Like many others, my smartphone can be accessed via biometric fingerprint login to reveal sensitive data such as email.
This got me thinking about the security implications for my smartphone. I'm curious about the potential risks and how secure my data really is after such an interaction. Even if a third party has my biometric fingerprint details, can I rely on how physical access to my phone is necessary to bypass the fingerprint lock?
Fingerprints, like all biometrics are not a secret like a password. The point is to assess your physical presence. When used with a phone, your fingerprints are not securing your data, the phone, as a physical device does ("something you have"). The fingerprint is a second factor ("something you are"), a way to make sure the device is in your hands and not someone else's hand.
Security depends on the sensor device. That is, how good it is a making a difference between your actual, live finger and something else.
If you are worried about the security of your phone fingerprint sensor, use a password. Your fingerprint itself is already available to anyone who cares.
This is mandatory for bank accounts, sim cards and what not. So its practically unlivable without Aadhaar these days.
Not sure about how much data any entity could leak but if you want to be sure, perhaps you can use a different method on your phone?
> Even if a third party has my biometric fingerprint details, can I rely on how physical access to my phone is necessary to bypass the fingerprint lock?
I think not, if the third party is a government.
FWIW I really don't recommend just fingerprint for phone access. You can change a PIN if someone else gets a hold of it, there's not much you can do to change your fingerprints.
It's like sticking a note with a password on your computer :)
Personal protip: I use fingerprint lock, but anything sensitive on my phone is blocked with extra pattern lock. With unlocked phone you can access my gallery but you cannot access bank apps. IIRC this will be the built in feature of next Android, I use Xiaomi smartphone which has many extra security features like this one since basically always. Maybe there is an app for this too, I don't know.
Of course this isn't 100% secure, I probably have USB Debugging unlocked, but at least saves me from a random person just grabbing my phone while I'm on a bus and running away with unlocked phone.
Before anyone asks "But aren't bank apps already locked with their own PIN codes?" - yes, they are. But some forces me to have 4 digits PIN only, some even suggests using fingerprint to unlock them (and for some I do). But I'm also blocking Google Play, a browser where I do the most private stuff, I could block a messenger app. Basic apps does not have extra security features.
30 years ago much of the population was concerned about typing a credit card number into 'the internet'. Now we have a small, hackable, stealable, insecure by design device with bank, personal communications, business communications, social security, family photos and numerous more data depending on your choice of app. It's a great win of drip-drip very convenient life is faster now (it isn't, there's just more gap for not planning).
Access by a criminal? probably not much - if they can get physical access to your phone, access to your fingerprint by social manipulation or threat isn't that hard.
Access by government agency that confiscates your phone? theoretically yes, but no more than using printed fingerprints on an arrest record or lifted from your home and printed so they can be used on your phone.
Access by a local sheriff/corrupt cop? a lot of hassle compared with getting access to your finger
* It is easier to push your thumb on a screen than to pry a password out of your head. (relevant XKCD: https://xkcd.com/538/)
* You will leave fingerprints and other biometric features everywhere.
Fingerprints for unlocking is not very secure it's just a convenience. Consider it to be equivalent to face unlocking. Anyone who is determined enough will bypass it. Whether it's secure enough depends on your threat model. I trust face unlock to prevent my kids unlocking my phone but that's a whole different kind of threat model from a state actor.
They are at best a quick convenience for perhaps a time logging machine? Where security really isn't a factor.
Two points to make:
First, I don't know about Android, but certainly on iPhone, the fingerprint data is stored in the Secure Enclave and the biometric reader on the phone establishes a secure communications channel (unique session key) with the Secure Enclave. So remote attacks are unfeasable unless you've managed to extract the underlying shared key from the Secure Enclave.[1]
Second, the definition of what is "stored". There are a number of different approaches to storing biometric data, and most if not all "modern" methods will store an algorithmic derivation of some sort rather than actual raw measurement data. Hence if the government is using algorithm A and your phone is using algorithm B, then in all likelyhood there is no viable way to transpose between the two.
Third, generally good OPSEC suggests to disable the biometric login to your phone anyway and rely on a password. That way, for example, someone can't just hit you on the head to render you unconcious and hold your finger to the sensor. (They would have to force the password out of you whilst you were concious, per XKCD[2] ;-)
[1]https://support.apple.com/en-gb/guide/security/sec067eb0c9e/... [2]https://xkcd.com/538/
if your device is locked with fingerprint, it will be FAR easier to grab your fingerprint from something you touched. and creating a fingerprint impression from this will be VERY easy. it takes simple glue and it is very low-cost. you use cyanolate and a gummy bear. the gummy bear will hold the fingerprint while you apply it to the sensor :)
here are a few links : https://blog.kraken.com/product/security/your-fingerprint-ca... https://blog.talosintelligence.com/fingerprint-research/ https://www.ccc.de/en/updates/2013/ccc-breaks-apple-touchid
fingerprints are a conveniance. they will work at home where you want that phone to be protected from your kid you don't want to be accessing internet too easily.
as a security measure, it's stupid because it is very easy to grab fingerprints : you leave those all around. it is also very easy to just create an impression from a picture with a good quality camera. and once it's compromised, you CANNOT change your fingerprint for another one.
do. not. use. fingerprints. for. security.