As per new report, fingerprint sensors in Android devices are also allowing hackers to duplicate the user’s fingerprints.
Only a few manufacturers have included biometric fingerprint scanners on their smartphones so far, but this is set to increase as Google announced plans to integrate scanner-related software into the next version of its OS, codenamed Android M.
Zhang noted that Apple’s iPhone, which pioneered the modern fingerprint sensor, is “quite secure”, as it encrypts fingerprint data from the scanner. This fingerprint hacking could result in identity theft accessing data from connected devices to authentication systems.
Security researchers which claimed earlier this year to have revealed serious vulnerabilities in the way Android stores fingerprint data have again stated warnings over the operating system.
“Unlike passwords, fingerprints last a lifetime and are usually associated with critical identities”.
FireEye researchers Tao Wei and Yulong Zhang plan to present new research at the Black Hat conference in Las Vegas next week that details ways hackers can extract fingerprint scans from Android devices. “Thus, the leakage of fingerprints is irredeemable”, read the researcher’s statement.
Fingerprint scanners are slowly becoming a very important feature of a mobile specs sheet. Though companies like Samsung, Huawei, and HTC now produce Android devices with those sensors, Apple still has a significant hold on the market.
The researcher devised four vectors that hackers could use to target fingerprint sensors. It would be easy (presumably) for the Android framework to carry similar protocols, and OEM?s are certainly aware of this and many are updating their devices to solve the issues, and some devices have already been fixed.
In the interim, the researchers take basic measures to protect themselves from attack.
“Also, it is always a good practice to install popular apps from reliable sources”.