Beijing has repeatedly insisted that the government played no role in the intrusions, which compromised sensitive personal, financial and biometric data of the employees, and data on their families.
Showing posts with label finger print. Show all posts
Showing posts with label finger print. Show all posts
Thursday, December 3, 2015
China: Arrests in US OPM case
Chinese government has arrested hackers it says breached OPM database (Washington Post)
Thursday, April 23, 2015
Older Andriod versions had more vulnerabilities
Is Samsung's Galaxy S5 'leaking' YOUR fingerprints? Flaw means hackers can intercept and steal biometric data (Daily Mail); Forbes piece, here.
A close reading of the article reveals that earlier releases of Google's version of the Android mobile OS weren't as secure as they are now. This will come as news to few. The article points out that, "Once inside they can monitor all data sent to and from the phone, as well as data recorded by the handset's built-in sensors, including the fingerprint scanner."
Get it? Exploiting the security flaw means that the whole device is compromised: Email apps, microphone, location information, and possibly even the contents of phone calls themselves, but according to the author and editor(s), the news value is in the possibility of capturing a fingerprint image. Of course, it's their outfit; it's their call.
For readers here, instead of "OMG fingerprinst[!]," I'd emphasize that:
Not all mobile operating systems are created equal.
Different mobile applications offer a different mix of privacy costs and benefits.
Installing OS updates and patches is very important.
If the OS is compromised, the applications it runs are vulnerable.
Left out of the information readily available online about this hack is how the people at FireEye got their malware onto the hardware in the first place. Past "hacks" of biometric systems have been executed on a playing field that is far more favorable than the real world to the the hackers, where all the other layers of the security regime are stripped away from the one security link they want to test. Here's a particularly striking example. If FireEye rooted the phone, side-loaded their malware onto the device, and went from there, this isn't a hack in any real sense — it's a malware test.
That hypothetical scenario would mimic a real world example where a user lost their phone and bad guys got it, loaded software on it and then returned the mobile device to the user who continued as if nothing had happened. In the security world, if you lose control of the hardware, all bets are off for anything that isn't encrypted (with a strong key).
So, without more information, it's hard to say how big a deal this is, or in many (most?) cases, was. In the bigger picture, this is a Google Android OS story. The subtext is that users who care about mobile device security should be thoughtful about what device/OS/app combinations they adopt, keep their device's software up to date, and be careful about malware.
As automated and convenient security including biometrics becomes better and more common, the highway robbers of the 21st Century are increasingly forced to turn to social engineering techniques rather than frontal assaults on security technology.
See: The Con is Mightier than the Hack
The pair told Thomas Fox-Brewster from Forbes that the flaw lies in older versions of the Android operating system, up to and including Android 4.4.The semi-technical press seizes upon biometrics as a proxy for personal data. This is old news, but here's a great example.
Subsequently, anyone running Android 5.0 or above are not at risk and the security experts are advising people on older models to update as soon as possible.
A close reading of the article reveals that earlier releases of Google's version of the Android mobile OS weren't as secure as they are now. This will come as news to few. The article points out that, "Once inside they can monitor all data sent to and from the phone, as well as data recorded by the handset's built-in sensors, including the fingerprint scanner."
Get it? Exploiting the security flaw means that the whole device is compromised: Email apps, microphone, location information, and possibly even the contents of phone calls themselves, but according to the author and editor(s), the news value is in the possibility of capturing a fingerprint image. Of course, it's their outfit; it's their call.
For readers here, instead of "OMG fingerprinst[!]," I'd emphasize that:
Not all mobile operating systems are created equal.
Different mobile applications offer a different mix of privacy costs and benefits.
Installing OS updates and patches is very important.
If the OS is compromised, the applications it runs are vulnerable.
Left out of the information readily available online about this hack is how the people at FireEye got their malware onto the hardware in the first place. Past "hacks" of biometric systems have been executed on a playing field that is far more favorable than the real world to the the hackers, where all the other layers of the security regime are stripped away from the one security link they want to test. Here's a particularly striking example. If FireEye rooted the phone, side-loaded their malware onto the device, and went from there, this isn't a hack in any real sense — it's a malware test.
