
According to an article in The Guardian1, it appears that an HTC smartphone stored users’ fingerprint images in a form that anyone could read. The issue was discovered by 4 FireEye researchers, and on August 5 they presented at BlackHat2 the paper3. The fingerprint images were reportedly stored unencrypted and world-readable at /data/dbgraw.bmp. Consequently, applications and other software could read them freely.
After this discovery, HTC’s share price plunged by nearly 2 percent, and its market capitalization reportedly fell below its liquidation value4.

This security hole affects HTC, but many smartphone manufacturers, including Samsung, reportedly do not use built-in security features provided by ARM and others. As a result, attackers can continue secretly reading users’ fingerprints freely and without detection.
Password theft has become a major problem, but the theft of biometric data—especially raw biometric data—poses an even more serious problem. Unlike passwords, biometric data cannot be replaced. It could therefore create an identity-theft problem more serious than password theft. Much more careful handling is required.
- The Guardian: “HTC stored user fingerprints as image file in unencrypted folder”, (2015/8/10) http://www.theguardian.com/technology/2015/aug/10/htc-fingerprints-world-readable-unencrypted-folder
- BlackHat Briefings – August 5-6, https://www.blackhat.com/us-15/briefings.html
- Zang, Y., Zhaofeng, C., Xue, H., Wei, T.: “Fingerprints On Mobile Devices: Abusing and Leaking”, (2015/8) https://www.blackhat.com/docs/us-15/materials/us-15-Zhang-Fingerprints-On-Mobile-Devices-Abusing-And-Leaking-wp.pdf
- Biggs, J.:”HTC Is Now Essentially Worthless (And Insecure)”, (2015/8/10), TechCrunch, http://techcrunch.com/2015/08/10/htc-is-now-essentially-worthless-and-insecure/?ncid=rss&utm_medium=twitter&utm_source=twitterfeed
Related posts
NTT DoCoMo and HTC Develop the hTc Z Corporate Device with Windows Mobile 5.0
NTT DoCoMo and Taiwan's High Tech Computer Corporation, HTC, announced on July 12 that they had developed the HTC mobile information device hTc Z. Sales through…
The Sensational Article “Successfully Stole PC Data—Is VISTA Security Up to the Task?”
This article has a very provocative title, but there is really nothing remarkable about it. The story is that a Windows XP PC broke, so its…
Biometric Authentication at Bank ATMs
There was news that they would support both palm and finger authentication, but I wonder whether that is a good idea. Have they properly considered the…

You must be logged in to post a comment.