混沌计算机俱乐部黑客Jan Krissler近日演示了一项令人担忧的技术漏洞:仅用标准相机拍摄的照片和商业软件,就能成功复制德国防长Ursula von der Leyen的指纹1。这些照片来自10月份防长参加的一场新闻发布会,其中包含了从多个角度拍摄的拇指特写1。该演示表明,即使没有接触真实指纹样本,攻击者也能通过公开可得的图像材料伪造指纹信息。
指纹识别技术目前被广泛应用于消费电子产品和政治制度中,苹果、三星等设备均采用此技术,巴西总统选举的投票站也使用了指纹识别系统1。对此,安全专家Alan Woodward指出:"依赖面部识别或指纹等静态信息的生物识别并不是很好的安全形式,因为它们可以被伪造"1。为应对这一风险,专家建议转向更难被复制的动态生物特征识别方式。Barclays银行已在2013年9月为商业客户推出了手指血管识别技术1,这种方式仅在手指与活人连接时才能有效1,从而提高了欺骗难度。
A hacker from the Chaos Computer Club has demonstrated a significant vulnerability in fingerprint biometric security. Jan Krissler successfully replicated the fingerprints of German Defense Minister Ursula von der Leyen using only standard camera photographs and commercial software, without ever obtaining her actual fingerprints.1 The images, taken at a press conference in October featuring multiple angles of her thumb, proved sufficient for the reproduction.1
The demonstration raises serious concerns about the widespread adoption of fingerprint authentication technology. Fingerprint recognition has been integrated into consumer devices from Apple and Samsung, and has been used in voting systems in Brazil.1 Security expert Alan Woodward cautioned that "biometric systems relying on static information such as facial recognition or fingerprints are not a very good form of security, as they can be forged."1
In response to these vulnerabilities, experts have recommended transitioning toward dynamic biometric methods that are more resistant to spoofing. Vein recognition, which analyzes the pattern of blood vessels in the finger, offers improved security since it functions only when the finger belongs to a living person.1 Barclays Bank began offering vein recognition technology to commercial customers in September 2013.1
评论
还没有评论,欢迎留下第一条。