Suggy Posted April 1, 2021 Posted April 1, 2021 (edited) Hi, For background, I’ve worked in IT/Cyber Security for over two decades and only recently became aware of the pervasiveness of biometric cashless catering systems in UK schools when my son's future school sent a consent form to opt in/or out of their lunch system. I note that providers of these systems and schools generally state that they don’t store fingerprint images, but instead store key points from the image which are translated into a computer readable code called a template. There seems to be a perception that these templates can't be turned back into fingerprints. Following a rudimentary search of research literature, I found a meaningful body of work that seems to arrive at a different conclusion. A 2019 paper by Professor Marta Gomze-Barrero and Javier Galbally provides an insight into the current state of play writing: “It is now an accepted fact that it is possible to reconstruct from an unprotected template a synthetic sample that matches the bona fide one”. I'd be very surprised if cashless payment system software is one step ahead of this research. I suspect the vendors would reassure schools and parents that the data is encrypted, but there's at least one vulnerability with a popular biometrics SDK (CVE-2019-12813) that defeats the encryption (or obfuscation).My hunch is that these systems might not be as secure as headteachers and parents are led to believe. Reading through some of the comments in this forum doesn't increase my confidence. To that end, I have a few questions I'd hope some could help with (in the UK) i) what are the most popular systems? I see crbcunninghams and IRIS fastrak mentioned the most. (ii) what biometric SDK are the popular systems built on? I imagine mostly DigitalPersona? (iii) are any of you aware of any of these biometrics systems ever having had an independent security assessment? are you willing to share the results? (iv) does anyone on the list manage such a system and if so, would you be open to a pro bono security assessment? Happy to provide more details and continue discussion here or in email, phone, signal, threma etc. Many thanks, Suggy Edited April 1, 2021 by Suggy
synaesthesia Posted April 1, 2021 Posted April 1, 2021 CRB & Digital Persona here. No idea about any security assessments having been carried out, however from the school's perspective it's one of the best compromises between security and usability - and I say that even as we start to phase biometrics out and replace with cards; I prefer biometrics. You are correct that it is indeed possible to recreate that data to a degree - not wholly though as it relies on assumptions for the missing data (trying to avoid similarities to the Jurassic Park filling in dino-DNA with frog DNA!). Alternatives at a similar level of security & convenience nearly always involve some other type of biometric data and schools have to manage this carefully. Too much to do in too little time and those lunch queues can get mighty long, particularly with fewer staff and larger cohorts. Pin codes are pointless, swipe/RFID cards probably the best alternative method but unlike a fingerprint, easily stolen (but at the same time, no different to someone's lunch money) Ideal world it will be a multi-factor authentication scenario that remains quick and easy - photo ID card with RFID is probably what I'd think is best. Pro's and con's everywhere - the only real downside to biometrics is the thought of ID theft but the risk of that in a school as a targeted attack is very, very low - near nil regarding security or financial, and manageably small from a safeguarding perspective. Plus the data held by schools on every child is way over and above biometric data and the consent form should identify what any of this is used for. 1
Suggy Posted April 1, 2021 Author Posted April 1, 2021 (edited) Thank you for taking the time to respond. >>photo ID card with RFID is probably what I'd think is best That makes sense, I agree. FWIW, I don't think there's much likelihood of a targeted attack either (although, I could be mistaken). The likelihood of other attacks/mistakes depends on variables I (as an outside) have (as yet) almost no insight into. Are fingerprint templates stored in the MIS? If so, are they encrypted and how is the crypto solution implemented? How are cryptographic keys managed? Who has access to the systems where the fingerprint templates are stored? How is access to the system controlled? Is the system hosted/data hosted/stored in the cloud? How is old kit destroyed? etc. In terms of consequences, I'd think that the consequences of a breach could be high enough to be a problem for a very very small number of people. IMO it's not a gamble that kids should have forced upon them (don't get me started on the parents who post pictures of their kids on social media either). That said, I do appreciate the challenges/issues you have to balance, such as long queues, large cohorts, less money, etc. I'd still be very interested to hear from anyone who's had a security assessment or required the vendor to have one as part of the procurement process. Edited April 1, 2021 by Suggy
