• Skip to main content
  • Skip to primary sidebar
  • Skip to footer
  • Home
  • About Darknet
  • Hacking Tools
  • Popular Posts
  • Darknet Archives
  • Contact Darknet
    • Advertise
    • Submit a Tool
Darknet – Hacking Tools, Hacker News & Cyber Security

Darknet - Hacking Tools, Hacker News & Cyber Security

Darknet is your best source for the latest hacking tools, hacker news, cyber security best practices, ethical hacking & pen-testing.

Biometric Keylogger Can Grab Fingerprints

April 3, 2008

Views: 6,594

Well this is quite scary as biometrics are touted as the ultimate in security and two factor authentication with biometrics is about as ‘heavy’ as most places get.

The fact that the biometric data can be ‘sniffed’ reconstructed and re-used…is worrying to say the least. Do any of you have biometric measures in your workplace?

A British researcher has developed a biometric keylogger of sorts that can capture fingerprints required to unlock building doors or gain access to computer networks or other restricted systems.

For now, the Biologger is a proof-of-concept aimed at showing the insecurity of many biometric systems, according to Matthew Lewis, who demonstrated the tool at last month’s Black Hat Amsterdam conference. But the researcher, who works for Information Risk Management, warns the attack could become commonplace if current practices don’t change and could be used to log images of retinas, facial features and any other physical characteristics used by biometric systems.

“Biometric device manufacturers and system integrators cannot rely on security through obscurity alone for the overall security of their devices and systems,” he writes in this white paper (PDF). “Without adequate protection of the confidentiality, integrity and availability of biometric access control devices and their data, the threat of “Biologging” activities within those enterprises employing such access controls is real.”

An interesting read, and yes it seems ‘biologging’ is a real threat. A lot of these system designers and integrators/implementers don’t really have a grip on architecture security.

They just assume biometrics = safe and disregard how it’s implement, how safe the data is, how it’s stored and what state it’s in during transit (unencrypted?).

Lewis was also able to issue commands to the access control device that enabled him to unlock doors and add new users with full administrative rights without presenting a fingerprint. That’s because the device needed a single 8-byte message that passed over the network in plaintext. Although he was never able to crack a 2-byte checksum used for issuance of each message, he was able to overcome this limitation by taking a brute-force approach, in which every possible combination of checksums was used.

There are other limitations to Lewis’s attack. For one, it requires attackers to have privileged access to the network connecting the access point to the server. Another is that the traffic was transmitted using the user datagram protocol, which rendered the brute-force attempts “not 100% reliable.”

But his point seems to be that, just as best practices require that passwords are never stored in the clear, fingerprints and other biometric data should likewise be encrypted. Architects designing the next generation of biometric systems, are you listening?

I hope they are listening, and they sort it out!

Source: The Register

Related Posts:

  • Privacy Implications of Web 3.0 and Darknets
  • Leveraging OSINT from the Dark Web - A Practical How-To
  • An Introduction To Web Application Security Systems
  • Understanding the Deep Web, Dark Web, and Darknet…
  • Intel Finally Patches Critical AMT Bug (Kinda)
  • Telegram Hack - Possible Nation State Attack By Iran
Share
Tweet
Share
Buffer
WhatsApp
Email

Filed Under: Hardware Hacking Tagged With: fingerprinting, Hardware Hacking, man-in-the-middle



Reader Interactions

Comments

  1. Pantagruel says

    April 4, 2008 at 4:47 am

    Nice article!

    Rather stupid that this advanced id technique is flawed by sending the valuable data around without encryption basically relying on security through obscurity, Also quite impressive to see they where able to issue a ‘open door’ command with a fairly simple brute-force attempt running every possible 2-bit checksum, 6 min for the non optimized code is not bad. I was quite impressed with the data break down of the finger print image data capture from the network backup, clearly pointing out a weak spot.

    We’ve tested some biometric, finger print that is, access protection system, but the false positive rate (or false acceptance rate as they call it) was too high. We’re basically back to token/pw for patient data.

  2. Mike Touch says

    April 7, 2008 at 5:26 pm

    Great read.

    The security is only as strong as the weakest link which appears to be the actual transfer of the data.

  3. Zebulon says

    April 8, 2008 at 2:03 am

    It just goes to show you even the most advanced security seystems are vunerable

  4. fever says

    April 8, 2008 at 7:01 pm

    good thing i dont use biometrics on my fridge than. i wouldn’t want the neighbors getting in by using this. haha!

    whats the world coming to when not even your fingerprints are secure.

