Advertisement
Promo

Security threats Toolkit

Jelly babies dupe fingerprint security

Rupert Goodwins GameSpot Europe

Published: 16 May 2002 16:03 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A Japanese researcher claims to have found a way to fool fingerprint scanners up to 80 percent of the time, using household materials and a little lateral thinking.

According to the security newsletter Crypto-Gram, Tsutomu Matsumoto from Yokohama National University has evolved a technique that takes casts from fingers and builds fake digits from gelatin -- the stuff of jelly babies. With care, he says, all 11 of the current fingerprint scanning technologies he tested give a false positive 80 percent of the time using the fraudulent jelly extremity.

Anyone can do this, says the researcher. First, take some free-molding plastic, obtainable from hobby stores. Take a cast of your finger. Once the plastic has hardened, pour in gelatin, available in sheets from grocery stores, and let it set. Optionally, you can then hollow out the fake finger and slip it over your own, bringing it up to body temperature for sensors that check that; you can also moisten it slightly to give it the same conductivity and capacitance as real flesh. Matsumoto also points out that if challenged by a security guard, you can eat the evidence.

In a more practical vein, Matsumoto has demonstrated a variation that works from fingerprints left on glass or other surfaces. First, he enhances it with cyanoacrylate adhesive -- superglue -- which is a standard technique used by forensic specialists to make prints visible. Then he takes a picture with a digital camera, enhances the contrast in PhotoShop and prints it on a transparency. He then uses this to etch a photosensitive copper-plated printed circuit board -- widely used by electronic engineers and hobbyists. This produces a 3D relief map of the original fingerprint, which can be then used to create a cast. The rest is as before.

Bruce Schneier, editor of Crypto-Gram, points out that Matsumoto is not a professional faker but a mathematician and conducted his experiments in what was in effect a kitchen environment. If he can achieve a reliable 80 percent hit rate, Scheier says, even semi-professionals can do much, much more and the results are enough to scrap all fingerprint recognition systems immediately.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
98 out of 163 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Sentry Posts Blog

INIFiles: Getting those legacy files i...

Handling INI files can be a little tricky these days when you have to consider new security restrictions, virtualized environment restrictions (App-V and Citrix) and legacy applications... More

Post a comment

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters