Researchers hack Galaxy S5's fingerprint scanner

Samsung logoReseachers at Germany's Security Research Labs sneaked past Samsung's fingerprint security by using a fingerprint spoof.

In a video of the hack, a researcher from Security Research Labs demonstrated how he was able to bypass the fingerprint security by using a "wood glue spoof" made from a mold taken from a photo of a fingerprint smudge left on a smartphone screen. It is actually the same technique used to hack past the fingerprint scanner in Apple's iPhone 5S last year.

But the S5's fingerprint scanner allows for multiple incorrect attempts without requring a password. So someone could potentially keep trying one fingerprint spoof after another until access is finally achieved.

Samsung Galaxy S5

The Galaxy S5's fingerprint scan can also be associated with apps such as PayPal, and the video shows a person that managed to log in to access a Paypal account.

"Despite being one of the premium phone's flagship features, Samsung's implementation of fingerprint authentication leaves much to be desired," the researcher in the video said. "The finger scanner feature in Samsung's Galaxy S5 raises additional security concerns to those already voiced about comparable implementations."

PayPal issued the following statement:

"While we take the findings from Security Research Labs very seriously, we are still confident that fingerprint authentication offers an easier and more secure way to pay on mobile devices than passwords or credit cards. PayPal never stores or even has access to your actual fingerprint with authentication on the Galaxy S5. The scan unlocks a secure cryptographic key that serves as a password replacement for the phone. We can simply deactivate the key from a lost or stolen device, and you can create a new one. PayPal also uses sophisticated fraud and risk management tools to try to prevent fraud before it happens. However, in the rare instances that it does, you are covered by our purchase protection policy."

Source: CDRinfo

Tags: Galaxy S5, Samsung, security, smartphones

Comments
Add comment

Your name:
Sign in with:
or
Your comment:


Enter code:

E-mail (not required)
E-mail will not be disclosed to the third party


Last news

 
Google’s voice assistant platform has been known as Google Now
 
The SanDisk 1TB SD card prototype represents another significant achievement as growth of high-resolution content
 
Microsoft is developing a new “Skype for Life” client
 
Siri on the Mac is new, and is similar to that on the iOS
 
The latency in this test was supposedly no more than 2 milliseconds
 
Apple has made to the iPhone 7/7 Plus is by making the home button a solid state button
 
Android Nougat should eventually extend back to the Galaxy S6 generation
 
You’re not supposed to expose the iPhone to water anyway
Samsung Galaxy TabPro S - a tablet with the Windows-keyboard
The first Windows-tablet with the 12-inch display Super AMOLED
June 7, 2016 /
Keyboards for iOS
Ten iOS keyboards review
July 18, 2015 /
Samsung E1200 Mobile Phone Review
A cheap phone with a good screen
March 8, 2015 / 4
Creative Sound Blaster Z sound card review
Good sound for those who are not satisfied with the onboard solution
September 25, 2014 / 2
Samsung Galaxy Gear: Smartwatch at High Price
The first smartwatch from Samsung - almost a smartphone with a small body
December 19, 2013 /
HP Slate 7 is a 7-inch Android 4 Tablet PC with good sound
A cost-effective, 7-inch tablet PC from a renowned manufacturer
October 25, 2013 / 4
 
 

News Archive

 
 
SuMoTuWeThFrSa
    123
45678910
11121314151617
18192021222324
252627282930 




Poll

Do you like Windows 10?
or leave your own version in comments (32)