That hypothetical scenario would mimic a real world example where a user lost their phone and bad guys got it, loaded software on it and then returned the mobile device to the user who continued as if nothing had happened. In the security world, if you lose control of the hardware, all bets are off for anything that isn't encrypted (with a strong key).
So, without more information, it's hard to say how big a deal this is, or in many (most?) cases, was. In the bigger picture, this is a Google Android OS story. The subtext is that users who care about mobile device security should be thoughtful about what device/OS/app combinations they adopt, keep their device's software up to date, and be careful about malware.
As automated and convenient security including biometrics becomes better and more common, the highway robbers of the 21st Century are increasingly forced to turn to social engineering techniques rather than frontal assaults on security technology.
See: The Con is Mightier than the Hack
Labels:
finger print,
google,
hack,
hardware,
mobile,
Samsung,
security,
software,
technology
Friday, May 6, 2011
South Africa Criminal record checks go biometric
IT Web
SA's newest credit information bureau, Inoxico, last week unveiled a biometric fingerprint scanning facility as the sector needs to comply with the police's digital system.The bolded section is often overlooked in the Identity management conversation.
The move is expected to speed up industry queries into whether prospective employees have criminal records. CIO Marius van Niewenhuizen adds the biometric facility will also help clear job applicants who are incorrectly thought to have records, because of inaccuracies when data is captured.(emphasis mine)
Thursday, May 5, 2011
Malaysia to start fingerprinting visitors
Foreigners entering and leaving the country will have both index fingers scanned at Immigration checkpoints beginning next month (New Straits Times)
And Also:
Malaysia to start fingerprint check of foreigners (Press Trust of India)
Malaysia's strategic location abutting some of the world's most important sea trade routes subjects it to risks that it has an obligation to address (see: Don’t mess with Malaysia, human traffickers warned (The Star)). Biometric technologies can help countries develop the efficient and needed law enforcement mechanisms that other countries spent much more time and money to implement.
Malaysia (CIA World Factbook)
The procedure is a new security feature to curb transboundary crime and terrorism.
Called the biometric fingerprint security system, it is aimed at enhancing security in the immigration clearance process, which currently involves only the stamping of passports and matching photographs in the passports to faces.
And Also:
Malaysia to start fingerprint check of foreigners (Press Trust of India)
Immigration officials said that with rampant forgery of travel documents nowadays, the biometric system would allay this worry.It is commonly assumed that governments implement biometric ID management techniques in some Orwellian effort to control people. But governments have obligations to their citizens and to neighboring countries. They have a duty to their citizens to prevent their victimization by those who would do them harm and they have a duty to neighboring countries not to provide a safe haven for those who would victimize citizens of neighboring countries.
Immigration Department director general Mr Alias Ahmad said such a security measure was deemed necessary in view of the increasing number of foreigners who had abused their privileges as visitors.
Malaysia's strategic location abutting some of the world's most important sea trade routes subjects it to risks that it has an obligation to address (see: Don’t mess with Malaysia, human traffickers warned (The Star)). Biometric technologies can help countries develop the efficient and needed law enforcement mechanisms that other countries spent much more time and money to implement.
Malaysia (CIA World Factbook)
Wednesday, May 4, 2011
Israel to issue 'world's most secure passport'
Biometric passports will include computer chip with photo, finger prints (ynet)
After years of delays Israel is finally getting ready to embark on a new age of biometric identification. In the coming months, Israeli citizens will be asked to replace their old passports and identity cards with new sophisticated means of identification.Perhaps because Israel's other security methods are so effective, Israel is actually somewhat late to the biometric passport party.
Friday, April 29, 2011
People are sick of passwords
It's becoming obvious that users interacting with more and more networked systems and services are being crushed under the burden passwords impose if they are to be used effectively to maximize security.
Pass On Passwords (Harvard Crimson)
Template only biometric applications are far superior to passwords and they sidestep the concerns raised about biometrics in this article. Middleware providers like SecurLinx can ensure against ID management risks even in the event that the templates are stolen, even if the customer doesn't even know they have been stolen.
Biometrics work.
Passwords are lame.
I believe we are nearing a tipping point where ordinary individuals begin more vocally to demand biometric ID management solutions. The status quo doesn't work and we're not going to be taking a time machine back to the single-password bliss of 1995.
Pass On Passwords (Harvard Crimson)
Think for a moment about your bank account password. There's a good chance it's a string of letters and numbers you know by heart, could type in your sleep, and have been using for years. You probably use it for at least one other website, too—a security study last year found that 73 percent of people use their bank password elsewhere.
Template only biometric applications are far superior to passwords and they sidestep the concerns raised about biometrics in this article. Middleware providers like SecurLinx can ensure against ID management risks even in the event that the templates are stolen, even if the customer doesn't even know they have been stolen.
Biometrics work.
Passwords are lame.
I believe we are nearing a tipping point where ordinary individuals begin more vocally to demand biometric ID management solutions. The status quo doesn't work and we're not going to be taking a time machine back to the single-password bliss of 1995.
Thursday, April 21, 2011
A fingertip solution?
Much of today's news seems to be coming from the UK.
Here's an article that applied biometric fingerprint technology to the challenges faced by those in positions of responsibility for the elderly.
Fingerprint recording technology has the potential to make life easier for elderly and vulnerable people (PublicService.co.uk)
Here's an article that applied biometric fingerprint technology to the challenges faced by those in positions of responsibility for the elderly.
Fingerprint recording technology has the potential to make life easier for elderly and vulnerable people (PublicService.co.uk)
Fingerprint biometric systems can help to support the safety and security of many people, ranging from the elderly and infirm to someone with an armful of shopping. For the elderly and vulnerable, it can help by allowing them to signal that they are up, are active during the day and have gone to bed safely. The technology is available to accurately scan and record fingerprints with reader technology that is robust and reliable. The other attraction is its simplicity in use, just requiring the reader to place the finger on a pad to take a positive scan. The pad won't be lost like a key or swipe card.
Wednesday, April 20, 2011
Biometric Authentication the Key to Keeping Businesses and Users Happy
Biometric authentication is more convenient (ITPro.co.uk)
Biometrics aren’t just useful for protecting confidential data. Construction firm Killby & Gayford is using custom fingerprint readers (built for personnel management software supplier Simeio by Psion) that also record a signature. That means the firm can accurately log hours worked by sub-contractors on building sites and automatically generate invoices, as well as proving that workers have read the safety rules for each site and simplify checking the roll call if there’s an emergency. Using the information to generate accurate invoices has avoided concerns about spying on staff by showing the system is useful to everyone. But, equally, productivity has improved too.A good survey of biometric modalities and applications.
Tuesday, April 19, 2011
Villages leapfrog the grid with biometrics and mobile money
In low-tech villages, biometrics and mobile money can level market spikes and allow a way for people to bypass the grid (Christian Science Monitor)
Widespread fingerprinting is controversial in Western nations, but in countries where births aren't recorded, people lack official identification, and many can't even sign their names, fingerprints might be a person's best shot at securing a bank account.ID management is about people. Biometrics can help the worlds poor more fully participate in the markets that have lifted billions worldwide out of poverty.
Friday, April 15, 2011
UK Headteachers condemn new biometrics legislation
Heads’ anger at ‘backward step’ on fingerprints (Liverpool Daily Post)
On the positive side: for the student, fingerprint biometrics offer increased privacy* and safety**; the school achieves higher data integrity and increased operational efficiency. These benefits are not simply confined to the schools themselves. All taxpayers have a stake in the efficient use of educational resources.
If schools are unable to keep data secure, biometric template information is the last thing that should concern parents or civil liberties campaigners.
Schools also keep academic records, behavioral records, medical records & counseling notes which are much more sensitive than a string of binary gibberish that cannot be used to learn anything about a student.
*Privacy: If everyone uses a finger to buy lunch, no one knows who receives need-based subsidized or free lunches.
**Safety: No lunch money, no bullying to steal lunch money.
The Association of School and College Leaders (ASCL) warned the move will cost the education system between £20m and £45m a year.Fingerprint systems that store only an algorithm-generated template rather than an image of a fingerprint pose little-or-no threat to a person's biometric privacy.
It is thought that around 30% of secondary schools use finger or face recognition for a number of reasons, such as allowing pupils to check out library books, pay for lunch in the school canteen or access certain school buildings.