GrumbleDook Posted April 2, 2021 Posted April 2, 2021 A chunk of the information you are after will not be publicly shared due to IP and security considerations, and many of the cashless catering providers don’t just work in schools by across other sectors too. The range of due diligence taken when looking at systems vary, and to some extent, the reliance on procurement frameworks is part of this ... it you’ll know where I am coming from with that as it affects so many other aspects of InfoSec/Data Protection/Privacy. You are right about attacks too. As the systems are usually hosted on-site within schools, with no direct access externally, the main issue raised is usually about money transfer. As the other part of this, loading money on, is either within school or through online payment systems ... and they get checked over as part of PCI-DSS. I can’t talk about particular solutions but I would always say that should concerns be in place that any pseudonymised data is too easily converted back to its original form and re-used for other purposes, you must look at what measures can limit this. I’ll never say something is impossible ... very hard and improbable, but never impossible. 2
synaesthesia Posted April 2, 2021 Posted April 2, 2021 Indeed, for the reasons mentioned above I can't really say too much more - systems could be locally hosted or in the cloud and the levels of encryption on systems/software outside are own are unlikely to be understood by most of us mortals. I don't think any MIS systems store biometric data but don't have experience with any of the modern cloud based solutions. For data that is stored locally, regardless of whether it's biometric or not schools like anyone are bound to comply with WEEE regulations for electronics disposal and typically (at least ours do) we receive a data destruction certificate for any kit with non-volatile storage. From memory this is physical shredding of devices - not something I agree with unless it's just old e-waste level 500GB hard drives etc but for servers I would expect anyone to at least format & zero drives regardless before this. For re-use/re-deployment outside of schools, same going for business I would expect "military grade" data destruction & certification of such.
Suggy Posted April 2, 2021 Author Posted April 2, 2021 Very much appreciate the discussion, thank you both. What I've seen so far doesn't fill me with confidence that the solution is as secure as the vendor claims suggest. CRBCunningham's documentation states "The data points are encrypted before being stored. The encryption standard used for encrypting the data points is AES 256 with the symmetric key being stored in RSA 2048". The (rhetorical) question I have is where is the key stored, how is it used, and how is it protected? (also, why symmetric over asymmetric?). If the CRB solution has the same vulnerability as that found in CVE-2019-12813, then that's a bit of a problem IMO. Presumably it would have this weakness if its built on the DigitalPersona SDK and hasn't been patched. TBH, I'm not sure there's fixed version of the SDK. The CVE states: "The key and salt used for obfuscating the fingerprint image exhibit cleartext when the fingerprint scanner device transfers a fingerprint image to the driver.". Could I imagine malware attacking this vector (assuming it's a problem for CRBCunninghams and others)? Yes. Is it likely? ¯\_(ツ)_/¯ Still leaves the question of what's the real impact to an individual if their template(s) ends up in HaveMyBiometricsBeenPwnd or whatever :-)
synaesthesia Posted April 2, 2021 Posted April 2, 2021 The likes of Troy Hunt would have a field day just looking at the state of educational software full stop
Suggy Posted April 2, 2021 Author Posted April 2, 2021 I'd hope it's happened at one or more schools/establishments (as technical security review). If not, is money the major obstacle or edutech politics? I'm sure there's enough people willing to do some pro bono work to conduct some reviews.
synaesthesia Posted April 2, 2021 Posted April 2, 2021 I don't believe many would go further than a DPIA although larger trusts may do, and would likely go on the assurances & guarantees provided by the 3rd parties. Not sure how the liability works there should something happen. I suspect with everything going on currently leadership teams are likely to take "cyber-security" more seriously so it wouldn't surprise me to see much more done in the future to this end. 1
enjay Posted April 12, 2021 Posted April 12, 2021 Catering and MIS are generally separate systems, so the templates won't be stored in the MIS but on whatever server is running the Cunninghams/Fastrak/etc. platform. MIS feeds data to payment and till system(s), and the payment and till system(s) talk to each other but not back to the MIS. I don't off the top of my head know of any cloud-based catering systems although I wouldn't be surprised if there is one; the school's server may well be cloud-based of course. In honesty, the cloud-based servers are probably more secure than on-prem ones because they sit behind far superior firewalls than anything we could afford in-house. There are some companies who offer one-stop-shop systems which cover MIS, payment, catering, parents evening bookings, room booking and more - I'd definitely want to do a thorough assessment on their security if we were to start using one! I would expect full data destruction to be carried out on any server's drives when scrapped. The WEEE company we use do this as standard on all drives we give them, but even if not, I would expect schools to request this specifically on decommissioned servers.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now