  5. James C says

    April 8, 2008 at 7:23 pm

    Its easier + quicker to lift and reproduce a finger print than it is crack a descent password.

  6. Mike Touch says

    April 9, 2008 at 2:07 pm

    Why’s that?

  7. James C says

    April 9, 2008 at 5:46 pm

    Unless your wearing gloves, your leaving your finger prints every where (which in the case of a Biometric device is like leaving a copy of your keys on every thing you touch)

  8. zupakomputer says

    April 9, 2008 at 6:22 pm

    lol, you shouldn’t have used your fridge as an entrance to your home in the first place..

    down the basement hatch outside, and you’re out the fridge & into the kitchen in no time.

  9. zupakomputer says

    April 9, 2008 at 6:27 pm

    I bet they’re working out a method of seeing what you touched last in the fridge, so they can try to open it from the inside by rubbing the produce against the sensor.

    Better watch it doesn’t become like the one in Ghostbusters.

    =I am the keylogger=

    =I am the gateway keeper=

    there is no Dana there is only Zuul

  10. fever says

    April 10, 2008 at 4:44 am

    sounds like an interesting plan. hmm. must take into consideration.
    lol

  11. digiemi says

    April 18, 2008 at 11:19 pm

    id be more worried about my stashbox!!..and leave my parma ham alone!!….
    yeah,interesting article,..i have a question….
    i see the future of information pretty much like organized crime.the mafia in america controlled gambling,prostitution,narcartics for many years,the goverment wised up,now they control or profit from it and the mafia has taken a massive blow.the f.b.i are now ten steps ahead.Hackers were the first programers for games,applications ect now its all done by big corp and the hackers are the enemy. do you think the scales are going to tip real soon and hackers will be left ten steps behind??i feel the more peopel are joining big corps and the business side is grwing so much that free source will become a very isolated spere/….OH ORWELL I HOPE YOURE WRONG!peace

  12. fever says

    April 19, 2008 at 6:46 am

    Big business is where the money is and in a world controlled money every follows it. thus you will have all of your talented people going for the bucks and not the backs of the likes of you and me. so we are already twenty steps behind in my opinion. the gov has been recruiting the best and brightest from every generation to do their bidding and keeping the rest of us in the dark ages. we are the only thing standing between us and the end of our kind altogether.

    so down the rabbits hole we go some more.

  13. Bogwitch says

    April 19, 2008 at 10:01 am

    @fever

    You’re wrong about government. Typical paranoia. Research civil service wages and re-think.

  14. fever says

    April 20, 2008 at 2:56 pm

    @ Bogbitch

    “Big business is where the money is and in a world controlled by money every follows it.” and do you really think the gov tell you and me how much they really pay their hackers for their services?

  15. fever says

    April 20, 2008 at 3:00 pm

    I’d rather be a little “paranoid” than overly complacent. its more of just being alert to what is really going on.

  16. Bogwitch says

    April 20, 2008 at 5:38 pm

    @fever
    Had it occurred to you that I actually know?

  17. fever says

    April 21, 2008 at 1:22 am

    @bogwitch
    It occured to me that you might have information which i do not, and that is very possible. However, what makes you think that whatever information you are privy to is all that there is. did the thought cross your mind that i might have access to information that you don’t? either way you go there is always going to be information that one side or the other does not know. YOUR NOT ALL KNOWING, but neither am I! We could continue to argue this point to no end, but that would be pointless. So what do you say if we try to stay on subject from now on. Just a thought.

Primary Sidebar

Search Darknet

  • Email
  • Facebook
  • LinkedIn
  • RSS
  • Twitter

Advertise on Darknet

Latest Posts

Reconnoitre - Open-Source Reconnaissance and Service Enumeration Tool

Reconnoitre – Open-Source Reconnaissance and Service Enumeration Tool

Views: 306

Reconnoitre is an open-source reconnaissance tool that automates multithreaded information gathering … ...More about Reconnoitre – Open-Source Reconnaissance and Service Enumeration Tool

Scanners-Box - Open-Source Reconnaissance and Scanning Toolkit

Scanners-Box – Open-Source Reconnaissance and Scanning Toolkit

Views: 481

Scanners-Box is an open-source, community-curated collection of scanners and reconnaissance … ...More about Scanners-Box – Open-Source Reconnaissance and Scanning Toolkit

