Fingerprint Sensors in Android Phones Easier to Hack Than Apple's Touch ID: Report

Advertisement
By Manish Singh | Updated: 6 August 2015 20:40 IST

Researchers have found major security vulnerabilities in the Android smartphones that come with fingerprint scanners. Security firm FireEye's researchers have devised four different attacks that could extract user fingerprints from Android smartphones, and claim the technology is more vulnerable than Touch ID implemented by Apple.

FireEye researchers Tao Wei and Yulong Zhang have revealed major vulnerabilities in fingerprint scanner-powered Android smartphones. One such attack is "fingerprint sensor spying" which can "remotely harvest fingerprints in a large scale," the researchers told ZDNet.

Smartphones like the HTC One Max and Samsung's Galaxy S5 that sport a fingerprint scanner don't fully lock down the sensor, the researchers note. The sensor in these phones are protected by only "system" level privilege instead of "root", making it easier for an attacker to find a workaround. The affected vendors were notified, and have since provided patches for the issue.

Advertisement

It wasn't very long ago when Android smartphone manufacturers started to add fingerprint sensors on their handsets. The technology which is largely similar to iPhone and iPad's Touch ID, makes it easier to unlock a smartphone. Zhang however says the iPhone Touch ID sensor is "quite secure" since it encrypts the fingerprint data it gleans from the sensor. He added, "Even if the attacker can directly read the sensor, without obtaining the crypto key, [the attacker] still cannot get the fingerprint image."

Advertisement

Only a select number Android handsets have this technology, however. Google introduced official support for fingerprint scanners with Android M, which releases later this year.

Any vulnerability in the fingerprint scanners is crucial because of their nature of operating with sensitive details. The fingerprint sensors - in addition to unlocking a screen and enabling users to quickly login to their accounts - have also been used for authentication in mobile wallets and banking features. If the data gets in the wrong hands, it could leave devastating results on the victim.

Advertisement

This isn't the first time a vulnerability has been found in the fingerprint scanner of an Android smartphone. Last year, a German firm named H Security had found a way to fool the Galaxy S5's sensors to get access to it using a "dummy" finger.

Earlier this year, Wei and Zhang had found another vulnerability in the same Samsung flagship smartphone. The handset encrypts the data and stores it into a secure zone, however, researchers had found a way to create a copy of the data before it could store and lock down the information.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Realme 15T With 50-Megapixel Selfie Camera Debuts in India: See Price
  2. Amazon Great Indian Festival Sale: Deals on Smartphones, Laptops Teased
  3. Su From So OTT Release Date is Here! Know all the Details
  4. India's Indigenous Vikram Microprocessor Showcased at Semicon India 2025
  5. Redmi 15 5G, Note 14 Pro Prices Dropped During Diwali With Xiaomi Sale
  6. Cannibal Solar Storm May Trigger Aurora in the Sky Soon
  1. BCCI Says Crypto, Real Money Gaming Platforms Can’t Bid for Team India’s Title Sponsorship
  2. Scientists Discover Hidden Mantle Layer Beneath the Himalayas Challenging Century-Old Theory
  3. Astronomers Propose Rectangular Telescope to Hunt Earth-Like Planets
  4. Microsoft Testing Native Clipboard Sync Feature to Share Text Between Windows PCs, Android Devices
  5. Su From So OTT Release: When and Where to Watch This Kannada-Language Horror-Comedy Online
  6. Sennheiser Momentum 4 Wireless 80th Anniversary Edition Launched in India With Up to 60 Hour Battery Life
  7. Call of Duty Film Adaption Said to Be a 'Priority' at Paramount, Negotiations on to Acquire Rights
  8. Cannibal Solar Storm May Trigger Auroras as Powerful Geomagnetic Storm to Hit Earth Soon
  9. Apple's iPhone 8 Plus Listed as Vintage Product Ahead of iPhone 17 Launch, 11-Inch MacBook Air Now Obsolete
  10. Hidden Reason Behind Portugal’s Deadly Earthquakes Finally Explained
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.