Feeds

Carjackers swipe biometric Merc, plus owner's finger

Sometimes you might not want such great security...

  • alert
  • submit to reddit

Build a business case: developing custom apps

A Malaysian businessman has lost a finger to car thieves impatient to get around his Mercedes' fingerprint security system. Accountant K Kumaran, the BBC reports, had at first been forced to start the S-class Merc, but when the carjackers wanted to start it again without having him along, they chopped off the end of his index finger with a machete.

Although security systems of this sort are typically fitted to high end cars (because of import duties, Kumaran's car is reported to have been worth $75,000 "second-hand" - under the circumstances, we think we'd have said 'at resale'), they're not in essence particularly high tech or high security. As is the case with most auto security systems, they're mainly a speed bump intended to make it sufficiently hard for the would-be thief to encourage them to look elsewhere for victims. The fingerprint readers themselves will, like similar devices aimed at the computer or electronic device markets, have a fairly broad tolerance, on the basis that products that stop people using their own cars, computers or whatever because their fingers are a bit sweaty won't turn out to be very popular.

They slow thieves up a tad, many people will find them more convenient than passwords or pin numbers, and as they're apparently 'cutting edge' and biometric technology is allegedly 'foolproof', they allow their owners to swank around in a false aura of high tech. Get the secured object on its own for a little while and you can usually chop the security off fairly easily, but as the evidence now shows the more determined and impatient class of thief might just chop off your finger as a temporary measure.

Clearly we need to think carefully about how we see security here. If you're held at knife point at the cash machine and your assailant demands your pin number, then you will understand there may be consequences to refusing. Whether or not you do will depend on numerous of factors, but it is likely that most people will under certain conditions decide it's sensible to give in. You could see this as meaning that a pin number is inadequate as a security device, and that something else, backed, say, by biometrics, would be better. Which is pretty much what many of our leaders, including our own, which has specifically commended the efficacy of ID card-backed security for financial transactions, have been recommending.

But as the S-class Merc with security too irritating for the good of its owners health has shown, it's a lot more complicated than that. You don't want situations where a severed finger (or, would be kid-chippers should note) or arm can be used in unsupervised situations in their owner's absence. You could consider more sophisticated systems which used more complex biometrics and performed some form of check to make sure the owner was still attached and breathing, but even then you shouldn't view this as 100 per cent perfect.

If, for example, it's a case of ruthless gangsters trying to steal an extremely valuable motor car, then they'll quite probably take you along for a ride down to the bent auto shop they use, then kill you. Or if the security is so frustratingly good that the drug-crazed psycho can't even get a cashpoint withdrawal out of the deal, they might just stab you.

The UK's Association of Chief Police Officers (ACPO) incidentally extolled the virtues of biometric security in its evidence for the Parliamentary Transport Committee's Cars of the Future enquiry, and while the Home Office hasn't put forward biometric credit card validation as an immediate gain for the ID card scheme, this is certainly on its roadmaps.

But they should consider the implications before they get into that kind of territory, and understand that in most cases there will come a point where you actually want the owner to be able to disable the security quickly and easily. At minimum, biometrically-locked motor vehicles should surely kick up a 'Disable fingerprint security? Y/N') dialogue whenever you stick your finger into them. ®

Related Stories:

Civil liberty group pans EU biometrics plans
HP iPaq hx2750 PocketPC
Japanese banks deploy biometric palm scanners

Next gen security for virtualised datacentres

More from The Register

next story
Kate Bush: Don't make me HAVE CONTACT with your iPHONE
Can't face sea of wobbling fondle implements. What happened to lighters, eh?
Video of US journalist 'beheading' pulled from social media
Yanked footage featured British-accented attacker and US journo James Foley
Caught red-handed: UK cops, PCSOs, specials behaving badly… on social media
No Mr Fuzz, don't ask a crime victim to be your pal on Facebook
Ballmer leaves Microsoft board to spend more time with his b-balls
From Clippy to Clippers: Hi, I see you're running an NBA team now ...
Online tat bazaar eBay coughs to YET ANOTHER outage
Web-based flea market struck dumb by size and scale of fail
Amazon takes swipe at PayPal, Square with card reader for mobes
Etailer plans to undercut rivals with low transaction fee offer
Assange™: Hey world, I'M STILL HERE, ignore that Snowden guy
Press conference: ME ME ME ME ME ME ME (cont'd pg 94)
Call of Duty daddy considers launching own movie studio
Activision Blizzard might like quality control of a CoD film
US regulators OK sale of IBM's x86 server biz to Lenovo
Now all that remains is for gov't offices to ban the boxes
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 10 endpoint backup mistakes
Avoid the ten endpoint backup mistakes to ensure that your critical corporate data is protected and end user productivity is improved.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Rethinking backup and recovery in the modern data center
Combining intelligence, operational analytics, and automation to enable efficient, data-driven IT organizations using the HP ABR approach.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.