Skip to content

Hackers use a fake wax hand to fool vein authentication security

Vein authentication, a biometric security method that scans the veins in your hand, has been cracked, reports motherboard. Using a fake hand made out of wax, Jan Krissler and Julian Albrecht demonstrated how they were able to bypass scanners made by both Hitachi and Fujitsu, which they claim covers around 95 percent of the vein authentication market. The method was demonstrated at Germany’s annual Chaos Communication Congress.

While imprints of fingerprints can often be left behind on surfaces just by touching them, vein patterns cannot, and are considered to be much more secure as a result. However, this wasn’t a problem for the researchers, who were able to copy their target’s vein layout from a photograph taken with an SLR camera modified to remove its infrared filter.

Although constructing the wax hand eventually only required a single photograph and a construction time of 15 minutes, getting to that point took 30 days and over 2,500 test photos. Even the demonstration didn’t go entirely to plan; the researchers had to put one of the scanners underneath a table to stop the hall’s light’s from interfering with the hack. However, now that the method has been proven to work, other researchers will likely build upon it to create a process that’s more efficient and reliable.

Vein authentication isn’t currently used in any mainstream smartphones. Instead it is more commonly used to control access to buildings such as Germany’s signals intelligence agency. In a statement provided to heise online, a Fujitsu spokesperson sought to downplay the implications of the hack and said that it could only succeed under laboratory conditions and that it would’nt likely work in the real world.


Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out /  Change )

Google photo

You are commenting using your Google account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

This site uses Akismet to reduce spam. Learn how your comment data is processed.

%d bloggers like this: