Wednesday, September 24, 2014 3:38:48 PM
By Antone Gonsalves
CSO |Sep 23, 2014 3:17 PM PT
Apple's iPhone 6 fingerprint scanner has a level of accuracy that makes it a solid authentication tool for people planning to use the smartphone in place of a credit card for in-store purchases, research shows.
The scanner called Touch ID was more difficult to fool with a fake fingerprint than the previous version in the iPhone 5s, according to mobile security vendor Lookout. The new scanner's level of accuracy is sufficient for use with Apple Pay, the payment system available in the iPhone 6.
"As it stands, right now, it's a great security measure," Marc Rogers, the Lookout researcher who tested the new iPhone, said Tuesday. "I don't think you'll find street criminals that are able to duplicate fingerprints."
Creating a fake fingerprint capable of tricking the new scanner requires a high-level of skill, patience and over $1,000 worth of equipment. A description of the lengthy process is on the Lookout blog.
Rogers found that the latest Touch ID scanned a much wider area of the fingerprint to improve reliability and used a higher resolution in identifying a print more accurately.
A fake fingerprint would most likely be used in a targeted attack against an individual, provided the criminal could get a well-defined fingerprint of the digit the person uses with Touch ID. Such a print would unlikely be available on the phone's touchscreen.
Experts who read Rogers' blog said the research added credence to the argument that the use of Apple Pay is safer than handing a stranger at a restaurant or store a debit or credit card.
"The consumer is currently accepting a horribly insecure system with general credit cards," Tyler Shields, analyst for Forrester Research, said. "I believe that Touch ID is a great addition to mobile payments regardless of the recent research."
Indeed, the insecurity of credit cards has been highlighted in the theft of tens of millions of payment card numbers from retailer Target last year and Home Depot this year.
Apple Pay uses a near-field communication (NFC) transmitter to send payment data to a store reader. The actual credit card number is never sent. Instead, the phone transmits a payment token that is a representation of the actual number.
Touch ID is used for authentication before the payment is sent.
Along with the improvements in the scanner, Rogers would like to see Apple bolster security in other areas.
Currently, a person gets six tries with Touch ID to unlock a phone. On the seventh, the user will have to enter his passcode.
Rogers would like Apple to let the iPhone owner decide how many tries to unlock the phone. Choosing a smaller number would strengthen security.
Also, Rogers wants Apple to incorporate in Touch ID technology that would no longer make it possible to fool the scanner with a fake fingerprint, no matter how high the quality.
Rogers said Apple obtained such technology in the 2012 acquisition of AuthenTec, a maker of fingerprint sensors for mobile phones and other portable electronics.
"My guess is it (the technology) was either too expensive or too cumbersome to put into the iPhone, so Apple didn't use it," Rogers said.
http://www.computerworld.com/article/2687323/iphone-6-fingerprint-scanner-found-to-be-accurate-enough-for-apple-pay.html#tk.rss_news
"Intellectuals solve problems; geniuses prevent them." - Albert Einstein
Recent BKYI News
- Form 8-K - Current report • Edgar (US Regulatory) • 09/16/2024 08:45:26 PM
- BIO-key International Enters into $1.9 Million Warrant Inducement • GlobeNewswire Inc. • 09/12/2024 05:18:35 PM
- Leading Government Defense Ministry Awards BIO-key $500K In Follow-On Orders for Biometric User Authentication • GlobeNewswire Inc. • 09/10/2024 12:27:00 PM
- Form 8-K - Current report • Edgar (US Regulatory) • 08/28/2024 08:34:27 PM
- Identity and Access Management Software Provider BIO-key to Participate at H.C. Wainwright Investment Conf. Sept. 9th to 10th • GlobeNewswire Inc. • 08/22/2024 05:10:00 PM
- BIO-key’s PortalGuard Identity and Access Management Solution and Identity-Bound Biometrics Are Now Available on the Amazon Web Services (AWS) Marketplace • GlobeNewswire Inc. • 08/15/2024 12:00:00 PM
- Form 10-Q - Quarterly report [Sections 13 or 15(d)] • Edgar (US Regulatory) • 08/14/2024 09:00:34 PM
- BIO-key Reports Reduced Net Loss and Cash Used in Operations on Lower Q2’24 Revenues; Hosts Investor Call Thu. Aug. 15th at 10am ET • GlobeNewswire Inc. • 08/14/2024 08:30:00 PM
- Identity and Access Management Solutions Provider BIO-key Hosts Q2 Investor Call Thursday, August 15th at 10am ET • GlobeNewswire Inc. • 08/12/2024 02:35:00 PM
- Form 4 - Statement of changes in beneficial ownership of securities • Edgar (US Regulatory) • 08/02/2024 10:12:52 PM
- Form 4 - Statement of changes in beneficial ownership of securities • Edgar (US Regulatory) • 08/02/2024 10:06:03 PM
- Form 4 - Statement of changes in beneficial ownership of securities • Edgar (US Regulatory) • 08/02/2024 09:52:59 PM
- Form 4 - Statement of changes in beneficial ownership of securities • Edgar (US Regulatory) • 08/02/2024 09:46:02 PM
- Form 4 - Statement of changes in beneficial ownership of securities • Edgar (US Regulatory) • 08/02/2024 09:40:42 PM
- Form 4/A - Statement of changes in beneficial ownership of securities: [Amend] • Edgar (US Regulatory) • 08/02/2024 09:28:33 PM
- Form 4 - Statement of changes in beneficial ownership of securities • Edgar (US Regulatory) • 08/02/2024 09:03:27 PM
- Form 4 - Statement of changes in beneficial ownership of securities • Edgar (US Regulatory) • 08/02/2024 08:57:36 PM
- Form DEF 14A - Other definitive proxy statements • Edgar (US Regulatory) • 07/10/2024 08:30:50 PM
- Williamsburg, VA Advances Zero Trust Initiative for City Infrastructure and Data with BIO-key Identity-Bound Biometrics • GlobeNewswire Inc. • 07/08/2024 12:29:00 PM
- BIO-key Secures Los Angeles LGBT Center's IT Systems with Seamless Badge-Tap Authentication Solution • GlobeNewswire Inc. • 06/25/2024 12:29:00 PM
- Form 8-K - Current report • Edgar (US Regulatory) • 06/17/2024 08:17:51 PM
- Identity and Access Management Software Provider BIO-key Reports Q1’24 Revenue of $2.2M and Positive Operating Cash Flow; Hosts Investor Call Tuesday, 10am ET • GlobeNewswire Inc. • 06/17/2024 12:00:00 PM
- Form 10-Q - Quarterly report [Sections 13 or 15(d)] • Edgar (US Regulatory) • 06/14/2024 09:03:09 PM
- Form 8-K - Current report • Edgar (US Regulatory) • 06/14/2024 09:01:36 PM
- BIO-key Introduces Passkey:YOU, a Phish-resistant, Phoneless and Tokenless Biometric FIDO Passkey Authentication Solution • GlobeNewswire Inc. • 06/14/2024 12:00:00 PM
FEATURED Element79 Gold Corp. Appoints Kevin Arias as Advisor to the Board of Directors, Strengthening Strategic Leadership • Sep 18, 2024 10:29 AM
HealthLynked Launches Virtual Urgent Care Through Partnership with Lyric Health. • HLYK • Sep 19, 2024 8:00 AM
Mawson Finland Limited Further Expands the Known Mineralized Zones at Rajapalot: Palokas step-out drills 7 metres @ 9.1 g/t gold & 706 ppm cobalt • MFL • Sep 17, 2024 9:02 AM
PickleJar Announces Integration With OptCulture to Deliver Holistic Fan Experiences at Venue Point of Sale • PKLE • Sep 17, 2024 8:00 AM
North Bay Resources Announces Mt. Vernon Gold Mine Bulk Sample, Sierra County, California • NBRI • Sep 11, 2024 9:15 AM
One World Products Issues Shareholder Update Letter • OWPC • Sep 11, 2024 7:27 AM