Jump to content

Suggy

Members
  • Posts

    4
  • Joined

  • Last visited

Reputation

0 Neutral

About Suggy

Personal Information

  • Biography
    Security Consultant
  • Location
    Hampshire
  1. I'd hope it's happened at one or more schools/establishments (as technical security review). If not, is money the major obstacle or edutech politics? I'm sure there's enough people willing to do some pro bono work to conduct some reviews.
  2. Very much appreciate the discussion, thank you both. What I've seen so far doesn't fill me with confidence that the solution is as secure as the vendor claims suggest. CRBCunningham's documentation states "The data points are encrypted before being stored. The encryption standard used for encrypting the data points is AES 256 with the symmetric key being stored in RSA 2048". The (rhetorical) question I have is where is the key stored, how is it used, and how is it protected? (also, why symmetric over asymmetric?). If the CRB solution has the same vulnerability as that found in CVE-2019-12813, then that's a bit of a problem IMO. Presumably it would have this weakness if its built on the DigitalPersona SDK and hasn't been patched. TBH, I'm not sure there's fixed version of the SDK. The CVE states: "The key and salt used for obfuscating the fingerprint image exhibit cleartext when the fingerprint scanner device transfers a fingerprint image to the driver.". Could I imagine malware attacking this vector (assuming it's a problem for CRBCunninghams and others)? Yes. Is it likely? ¯\_(ツ)_/¯ Still leaves the question of what's the real impact to an individual if their template(s) ends up in HaveMyBiometricsBeenPwnd or whatever :-)
  3. Thank you for taking the time to respond. >>photo ID card with RFID is probably what I'd think is best That makes sense, I agree. FWIW, I don't think there's much likelihood of a targeted attack either (although, I could be mistaken). The likelihood of other attacks/mistakes depends on variables I (as an outside) have (as yet) almost no insight into. Are fingerprint templates stored in the MIS? If so, are they encrypted and how is the crypto solution implemented? How are cryptographic keys managed? Who has access to the systems where the fingerprint templates are stored? How is access to the system controlled? Is the system hosted/data hosted/stored in the cloud? How is old kit destroyed? etc. In terms of consequences, I'd think that the consequences of a breach could be high enough to be a problem for a very very small number of people. IMO it's not a gamble that kids should have forced upon them (don't get me started on the parents who post pictures of their kids on social media either). That said, I do appreciate the challenges/issues you have to balance, such as long queues, large cohorts, less money, etc. I'd still be very interested to hear from anyone who's had a security assessment or required the vendor to have one as part of the procurement process.
  4. Hi, For background, I’ve worked in IT/Cyber Security for over two decades and only recently became aware of the pervasiveness of biometric cashless catering systems in UK schools when my son's future school sent a consent form to opt in/or out of their lunch system. I note that providers of these systems and schools generally state that they don’t store fingerprint images, but instead store key points from the image which are translated into a computer readable code called a template. There seems to be a perception that these templates can't be turned back into fingerprints. Following a rudimentary search of research literature, I found a meaningful body of work that seems to arrive at a different conclusion. A 2019 paper by Professor Marta Gomze-Barrero and Javier Galbally provides an insight into the current state of play writing: “It is now an accepted fact that it is possible to reconstruct from an unprotected template a synthetic sample that matches the bona fide one”. I'd be very surprised if cashless payment system software is one step ahead of this research. I suspect the vendors would reassure schools and parents that the data is encrypted, but there's at least one vulnerability with a popular biometrics SDK (CVE-2019-12813) that defeats the encryption (or obfuscation).My hunch is that these systems might not be as secure as headteachers and parents are led to believe. Reading through some of the comments in this forum doesn't increase my confidence. To that end, I have a few questions I'd hope some could help with (in the UK) i) what are the most popular systems? I see crbcunninghams and IRIS fastrak mentioned the most. (ii) what biometric SDK are the popular systems built on? I imagine mostly DigitalPersona? (iii) are any of you aware of any of these biometrics systems ever having had an independent security assessment? are you willing to share the results? (iv) does anyone on the list manage such a system and if so, would you be open to a pro bono security assessment? Happy to provide more details and continue discussion here or in email, phone, signal, threma etc. Many thanks, Suggy
×
×
  • Create New...