/crypto-gram-9808.html#biometrics

Biometrics at the shopping center: pay for your groceries with your thumbprint. http://seattlepi.nwsource.com/local/68217_thumb27.shtml


TOPICS: Business/Economy; Culture/Society; News/Current Events
KEYWORDS: biometrics; fingerprintreader; snakeoilsalesmen; techindex; unita
Lots of stuff about biometrics lately, especially with respect to security and payment systems. As is usual, Bruce brings the hype down to earth.

Subscribe to the (free) Crypto-Gram Newsletter here.

1 posted on 05/16/2002 10:36:19 PM PDT by general_re
[ Post Reply | Private Reply | View Replies]

To: bio_metrics;tech_index
list ping
2 posted on 05/16/2002 10:41:39 PM PDT by general_re
[ Post Reply | Private Reply | To 1 | View Replies]

To: general_re
My experience wth "Fingerprint Readers:"

Four years ago the company I work for decided to put thumbprint readers at each computer workstation - that way we could "securely" log-in.

After three months of trying to log-in by thumbprint (and countless hours wasted by computer support people) the system was scrapped.

Failed over 90% of the time.

3 posted on 05/16/2002 10:46:46 PM PDT by spectre
[ Post Reply | Private Reply | To 1 | View Replies]

To: general_re
I'm working feverishly to perfect my biometric nipple device . . . Much more reliable than fingerprints! I expect to make a fortune, too, made easier by the large volunteer workforce I've assembled.
4 posted on 05/16/2002 10:47:41 PM PDT by LibWhacker
[ Post Reply | Private Reply | To 1 | View Replies]

To: general_re
Let me see if I understand this....

Democrat fundraiser + latent prints off a glass + "fake finger" = fun with Tommy Daschle.

5 posted on 05/16/2002 10:48:47 PM PDT by Helix
[ Post Reply | Private Reply | To 1 | View Replies]

To: general_re
Thanks for posting this -
I will be attending the COMDEX computer show in Las Vegas in November and intend to make a latex copy of my thumb to confront those print readers at the show.
I'd love to give those guys the finger !
6 posted on 05/16/2002 10:49:31 PM PDT by RS
[ Post Reply | Private Reply | To 1 | View Replies]

To: spectre
Hey, that's one way to increase security. If nobody can log in, nobody can do any damage, right? ;)
7 posted on 05/16/2002 10:55:47 PM PDT by general_re
[ Post Reply | Private Reply | To 3 | View Replies]

To: Helix
Democrat fundraiser + latent prints off a glass + "fake finger" = fun with Tommy Daschle.

Well, since you put it that way, I guess there is an upside after all ;)

8 posted on 05/16/2002 10:58:00 PM PDT by general_re
[ Post Reply | Private Reply | To 5 | View Replies]

To: longshadow
A what-mathematicians-do-when-they're-not-watering-ferns bump ;)
9 posted on 05/16/2002 11:00:21 PM PDT by general_re
[ Post Reply | Private Reply | To 1 | View Replies]

To: general_re
I DO seem to remember that internet lunchtime useage was cut waaayy back :>)
10 posted on 05/16/2002 11:05:59 PM PDT by spectre
[ Post Reply | Private Reply | To 7 | View Replies]

To: general_re
bang back to the top for the morning crew...
11 posted on 05/17/2002 5:24:09 AM PDT by general_re
[ Post Reply | Private Reply | To 2 | View Replies]

To: general_re
His more interesting experiment involves latent fingerprints. He takes a fingerprint left on a piece of glass, enhances it with a cyanoacrylate adhesive, and then photographs it with a digital camera. Using PhotoShop, he improves the contrast and prints the fingerprint onto a transparency sheet. Then, he takes a photo-sensitive printed-circuit board (PCB) and uses the fingerprint transparency to etch the fingerprint into the copper, making it three-dimensional. (You can find photo-sensitive PCBs, along with instructions for use, in most electronics hobby shops.) Finally, he makes a gelatin finger using the print on the PCB. This also fools fingerprint detectors about 80% of the time.

Does it occur to anyone that this could be used to fool more than just a secuirty device? He's essentially devised a method by which a person's fingerprint (or fingerprint IMAGE) can be used to create a duplicate "finger" which can then be used to leave YOUR fingerprint wherever someone wants to.

The implications for the judicial system is astounding. Criminal lawyers will have a field day casting doubt about the defendant's fingerprints found at the scene of the crime. Every trial will be another OJ Simpson trial.

Lastly, do you suppose there are a few people at the CIA who are very unhappy that this info is now in the public domain?

12 posted on 05/17/2002 9:00:27 AM PDT by longshadow
[ Post Reply | Private Reply | To 9 | View Replies]

To: Gail Wynand
ping
13 posted on 05/17/2002 9:01:17 AM PDT by longshadow
[ Post Reply | Private Reply | To 12 | View Replies]

To: longshadow
ding ding ding! you win the prize. I speculated about this very thing on a biometric national ID thread a couple of weeks ago and I was shot down by statists.
14 posted on 05/17/2002 9:03:16 AM PDT by Black Agnes
[ Post Reply | Private Reply | To 12 | View Replies]

To: general_re
"Lots of stuff about biometrics lately, especially with respect to security and payment systems. As is usual, Bruce brings the hype down to earth."

The in the course of my work, I have visited various secure government facilities since the mid 80s. Over the years, I've noticed all sorts of biometrics devices installed at the entrances to these facilities - fingerprint/hand geometry readers, face recognition systems, even a "booth" that was supposed to combine all of these with a body weight measurement to boot. I have nver seen one in actual day-to-day operation; in fact, most of them were abandoned. I've often wondered how much taxpayer money has been wasted on these things.

15 posted on 05/17/2002 9:13:12 AM PDT by buaya
[ Post Reply | Private Reply | To 1 | View Replies]

To: buaya
I feel fairly certain the 'body weight' determination would be sued into non existence by the fat acceptance crowd.
16 posted on 05/17/2002 11:29:06 AM PDT by Black Agnes
[ Post Reply | Private Reply | To 15 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson