• Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
Blog - Creative Collaboration
No Result
View All Result
Home Android

Researchers find that Android phones are prone to new fingerprint attack

May 22, 2023
Share on FacebookShare on Twitter

What you need to know

  • Chinese researchers have found that Android phones are vulnerable to new attacks.
  • Dubbed BrutePrint attack, it can unlock any Android phone which uses a fingerprint sensor for authentication.
  • It is done by brute forcing fingerprint images obtained by attackers to gain access to devices.

New research findings suggest Android phones are susceptible to fingerprint attacks (via BleepingComputer).

Dubbed BrutePrint, these attacks seem to bypass user authentication and take control of your Android device, per researchers from Tencent Labs and Zhejiang University.

Fingerprint authentication on Android phones generally comes with safeguards, which are associated with users’ attempt limits as well as liveness detection, to protect against brute force attacks. The Chinese researchers, however, overcame these safeguards with two zero-day vulnerabilities dubbed Cancel-After-Match-Fail (CAMF) and Match-After-Lock (MAL).

(Image credit: arxiv.org/via BleepingComputer)

Further, the researchers have found that “biometric data on the fingerprint sensors’ Serial Peripheral Interface (SPI) were inadequately protected, allowing for a man-in-the-middle (MITM) attack to hijack fingerprint images,” the BleepingComputer report states.

These BrutePrint and SPI MITM attacks, which utilize the user’s fingerprint image, were carried out on nearly ten prominent smartphones running on Android, including the Xiaomi Mi 11 Ultra, OnePlus 7 Pro, Huawei devices running on HarmonyOS (Huawei P40), and some iOS devices.

“The tested Android devices allow infinite fingerprint tryouts, so brute-forcing the user’s fingerprint and unlocking the device is practically possible given enough time.”

Researchers suggest the attacker would need physical access to the phone as well as fingerprint databases, seemingly available from academic datasets or biometric data leaks from the past, notes the report. Moreover, the necessary equipment is said to be available for just $15.

It was found to take between 2.9 hours to 13.9 hours to complete a BrutePrint attack if the device owner has registered one fingerprint for authentication. This would take significantly less time with more fingerprints registered to the device.

That said, the threat from a BrutePrint attack is not an immediate cause for major concern, as the attacker still needs physical access to the device. That said, it could still be dangerous when it comes to stolen devices, as BrutePrint can then be used to bypass device authentication.

The BleepingComputer further implies that it could raise privacy-related questions regarding investigations conducted by law enforcement, saying they could potentially use the aforementioned techniques to unlock any phone with a fingerprint sensor for authentication.

Next Post

Twitter users report deleted tweets return, won't delete

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

No Result
View All Result

Recent Posts

  • Resident Evil Village Gold Edition Review – Twisted Voxel
  • I tested the JLab giant headphone speakers. I have opinions!
  • Chrome still doesn’t have extensions on Android, so I found a browser that does
  • Pokémon TCG First Partner Illustration Collection preorders — buy now for under $70 at Amazon
  • The DJI Mini 5 Pro drone has hit its best-ever price at Amazon — save $500 this weekend

Recent Comments

    No Result
    View All Result

    Categories

    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi
    • Home
    • Shop
    • Privacy Policy
    • Terms and Conditions

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    No Result
    View All Result
    • Home
    • Blog
    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    Get more stuff like this
    in your inbox

    Subscribe to our mailing list and get interesting stuff and updates to your email inbox.

    Thank you for subscribing.

    Something went wrong.

    We respect your privacy and take protecting it seriously