The HTC One Maxの指紋読取装置が指紋を誰でも読める形で保存していたことが発覚 写真提供: HTC
It was discovered that the HTC One Max fingerprint reader stored fingerprints in a form that anyone could read. Photo courtesy of HTC

According to an article in The Guardian1, it appears that an HTC smartphone stored users’ fingerprint images in a form that anyone could read. The issue was discovered by 4 FireEye researchers, and on August 5 they presented at BlackHat2 the paper3. The fingerprint images were reportedly stored unencrypted and world-readable at /data/dbgraw.bmp. Consequently, applications and other software could read them freely.

After this discovery, HTC’s share price plunged by nearly 2 percent, and its market capitalization reportedly fell below its liquidation value4.

発覚後、HTCの株価は急落
HTC’s share price plunged after the disclosure

This security hole affects HTC, but many smartphone manufacturers, including Samsung, reportedly do not use built-in security features provided by ARM and others. As a result, attackers can continue secretly reading users’ fingerprints freely and without detection.

Password theft has become a major problem, but the theft of biometric data—especially raw biometric data—poses an even more serious problem. Unlike passwords, biometric data cannot be replaced. It could therefore create an identity-theft problem more serious than password theft. Much more careful handling is required.

  1. The Guardian: “HTC stored user fingerprints as image file in unencrypted folder”, (2015/8/10) http://www.theguardian.com/technology/2015/aug/10/htc-fingerprints-world-readable-unencrypted-folder
  2. BlackHat Briefings – August 5-6, https://www.blackhat.com/us-15/briefings.html
  3. Zang, Y., Zhaofeng, C., Xue, H., Wei, T.: “Fingerprints On Mobile Devices: Abusing and Leaking”, (2015/8) https://www.blackhat.com/docs/us-15/materials/us-15-Zhang-Fingerprints-On-Mobile-Devices-Abusing-And-Leaking-wp.pdf
  4. Biggs, J.:”HTC Is Now Essentially Worthless (And Insecure)”, (2015/8/10), TechCrunch, http://techcrunch.com/2015/08/10/htc-is-now-essentially-worthless-and-insecure/?ncid=rss&utm_medium=twitter&utm_source=twitterfeed

Related posts

Biometric Authentication at Bank ATMs

There was news that they would support both palm and finger authentication, but I wonder whether that is a good idea. Have they properly considered the…

Identity · 2005-07-12