Feeds

Steal my ID, steal my fingers - the public gets nervous

So how many fingers do you need anyway?

Remote control for virtualized desktops

The public fears losing their fingers to ruthless biometric ID thieves in the fingerprint-controlled future, apparently. Or at least, so says Frost & Sullivan analyst Sapna Capoor, who argued unconvincingly that "A dead finger is no good to a thief."

If you have a fingerprint scanner protecting your family jewels, your data might be safe, but what about your fingers?

So, it's all getting out of hand? Then on the other... there are recorded instances of people having their fingers chopped off, and the biometric industry takes the issue seriously.

For example, there were the Malaysian crooks who nabbed a man's fingers in order to operate the biometric security on the S-class Mercedes they stole from him.

Nevertheless, biometric firms are doing what they can to detect whether a fingerprint being scanned is alive or not, said Jean Francois Mainguet, chief scientist of fingerchip biometrics at Atmel-France, and inventor of the sweeping technique for direct silicon fingerprint scanning (he was awarded his patent on 9/11, as it happens).

Speaking at Biometrics 2006 in London, Mainguet said it wasn't yet possible to detect "liveliness", and even when it was, this would guarantee security no more than a regular biometric.

"Absolute security doesn't exist," he said. If you could detect liveliness, you wouldn't be able to tell if someone was accessing some system or authorising some payment under duress or not.

Security causes an escalation of causes and reactions just like the arms race. Want to cheat the banking system? Forge an ID. Fingerprint scanner making it tricky? Chop someone's finger off. Live fingerprint scanner? Hold someone's family at gun point.

The techniques being explored for live scanners include inducing involuntary responses via an electric charge to cause a spasm in skin pressed against the glass. Or there's the use of light fluctuations to induce involuntary responses from the user of an iris scanner.

They can all be faked, said Mainguet. The electrical response, for example is as easy as making a frog's leg twitch if you have chopped carefully.

There is a solution, he said, which is to use a variety of biometrics to identify someone. Biometrics? You just can't get enough of them. At some shows, anyway. ®

Top 5 reasons to deploy VMware with Tegile

More from The Register

next story
Facebook pays INFINITELY MORE UK corp tax than in 2012
Thanks for the £3k, Zuck. Doh! you're IN CREDIT. Guess not
Big Content outs piracy hotbeds: São Paulo, Beijing ... TORONTO?
MPAA calls Canadians a bunch of bootlegging movie thieves
Google Glassholes are UNDATEABLE – HP exec
You need an emotional connection, says touchy-feely MD... We can do that
Just don't blame Bono! Apple iTunes music sales PLUMMET
Cupertino revenue hit by cheapo downloads, says report
US court SHUTS DOWN 'scammers posing as Microsoft, Facebook support staff'
Netizens allegedly duped into paying for bogus tech advice
Feds seek potential 'second Snowden' gov doc leaker – report
Hang on, Ed wasn't here when we compiled THIS document
Verizon bankrolls tech news site, bans tech's biggest stories
No agenda here. Just don't ever mention Net neutrality or spying, ok?
prev story

Whitepapers

Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
Protecting against web application threats using SSL
SSL encryption can protect server‐to‐server communications, client devices, cloud resources, and other endpoints in order to help prevent the risk of data loss and losing customer trust.