By Dan Goodin
Hackers have broken the iris-based authentication in Samsung’s Galaxy S8 smartphone in an easy-to-execute attack that’s at odds with the manufacturer’s claim that the mechanism is “one of the safest ways to keep your phone locked.”
The cost of the hack is less than the $725 price for an unlocked Galaxy S8 phone, hackers with the Chaos Computer Club in Germany said Tuesday. All that was required was a digital camera, a laser printer (ironically, models made by Samsung provided the best results), and a contact lens. The hack required taking a picture of the subject’s face, printing it on paper, superimposing the contact lens, and holding the image in front of the locked Galaxy S8. The photo need not be a close up, although using night-shot mode or removing the infrared filter helps. The hackers provided a video demonstration of the bypass.
Starbug, the moniker used by one of the principal researchers behind the hack, told Ars he singled out the Samsung Galaxy S8 because it’s among the first flagship phones to offer iris recognition as an alternative to passwords and PINs. He said he suspects future mobile devices that offer iris recognition may be equally easy to hack. Despite the ease, both Samsung and Princeton Identity, the manufacturer of the iris-recognition technology used in the Galaxy S8, say iris recognition provides “airtight security” that allows consumers to “finally trust that their phones are protected.” Princeton Identity also said the Samsung partnership “brings us one step closer to making iris recognition the standard for user authentication.”
Source:: Ars Technica Gadgets
I fail to see the actual security flaw here, unless the hacker knows you and can get you to pose for a picture. The entire idea behind the Iris scanning software is to keep the jackass who stole your phone from getting into it. However, it will certainly make it quite easy for law enforcement to unlock your phone if they need to…
Follow Tim on Twitter @tl1000rzx2
Or check out my other Tablet Site: THE Tablet Test Server
Or you could get your own free WordPress site for free right now, here.