Daily Tech News, Interviews, Reviews and Updates

Hack against fingerprint theft in smart locks is released by a researcher

According to a new study, consumer smart locks are easily vulnerable, making it possible for attackers to steal the fingerprint patterns of specific individuals. This week, research from James Cook University in Singapore showed how a hacker might utilise common hardware and very basic hacking skills to quietly gather fingerprints using a smart lock hacking method called drop lock. Author and senior cybersecurity instructor Steven Kerrison claims that the problem is caused by the hardware constraints of IoT smart locks. Low-end Internet of Things devices like commercial smart locks lacks dedicated safe storage, in contrast to smartphones or tablets that store fingerprint information and other biometric data inside protected hardware enclaves.

In the report, Kerrison stated that “these devices often contain less powerful Processor cores, cheaper sensors, and do not provide the same level of security as a smartphone.” This is typically regarded as acceptable based on the product’s worth or what the sensor is intended to safeguard. In order to show the flaw, Kerrison created a proof-of-concept device that could establish a Wi-Fi connection with a smart lock and, through the use of an exploit or an exposed debug interface, replace the firmware of the lock with instructions to gather and upload fingerprint data. A different option would be to disassemble the lock and connect it directly to the controller using onboard debugging pads.

In any case, the lock would be able to provide information about the target’s fingerprint when activated within the attacker’s controller’s range, which could then be applied to additional biometric hardware.



Readers like you help support The Tech Outlook. When you make a purchase using links on our site, we may earn an affiliate commission. We cannot guarantee the Product information shown is 100% accurate and we advise you to check the product listing on the original manufacturer website. Thetechoutlook is not responsible for price changes carried out by retailers. The discounted price or deal mentioned in this item was available at the time of writing and may be subject to time restrictions and/or limited unit availability. Amazon and the Amazon logo are trademarks of Amazon.com, Inc. or its affiliates Read More
You might also like

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More