Red Teaming LLMs 2025 - Offensive Security Meets Generative AI

Red Teaming LLMs 2025 – Offensive Security Meets Generative AI

Views: 516

As enterprises deploy large language models (LLMs) at scale, the offensive security discipline of … ...More about Red Teaming LLMs 2025 – Offensive Security Meets Generative AI

gitlab-runner-research - PoC for abusing self-hosted GitLab runners

gitlab-runner-research – PoC for abusing self-hosted GitLab runners

Views: 335

gitlab-runner-research is a proof-of-concept repository and write-up that demonstrates how attackers … ...More about gitlab-runner-research – PoC for abusing self-hosted GitLab runners

mcp-scanner - Python MCP Scanner for Prompt-Injection and Insecure Agents

mcp-scanner – Python MCP Scanner for Prompt-Injection and Insecure Agents

Views: 583

mcp-scanner is an open-source Python tool that scans Model Context Protocol (MCP) servers and agent … ...More about mcp-scanner – Python MCP Scanner for Prompt-Injection and Insecure Agents

Deepfake-as-a-Service 2025 - How Voice Cloning and Synthetic Media Fraud Are Changing Enterprise Defenses

Deepfake-as-a-Service 2025 – How Voice Cloning and Synthetic Media Fraud Are Changing Enterprise Defenses

Views: 670

Deepfake operations have matured into a commercial model that attackers package as … ...More about Deepfake-as-a-Service 2025 – How Voice Cloning and Synthetic Media Fraud Are Changing Enterprise Defenses

Topics

  • Advertorial (28)
  • Apple (46)
  • Cloud Security (8)
  • Countermeasures (231)
  • Cryptography (85)
  • Dark Web (4)
  • Database Hacking (89)
  • Events/Cons (7)
  • Exploits/Vulnerabilities (433)
  • Forensics (64)
  • GenAI (12)
  • Hacker Culture (10)
  • Hacking News (236)
  • Hacking Tools (708)
  • Hardware Hacking (82)
  • Legal Issues (179)
  • Linux Hacking (74)
  • Malware (241)
  • Networking Hacking Tools (352)
  • Password Cracking Tools (107)
  • Phishing (41)
  • Privacy (219)
  • Secure Coding (119)
  • Security Software (235)
  • Site News (51)
    • Authors (6)
  • Social Engineering (37)
  • Spammers & Scammers (76)
  • Stupid E-mails (6)
  • Telecomms Hacking (6)
  • UNIX Hacking (6)
  • Virology (6)
  • Web Hacking (384)
  • Windows Hacking (171)
  • Wireless Hacking (45)

Security Blogs

  • Dancho Danchev
  • F-Secure Weblog
  • Google Online Security
  • Graham Cluley
  • Internet Storm Center
  • Krebs on Security
  • Schneier on Security
  • TaoSecurity
  • Troy Hunt

Security Links

  • Exploits Database
  • Linux Security
  • Register – Security
  • SANS
  • Sec Lists
  • US CERT

Footer

Most Viewed Posts

  • Brutus Password Cracker Hacker – Download brutus-aet2.zip AET2 (2,394,934)
  • Darknet – Hacking Tools, Hacker News & Cyber Security (2,173,814)
  • Top 15 Security Utilities & Download Hacking Tools (2,097,292)
  • 10 Best Security Live CD Distros (Pen-Test, Forensics & Recovery) (1,200,141)
  • Password List Download Best Word List – Most Common Passwords (934,345)
  • wwwhack 1.9 – wwwhack19.zip Web Hacking Software Free Download (777,066)
  • Hack Tools/Exploits (673,983)
  • Wep0ff – Wireless WEP Key Cracker Tool (531,050)

Search

Recent Posts

  • Reconnoitre – Open-Source Reconnaissance and Service Enumeration Tool November 10, 2025
  • Scanners-Box – Open-Source Reconnaissance and Scanning Toolkit November 7, 2025
  • Red Teaming LLMs 2025 – Offensive Security Meets Generative AI November 5, 2025
  • gitlab-runner-research – PoC for abusing self-hosted GitLab runners November 3, 2025
  • mcp-scanner – Python MCP Scanner for Prompt-Injection and Insecure Agents October 31, 2025
  • Deepfake-as-a-Service 2025 – How Voice Cloning and Synthetic Media Fraud Are Changing Enterprise Defenses October 29, 2025

Tags

apple botnets computer-security darknet Database Hacking ddos dos exploits fuzzing google hacking-networks hacking-websites hacking-windows hacking tool Information-Security information gathering Legal Issues malware microsoft network-security Network Hacking Password Cracking pen-testing penetration-testing Phishing Privacy Python scammers Security Security Software spam spammers sql-injection trojan trojans virus viruses vulnerabilities web-application-security web-security windows windows-security Windows Hacking worms XSS

Copyright © 1999–2025 Darknet All Rights Reserved · Privacy Policy