Thursday, 19 February 2009

Biometric Scanner Cracked by Black Hats

You may have seen the recent articles highlighting flaws in some of the Biometric scanner implementations from vendors such as Toshiba, Asus and Lenovo. See:

http://arstechnica.com/security/news/2009/02/black-hat-blank-face-researchers-crack-biometric-scanners.ars

It's clear from the evidence being presented there is considerable improvement to be made in the technology and therefore shouldn't be relied on as a single source of authentication. It raises concerns over the drive to implement biometrics in high security solutions such as boarder controls, when the technology is still unproven in the security market.

We at PINoptic have always viewed biometric as a technology for the future and needing more time to prove it's capabilities. We do believe it will become a dominate means of authentication in the future, but until then we recommend the use of multiple layers of authentication for access control.