0%
BACK TO OVERVIEW

Hacking Biometrics: Bypassing Fingerprint, Face, Voice, and Vein Recognition – How secure are Access Control Systems really?

Hacking Biometrics: Bypassing Fingerprint, Face, Voice, and Vein Recognition – How secure are Access Control Systems really?
27.8 Million Records in Plain Text: The Suprema Breach and the Paradox of Unchangeable Data

27.8 Million Records in Plain Text. The Suprema Breach and the Paradox of Unchangeable Data

Whether it's a smartphone, a laptop, or an office door – biometrics promises security with minimal effort. But what happens when the very physical traits that make someone unique become a security risk?

Just how vulnerable this technology can be was proven in 2019 by the South Korean company Suprema. A massive data breach in its web-based platform BioStar 2 suddenly exposed 27.8 million records belonging to more than a million people in a publicly accessible database. This included passwords, usernames, and, for more than a million users, unencrypted fingerprints and facial recognition records. All of it stored in plain text and freely accessible online.

The case exposes the fundamental risk of biometric authorization: a hacked password can be changed in seconds – a compromised fingerprint or face stays compromised for life. This is exactly where the problem begins: how easily biometric access systems can be defeated, and which protective measures actually work.

What biometrics is and what makes it so popular

Biometric information refers to any kind of measurement data about a person's biological or behavioral characteristics. In theory, almost any physical trait can be used for identification – from gait to body temperature to individual handwriting. In practice, a specific set dominates:

Biometric Definition
Fingerprint The classic among these methods. A sensor captures the fine ridges and branches of the skin on the fingertip and converts this unique pattern into a digital code.
Face A camera analyzes the characteristic features of the face – such as the distance between the eyes, the nose, or the jawline. Modern systems use 3D scans to make forgery harder.
Iris An infrared camera scans the fine, colored pattern of the iris. This network of lines and points is extremely complex, unique to every person, and barely changes over a lifetime.
Veins A highly precise trait. The structure of the vein network is typically captured using near-infrared light, since blood absorbs this light more strongly than the surrounding tissue.
Voice The system measures the geometry of the vocal cords and vocal tract through acoustic analysis.

According to the vzbv market overview (as of January 2024), the most commonly used methods are fingerprint and facial recognition.

These systems are used for authentication, meaning identity verification – either as identification (who is this person?) or verification (is this person really Person X?).

Application examples:

  • Unlocking a device (e.g. laptop, smartphone, tablet, or individual apps)
  • Logging into a user account
  • ID checks, e.g. at airports, where the face is compared to the photo on the ID document
  • Government recognition systems (e.g. at train stations/airports)
  • Access control, i.e. for applications requiring a high level of recognition accuracy
  • General examples: computers, hospitals, ATMs

Whether for personal devices, digital services, ID checks, or physical access systems – the range of applications is broad. The reason for the popularity of biometric traits is obvious. Alongside a high level of security, they offer an inherent, permanent link to the user. Unlike passwords or physical keys, they can't be lost or forgotten, since they're always carried by the person themselves. This makes everyday authentication extremely convenient.

The basic principle of matching

For biometric data to be usable at all, it must be measurable, unique, and stable over time. Authentication follows a basic principle:

  1. Enrollment: During enrollment, the trait is captured for the first time and stored as a reference template.
  2. Matching: At login, the system compares the newly captured sample against the stored template for sufficient similarity. On a match, the device confirms correct recognition and grants access.
  3. Threshold decision: A biometric system never delivers a hundred-percent match, only a statistical probability score. The system's decision is based on a threshold value defined by the manufacturer.

The larger the tolerance allowed by the threshold, the lower the False Rejection Rate (FRR), but the higher the security risk from the False Acceptance Rate (FAR) becomes. A threshold that is too lenient also lets similar, unauthorized traits through.

Vulnerability, and how attackers crack biometrics

The core weakness lies in the fact that physical traits are not secret at all. They are left behind everywhere, and unlike passwords, they can't be changed at will. Once a fingerprint is compromised, criminals can use it to unlock devices, compromise linked services and accounts (if the same biometric is reused), bypass multi-factor authentication, commit identity theft, spread disinformation, or carry out fraud such as modern impersonation scams.

The methods used to trick these systems keep getting more sophisticated, but they all ultimately follow the same principle: acquiring material to precisely replicate the biometric trait.

Fingerprint

Fingerprint biometrics is well established, but it can still be tricked using both analog and highly modern digital methods. The following approaches show how attackers proceed, from physical mold-making to acoustic side-channel attacks.