Evidence suggests that in these schools that have so-called biometric systems, 99.8% of parents have no objection to it, the ASCL said.
On the positive side: for the student, fingerprint biometrics offer increased privacy* and safety**; the school achieves higher data integrity and increased operational efficiency. These benefits are not simply confined to the schools themselves. All taxpayers have a stake in the efficient use of educational resources.
If schools are unable to keep data secure, biometric template information is the last thing that should concern parents or civil liberties campaigners.
Schools also keep academic records, behavioral records, medical records & counseling notes which are much more sensitive than a string of binary gibberish that cannot be used to learn anything about a student.
*Privacy: If everyone uses a finger to buy lunch, no one knows who receives need-based subsidized or free lunches.
**Safety: No lunch money, no bullying to steal lunch money.
Thursday, April 14, 2011
ICE Secure Communities adds counties in MD, MI & SC
Maryland (Press Release via Yahoo)
Michigan (Press Release via Yahoo)
South Carolina (The Times and Democrat)
The Maryland counties added are of local interest to us here in West Virginia. All three counties border West Virginia. Garrett county lies about 25 miles east of Morgantown.
On Tuesday, U.S. Immigration and Customs Enforcement (ICE) began using the Secure Communities program in Alleghany, Garrett and Washington counties to help federal immigration officials identify criminal aliens in state prisons and local jails by running their fingerprints against federal immigration databases when they are booked into the system.
Michigan (Press Release via Yahoo)
U.S. Immigration and Customs Enforcement (ICE) began using the Secure Communities program in seven Michigan counties including Allegan, Barry, Calhoun, Jackson, Kalamazoo, Muskegon and Ottawa...
South Carolina (The Times and Democrat)
U.S. Immigration and Customs Enforcement has started using the Secure Communities program in Orangeburg and other counties to help identify criminal aliens in local jails by running their fingerprints against federal immigration databases.
The Maryland counties added are of local interest to us here in West Virginia. All three counties border West Virginia. Garrett county lies about 25 miles east of Morgantown.
Wednesday, April 13, 2011
Update: 300% ROI in first year on biometric time-and-attendance system
The Video at the link (M2SYS blog) documents a great discussion between John Trader of M2SYS and Sharon Fradella of the Cal Poly Pomona Foundation.
The short conversation hits all the high notes: modality, user acceptability, and ROI.
Based upon her experience with biometric time-and-attendance, Ms. Fradella expects Cal Poly Pomona to increase its adoption of biometric ID management technologies.
Earlier post on the topic here.
The short conversation hits all the high notes: modality, user acceptability, and ROI.
"The employees and managers like it because it's fast, easy, and especially, accurate."
Based upon her experience with biometric time-and-attendance, Ms. Fradella expects Cal Poly Pomona to increase its adoption of biometric ID management technologies.
Earlier post on the topic here.
Wednesday, April 6, 2011
Tenafly New Jersey Little League requires Fingerprinting Of All Volunteers
A New Jersey Little League is taking safety up a notch (CBS, New York - via Drudge)
Prompted by Carl Findlay's comments in the article, I searched "David Hartshorn". What I found is heartbreaking:
Queens, NY Little League coach accused of molestation; Cops look for more victims (ABC, New York)
Queens and Tenafly are 22 miles apart.
Tenafly Little League president John Preolo said the league had to require fingerprinting this year because of a much-needed grant.
“To get the grant there is certain criteria that had to be met. One of them is the fingerprinting process. If the town didn’t agree to get coaches and volunteers fingerprinted, I don’t think we would have gotten the money,” Preolo said.
Prompted by Carl Findlay's comments in the article, I searched "David Hartshorn". What I found is heartbreaking:
Queens, NY Little League coach accused of molestation; Cops look for more victims (ABC, New York)
Queens and Tenafly are 22 miles apart.
Monday, March 28, 2011
Malaysia biometric database to monitor borders
Criminals beware! (The Malay Mail)
Police are set to have a new weapon which will enable them to monitor the comings and goings of known foreign criminals.Malaysia really has been active in terms of government implementation of biometric ID management systems lately.
