Showing posts with label software. Show all posts
Showing posts with label software. Show all posts

Thursday, April 23, 2015

Older Andriod versions had more vulnerabilities

Is Samsung's Galaxy S5 'leaking' YOUR fingerprints? Flaw means hackers can intercept and steal biometric data (Daily Mail); Forbes piece, here.
The pair told Thomas Fox-Brewster from Forbes that the flaw lies in older versions of the Android operating system, up to and including Android 4.4.

Subsequently, anyone running Android 5.0 or above are not at risk and the security experts are advising people on older models to update as soon as possible.
The semi-technical press seizes upon biometrics as a proxy for personal data. This is old news, but here's a great example.

A close reading of the article reveals that earlier releases of Google's version of the Android mobile OS weren't as secure as they are now. This will come as news to few. The article points out that, "Once inside they can monitor all data sent to and from the phone, as well as data recorded by the handset's built-in sensors, including the fingerprint scanner."

Get it? Exploiting the security flaw means that the whole device is compromised: Email apps, microphone, location information, and possibly even the contents of phone calls themselves, but according to the author and editor(s), the news value is in the possibility of capturing a fingerprint image. Of course, it's their outfit; it's their call.

For readers here, instead of "OMG fingerprinst[!]," I'd emphasize that:

Not all mobile operating systems are created equal.
Different mobile applications offer a different mix of privacy costs and benefits.
Installing OS updates and patches is very important.
If the OS is compromised, the applications it runs are vulnerable.

Left out of the information readily available online about this hack is how the people at FireEye got their malware onto the hardware in the first place. Past "hacks" of biometric systems have been executed on a playing field that is far more favorable than the real world to the the hackers, where all the other layers of the security regime are stripped away from the one security link they want to test. Here's a particularly striking example. If FireEye rooted the phone, side-loaded their malware onto the device, and went from there, this isn't a hack in any real sense — it's a malware test.

That hypothetical scenario would mimic a real world example where a user lost their phone and bad guys got it, loaded software on it and then returned the mobile device to the user who continued as if nothing had happened. In the security world, if you lose control of the hardware, all bets are off for anything that isn't encrypted (with a strong key).

So, without more information, it's hard to say how big a deal this is, or in many (most?) cases, was. In the bigger picture, this is a Google Android OS story. The subtext is that users who care about mobile device security should be thoughtful about what device/OS/app combinations they adopt, keep their device's software up to date, and be careful about malware.

As automated and convenient security including biometrics becomes better and more common, the highway robbers of the 21st Century are increasingly forced to turn to social engineering techniques rather than frontal assaults on security technology.

See: The Con is Mightier than the Hack



Thursday, May 30, 2013

Face rec for quality assurance

Edinburgh Airport installs biometric system to track passenger movements (Computerworld UK)
An anonymous facial image is taken of each passenger as they check in and the time it takes each to reach certain waypoints plotted over time. If this time breaches a pre-set parameter for enough passengers, alerts can be generated.

The principle is that moving passengers from check in to the terminal increases their satisfaction with that airport and boosts the amount of time they have to spend money in the retail outlets that generate profit for airports.

The system can also be used to track the movement of passengers through the airport as a whole.
This is another really interesting application for facial recognition technology and, unlike other uses of face technology better described as demographic detection, this one actually is a true face recognition application.

Although it is a true face recognition application, it isn't really an ID application so long as the facial image taken at the time of passenger is not linked to other personal information and it is deleted after the person reaches the "finish line."

The item of interest to airports in this case is the length of time it takes real individuals to travel through various points between check in and the jetway. It's a more sophisticated measure than a simple count and real-world measurement wasn't easily automated before face recognition technology.

Airports in the UK have been early adopters of face recognition for this application because they are held to certain performance metrics (and subject to fines) for airport throughput. Having accurate real-time information on passenger flows can inform on-the-fly staffing decisions. For example, additional security screeners can be dispatched in the event a slow-down is detected, saving passenger time and the airport money.

Though airports have been early adopters, this basic application has obvious utility in shopping malls, department stores, planning for emergency evacuations, and large facility scheduling.

SecurLinx has experience in the design and deployment of this type of system. Our FaceTrac system is readily adapted to the challenge of on-the-fly enrollment, finish-line matching, reporting, and automatically purging image data.

Tuesday, April 2, 2013

Start with the applications

10 Big Data Trends From the GigaOM Structure Data Conference (eweek) Good observations having broad applicability in understanding how the recipe for organizational success is being rewritten. Read the whole thing.

Money quote:
While big data might be getting ahead of itself in enterprise promises, it is real in bringing new capabilities to business. You need to think about the skills you have in your company and developing the data skills to adapt to this new model. Open source, which often has a bit of a fringe reputation in the enterprise, will be part of your technology future. Established vendors are going to promise they can give you all the capabilities of the startups with added stability, but I haven't seen any evidence so far. Think about your applications from the outside in, instead of inside out.
The application, not the technology, is everything.

Monday, February 20, 2012

Mobile Devices and Biometric Modalities

Smartphones and tablets combine the most powerful attributes of the networked computer and the cell phone, extending the web into every nook and cranny of the globe.

In one awesomely tiny package they facilitate data collection, storage and access to data stored elsewhere.

As a platform for near field communication (NFC) and SMS One-time passwords, mobile devices are also increasingly being used to deliver identity management applications by using a person's known possession of the device as a way of verifying their identity. In access control lingo, mobile devices are being used as tokens.

Using mobile devices is a dream come true for businesses that rely upon tokens: Your customer already owns it; If they lose it, they will be aware of the loss very quickly and they will replace it at their own expense; People are disinclined to lend their phone/credential to someone else; Etc.

Now to the question of securing the device itself and biometric modalities.

Fingerprints are currently the most frequently used biometric for overtly identifying cooperative, habituated individuals. They have a lot of things going for them. Fingerprints are well-understood scientifically, durable, reliable, and fingerprint ID management techniques have been shown to deliver high return on investment in many applications.

These are some of the reasons I lamented Motorola's announcement that it was leaving the fingerprint sensor out of the Atrix 2. The decision makes sense, though. The fingerprint sensor wouldn't be widely used until developers had written software using it, but including the sensor would drive up the cost of each unit for a thinly-used feature. The innovation chicken-and-egg problem is a real one and Motorola seems to have made the judgement that they weren't gaining enough of an advantage in the highly-competitive mobile device market by including it.

But that hasn't meant the end of mobile device biometrics. Just as businesses that issue tokens have been able to take advantage of the fact that their users are already carrying the necessary technology around with them, biometric identity management application developers are doing the same.

Mobile devices already contain the hardware required to deliver two biometric modalities: a camera for facial recognition and a microphone for voice. These modalities present challenges not usually associated with fingerprint biometrics — in the case of facial recognition challenges include lighting and the well-publicized photograph hack; for voice, background noise can be a problem — but they offer the advantage that the hardware is "free" and never going to be yanked out of mobile devices. That's quite an advantage, and it points to why face and voice biometrics are the front-runners for handset biometrics.

Nice and tidy, eh?

So, what to make of today's news that Fujitsu is set to compete more aggressively in the global handset market?

Fujitsu Aims for European Mobile Phone Market (Financial Times)
Fujitsu’s smartphones will certainly feature electronic money technology – enabling owners to use NFC, the mobile payment system – and biometric recognition to make their use as mobile wallets more secure.
Fujitsu, more than any other handset manufacturer, is deeply involved in biometric sensor hardware (finger, palm) that doesn't currently reside on stock mobile platforms. So stay tuned.