Variant 1
Direct impression
A finger is pressed directly into a moldable material (e.g. filler putty, modeling clay, or similar) to create a negative mold of the skin ridges. This mold is then filled with a flexible material (e.g. gelatin or silicone) that, once cured, reproduces the three-dimensional pattern of the original finger.
Variant 2
Latent print forgery
An indirect method with a far more accurate result, in which fingerprints left on a surface – so-called latent prints – are made visible, for example using fine powder, and captured via photograph using specialized techniques. The lifted pattern is then used (e.g. via circuit boards or film transfer) to produce a mold for creating the forged fingerprint.
Variant 3
Modern approach via PrintListener
Beyond classic approaches, there are now numerous additional ways to hack a user's fingerprint – such as the modern side-channel attack known as PrintListener, a kind of eavesdropping technique that analyzes the swiping sounds of a user's fingertip on the screen to extract fingerprint features. In real-world scenarios, this approach achieved a success rate of up to 26.5% for partial fingerprints and 9.3% for full fingerprints within five attempts at the highest security level.

Face & Voice

Thanks to rapid advances in generative AI models, visual and acoustic biometric data can now be forged at high quality. Attackers use these deepfake technologies to bypass real-time identity checks.

Variant 1
Face swapping & reenactment
Using generative AI, the victim's face is replaced in real time with another face and mapped onto a video. Facial expressions, lighting, and head movements are adapted through reenactment. This allows an attacker to put words in a person's mouth that this person would never actually say or do.
Variant 2
Text-to-speech & voice conversion
Just a few seconds of audio are enough for AI algorithms to realistically resynthesize a human voice through so-called voice cloning, or to make an attacker's own voice sound like the victim's in real time.

Vein recognition

Recognition of hand or finger vein patterns is considered one of the most secure biometric methods, since the traits lie beneath the skin. However, with the right technique, these infrared patterns can also be captured and replicated without the victim noticing.

Variant 1
Replicating the blood vessels

The vein pattern already forms in the sixth week of pregnancy and is genetically unique due to random developmental processes. Even so, it can be attacked:

Attackers capture the pattern, for example, using a digital single-lens reflex camera (DSLR) fitted with a suitable infrared filter and specific settings (such as wavelength, exposure time, grayscale levels).

This capture can happen very covertly, for instance by hiding the DSLR camera inside an ordinary hand dryer in a public place. When the victim dries their hands, the system silently creates a copy. After digital image processing and contrast enhancement of the blood vessels, a physical replica is produced via laser, 3D printing, or conductive specialty printing, which can then be used to reproduce the vein structure and gain access to certain services or access-controlled areas.

How do you protect something that can't be changed?

Since biometric traits can't be changed like a password, and these traits are permanently carried around in the open, it's worth using them sparingly and following these rules for the best possible protection against attacks:

  • Only use biometric traits for trustworthy applications, and don't blindly trust every app or device that captures biometric data.
  • Don't use the same biometric trait across all levels – for example, use the thumb to unlock a smartphone, but the index finger for authentication in security apps.
  • Use a second factor, so that logging into a user account requires both a password and a fingerprint.
  • Keep operating systems and software up to date at all times to shut down newly discovered exploits as much as possible.

Conclusion: Convenience with an expiration date

Biometric authentication undeniably offers total convenience in everyday digital life: a quick glance, a quick touch – and the system opens. The problem is fundamental: physical traits are public and unchangeable. While a hacked password can be changed in a few clicks, a compromised fingerprint, a forged facial recognition template, or a cloned voice is lost for life. Attackers keep escalating – from simple silicone casts to hidden infrared cameras in hand dryers to AI-powered deepfakes and acoustic side-channel attacks.

The key takeaway for practice: biometrics is an excellent booster for convenience, but not an unbeatable cure-all. Real protection only comes from being sparing with data sharing, diversifying which traits are used where, and above all, consistently using two-factor authentication. Because even the most secure biometric only becomes truly effective when combined with a strong password.

How secure are your biometric access systems, really?

We test your fingerprint, facial, or vein recognition systems against real-world attack scenarios – from simple spoofing attempts to complex side-channel attacks. Free initial consultation.

Request a consultation →
Tags // #Biometrics #2FA #Fingerprint-Recognition #Facial-Recognition #Vein-Recognition #Voice-Recognition #Access-Control

© AccessGranted X GmbH