Come June 1, their existing criminal database, the Biometric Fingerprint Identifi cation System (BIOFIS), will be linked up to Immigration Department’s National Foreigners Enforcement and Registration System (NERS).
This will grant police access to records of foreign visitors who enter Malaysia via immigration checkpoints, and ensure those with criminal records in Malaysia can be monitored closely.
Scientific background on the new Indian identity
Meet Samarth Bharadwaj and Himanshu Bhatt (Times of India)
As to his role in the UIDAI project at the IIIT-Delhi , Bharadwaj, a second-year research student said that they had begun working on the project last year. "Four research students from our college conducted a feasibility study on finger prints of labourers and farmers — people who work with their hands — to analyse the quality of their fingerprints and find out if they can be used as a part of unique identification," said Bhatt.
Friday, March 18, 2011
Malaysia to install fingerprint immigration system
The National Foreigners Enforcement and Registration System (NERS) (TheStar.com.my)
Foreigners entering the country from June 1 will have their thumbprints taken under a biometric system to enhance security at 96 entry points.Just having an automated way to know with certainty how many people overstay their visa is probably worth the investment. A system that can do that can also do so much more.
The National Foreigners Enforcement and Registration System (NERS) would register and monitor foreigners from their arrival until departure, said Deputy Prime Minister Tan Sri Muhyiddin Yassin.
Wednesday, March 16, 2011
Biometrics Becoming Popular for Access Control at Rec Facilities
For many facilities, the Return on Investment is irresistible (AthleticBusiness.com)
Earlier posts on deployments mentioned in the above linked article:
Poway Tells Skaters to Give Them the Finger (7/10/2010)
Montgomery recreation department moves ahead with finger vein scanners (11/17/2010)
"Simply, we were hoping to utilize the technology that was available and also keep our expenses lower by not having to issue membership cards to every one of our members," LeeAnn Plumer, director of the Annapolis, Md., recreation and parks department, says of the biometrics-based access control system the department launched in January 2010 with the opening of the city's largest recreation center. "We were using new software that had the technology to implement biometrics, so we thought we'd give it a try and see how it worked for us."via @m2sys (Twitter)
Most rec departments using the technology are indeed still in the "give it a try" phase, and the reviews are mostly positive.
Proud that this is our technology > #Biometrics Becoming Popular for Access Control at Rec FacilitiesDeployments like these validate the efforts of all of us that are working to bring more efficient techniques to the challenge of identity management.
Earlier posts on deployments mentioned in the above linked article:
Poway Tells Skaters to Give Them the Finger (7/10/2010)
Montgomery recreation department moves ahead with finger vein scanners (11/17/2010)
Thursday, March 10, 2011
FBI switches to faster fingerprint identification technology
New system could reduce print matching time to ten minutes (CIO.co.uk)
The old AFIS fingerprint-matching system took up to two hours to respond to a fingerprint pattern-matching request in criminal cases and 24 hours for civil cases, says Traxler. "Our goal for criminal prints is now 10 minutes, and civil, 15 minutes," says Traxler.John Traxler is the program manager for NGI in the FBI's Clarksburg, WV facility. Clarksburg is right down the road from our offices in Morgantown.
This is what Secure Communities actually does
Border-crosser wanted on other charge (El Paso Times)
Other posts on ICE Secure Communities.
One of six people allegedly found crossing the border near Santa Teresa was discovered to be wanted on a charge of molesting a child in Bernalillo County, according to the U.S. Border Patrol.U.S. Border Patrol nabs alleged sexual offender at station (Alamogordo Daily News)
Adrian Armendariz, 36, of Mexico, was positively identified as having an outstanding warrant for alleged criminal sexual contact of a minor in Bernalillo County. Records also indicated that Armendariz has an extensive criminal history that includes trafficking cocaine, aggravated assault of household member and transportation and selling of controlled substances.These two articles apparently describe the same event.
Other posts on ICE Secure Communities.
Monday, March 7, 2011
All California counties have activated Secure Communities
Secure Communities Program Uses Biometrics to Target Illegal Immigrants (Emergency Management)
Since May 2009, when San Diego County became the first California jurisdiction to activate Secure Communities, ICE has taken custody of nearly 48,000 convicted criminal aliens in the state.
Subscribe to:
Posts (Atom)