Researchers Bypass Samsung Galaxy S8's Iris Recognition System With A Photo And A Contact Lens

Chaos Computer Club (CCC) security researcher, Jan Krissler (nicknamed “Starbug”) has bypassed the Samsung Galaxy S8’s iris-based authentication system just one month after the phone started shipping.

Latest Videos FromTom's Hardware
Contributor

Lucian Armasu is a Contributing Writer for Tom's Hardware US. He covers software news and the issues surrounding privacy and security.

  • Jake Hall
    Should gone Retinal, Samsung... don't get cheap on me
    Reply
  • DookieDraws
    D'OH!
    Reply
  • InvalidError
    19727839 said:
    Should gone Retinal, Samsung... don't get cheap on me
    I would never recommend relying on biometric as a password replacement as it is merely a matter of time before someone finds a way to fool sensors and there is no way for you to prevent a would-be aggressor from coercing the ID out of you, with or without your knowing. Also, once your biometric ID has been compromised, there is no practical way for you to change it.

    Biometrics as the only authentication factor is only suitable for low security application where biometrics are used more for convenience than security.
    Reply
  • 10tacle
    On another note, what is up with Samsung and their Galaxy updates so frequently? I'm still using my one and a half year old Note 5 when they had the matching Galaxy S6. Now they are coming out with the 4K Note 8 this fall (they skipped the Note 6 series and went with the exploder Note 7) and Galaxy S9 next spring.

    I can't keep up anymore but I guess I'm getting old - I like to keep my phones for 3 years or so before feeling the need to upgrade (better cameras, better resolution, larger screen, better Android support from the carrier, etc.). And now that carriers (in the US anyway) make you buy the phone up front instead of "giving" you one with a new 2-year subsidized contract, it's just becoming ridiculous.
    Reply
  • alextheblue
    19727996 said:
    19727839 said:
    Should gone Retinal, Samsung... don't get cheap on me
    I would never recommend relying on biometric as a password replacement as it is merely a matter of time before someone finds a way to fool sensors and there is no way for you to prevent a would-be aggressor from coercing the ID out of you, with or without your knowing. Also, once your biometric ID has been compromised, there is no practical way for you to change it.

    Biometrics as the only authentication factor is only suitable for low security application where biometrics are used more for convenience than security.

    Exactly, low-security or as a tertiary factor. Anyway, has anyone bypassed the Windows Hello Iris or facial recognition with something similar yet? It's still breakable I'm certain, it's still biometrics and the same rules apply, but it seems to be a cut above the others.

    Reply
  • mrmez
    Ouch!
    Plenty of photos of my face around.
    Not so many of my fingerprints.
    Reply
  • therealduckofdeath
    If you notice someone taking a photo of you with a 200 mm lens less than five metres away, you really should be worried. :)
    Remember, you literally will have to look at the perp for them to succeed.
    Reply
  • humorific
    Biometrics were always fools gold. As much as we everyone likes to bash passwords, ultimately they are still the best, most secure, most flexible option, and likely to stay that way. Remember, the purpose of security is to be secure, not convenient.
    Reply
  • 19728903 said:
    So you don't have ANY photos of your face ANYWHERE?

    Nothing on Facebook, Twitter, Tumblr, Twitch, Tinder, Youtube, etc etc etc.

    You must be very paranoid or very ugly.
    Or maybe they're just not vain enough to want the whole world to see their pictures.
    Reply
  • Shagoii
    I think that the person could select more than 1 method of security. Exemple:
    Iris + Biometric
    or password + pin code
    or pin code + iris
    or password + iris + biometric
    or password + pin code + iris + biometric

    If the person want security, he select more than 1, if not select 1 ou none
    Reply