22 May 2023

BrutePrint: A new technique to bypass phone fingerprint authentication


BrutePrint: A new technique to bypass phone fingerprint authentication

A group of Chinese academics have devised a new attack method they dubbed “BrutePrint” that can bypass user authentication on modern smartphones by brute-forcing fingerprints.

The BrutePrint attack involves the exploitation of two security weaknesses called Cancel-After-Match-Fail (CAMF) and Match-After-Lock (MAL), which allows to bypass existing security measures.

The researchers found that biometric data stored on fingerprint sensors’ Serial Peripheral Interface (SPI) is susceptible to Man-in-the-Middle (MITM) attacks due to the lack of proper protection, thus enabling threat actors to intercept and hijack fingerprints images.

The technique requires the attacker to have physical access to the target device, access to a fingerprint database, and equipment costing around $15.

According to the researchers, it only takes between 2.9 and 13.9 hours to break a fingerprint using BrutePrint. A series of experiments involving ten Android and iOS devices showed that Android devices were susceptible to unlimited fingerprint attempts, while iOS devices resisted the brute-forcing attacks, as iPhones encrypt fingerprints in SPI.


Back to the list

Latest Posts

Free VPN provider SuperVPN exposes 360 million user records

Free VPN provider SuperVPN exposes 360 million user records

In total, 133GB of sensitive data including user email addresses, original IP addresses, and geolocation information is said to have been exposed in the leak.
29 May 2023
Cyber security week in review: May 26, 2023

Cyber security week in review: May 26, 2023

The world in brief: New ICS malware discovered, hacktivists expose Russian hacker wanted in the US, Pegasus spyware found in Armenia and Azerbaijan, and more.
26 May 2023
Barracuda’s email gateway appliances breached via zero-day bug

Barracuda’s email gateway appliances breached via zero-day bug

The vulnerability resided in a module which initially screens the attachments of incoming emails.
25 May 2023