Fingerprint Sensors in Android Phones Easier to Hack Than Apple's Touch ID: Report

Advertisement
By Manish Singh | Updated: 6 August 2015 20:40 IST

Researchers have found major security vulnerabilities in the Android smartphones that come with fingerprint scanners. Security firm FireEye's researchers have devised four different attacks that could extract user fingerprints from Android smartphones, and claim the technology is more vulnerable than Touch ID implemented by Apple.

FireEye researchers Tao Wei and Yulong Zhang have revealed major vulnerabilities in fingerprint scanner-powered Android smartphones. One such attack is "fingerprint sensor spying" which can "remotely harvest fingerprints in a large scale," the researchers told ZDNet.

Advertisement

Smartphones like the HTC One Max and Samsung's Galaxy S5 that sport a fingerprint scanner don't fully lock down the sensor, the researchers note. The sensor in these phones are protected by only "system" level privilege instead of "root", making it easier for an attacker to find a workaround. The affected vendors were notified, and have since provided patches for the issue.

It wasn't very long ago when Android smartphone manufacturers started to add fingerprint sensors on their handsets. The technology which is largely similar to iPhone and iPad's Touch ID, makes it easier to unlock a smartphone. Zhang however says the iPhone Touch ID sensor is "quite secure" since it encrypts the fingerprint data it gleans from the sensor. He added, "Even if the attacker can directly read the sensor, without obtaining the crypto key, [the attacker] still cannot get the fingerprint image."

Advertisement

Only a select number Android handsets have this technology, however. Google introduced official support for fingerprint scanners with Android M, which releases later this year.

Any vulnerability in the fingerprint scanners is crucial because of their nature of operating with sensitive details. The fingerprint sensors - in addition to unlocking a screen and enabling users to quickly login to their accounts - have also been used for authentication in mobile wallets and banking features. If the data gets in the wrong hands, it could leave devastating results on the victim.

Advertisement

This isn't the first time a vulnerability has been found in the fingerprint scanner of an Android smartphone. Last year, a German firm named H Security had found a way to fool the Galaxy S5's sensors to get access to it using a "dummy" finger.

Earlier this year, Wei and Zhang had found another vulnerability in the same Samsung flagship smartphone. The handset encrypts the data and stores it into a secure zone, however, researchers had found a way to create a copy of the data before it could store and lock down the information.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. How Instagram's Edits App Evolved Over the Past Year and What's Next
  2. NASA's Curiosity Rover Finds Crater Filled With Sand, Alters Drilling Plans
  3. Motorola Edge 70 Pro vs OnePlus Nord 6 vs Redmi Note 15 Pro+ Compared
  1. NASA’s Curiosity Rover Finds Crater Filled With Sand, Alters Drilling Plans
  2. Control Ultimate Edition Arrives on iPhone and iPad With Touch Controls, Universal Purchase
  3. Asus ExpertBook Ultra With Intel Core Ultra X7 Series 3 CPU Launched in India Alongside ExpertBook P3, ExpertBook P5 Series
  4. Boat Aavante Prime X Soundbar Launched in India With Dolby Atmos, Wireless Satellite Speakers: Price, Features
  5. Qualcomm CEO Reportedly Visits Samsung Foundry in Korea to Discuss Producing 2nm Chips
  6. Coinbase Announces USDC-INR Trading Services for Users in India
  7. Redmi K Pad 2 Launched With 8.8-Inch 3K Display, Dimensity 9500 Chip: Price, Specifications
  8. Suyodhana OTT Release Date: When and Where to Watch This Telugu Mystry Thriller Online?
  9. OnePlus Watch 4 Launch Appears Imminent as Listing Confirms Snapdragon W5 Chip, OxygenOS Watch 8
  10. Sennheiser CX 80U, Sennheiser HD 400U With USB Type-C Connectivity Launched in India: Price, Features
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.