We all go through this process at some point: looking at the camera, moving our head and following the instructions that appear on the screen. In a few seconds, a banking or financial application determines that there is a real person behind the phone and that their face matches that of the account holder. And that procedure conveys a feeling of security: a password can be stolen, but a face would seem much more difficult to fake.
However, two teams of researchers from Argentina and Ecuador showed during the hacker conference DEF CON, in Las Vegas, that many of these controls can be manipulated from the phone itself. In their tests they managed to introduce prepared images and videos into the verification process, pass life tests and deceive systems designed to detect deepfakes.
What both talks made it possible to notice is that the most serious problem appears when an application trust almost completely in what the user’s phone gives them: that the camera is showing a live image, that the video was not altered and that the device was not tampered with.
“It is very difficult to verify that the data obtained has not been modified when the attacker has full control of the application and the phone where he lives,” he explained to Clarín Dan Borgogno, Argentine researcher at the cybersecurity company Faraday.
Here, researchers from both teams, who gave two talks between Friday and Saturday at one of the largest cybersecurity conferences in the world, explain how these systems can be fooled and what could be done to make them more secure.
One face to open or recover an account: unhackable?
Borgogno presented, together with Javier Bernardo, from Strike Security, the investigation The Glass Perimeter: Systematic Bypasses in Biometric Frameworks and the Rise of Synthetic Identity. For more than six months they analyzed some of the main biometric systems used by banks and large technology providers.
According to the researchers, they obtained a “100% evasion rate” in the frameworks (the sets of tools and software components that an application uses to implement biometric verification) that they tested. That is to say: whenever they wanted to evade biometric controls, they succeeded.
In some cases they used high-fidelity physical representations (an image of a face). In others, they manipulated the path that images take within the operating system to replace information captured by the camera before it reached the biometric software.
The specific effect depended on the function that each application had assigned to facial recognition.
“The majority use the KYC [know your customer, a process to verify the client’s identity] as an account verification mechanism, but we saw cases where only a person’s face was enough to enter. Face validation It is also used to open accounts“Borgogno explained.
KYC, acronym in English for “know your customer,” encompasses the procedures used by banks, wallets and fintech to check who is behind a request. It can include the presentation of a document (which is why data leaks are very dangerous), facial recognition and a proof of life, designed to distinguish a real person from a photo or recording.
The most risky scenarios, according to the researcher, are those in which the face allows you to open an account or recover access no need for a password, a second authentication factor, or other independent verification.
When biometrics works only as a complement, the attack becomes more complex. The criminal also needs to obtain data such as the victim’s email, password or two-factor code.
Pass the life test
A second team, made up of Ecuadorians Xavier Riofrío Machado and Alex Tipan, presented Your Bank Thinks I’m You: A Complete Kill Chain Against Mobile Banking Security. The work analyzed real financial applications used by millions of people.
The researchers studied the different layers of security incorporated by these applications: detection of modified phones, mechanisms against software manipulation, biometric tests, life checks and artificial intelligence systems intended to recognize deepfakes.
Its objective was to introduce controlled images or videos into the authentication process. To achieve this, they first had to evade protections that prevented the application from intervening and then deceiving both the proof of life and the comparison between the face presented and that of the victim.
In the tests, carried out with authorization, they used material produced through generative artificial intelligence and information obtained from public sources.
Riofrío explained to Clarín who managed to overcome biometric authentication in two especially sensitive processes. The first was the enrollment of new clients, which allows them to create an account and access the services of the financial institution. The second was re-enrollment of existing customers, used when a user installs the app again or changes devices.
“We detected that certain critical flows they relied too much on biometric validation and had not generated additional verification methods. That is, these actions could only be carried out by impersonating the victim,” he said.
A poorly secured re-enrollment can be especially dangerous because it allows you to link an existing account to a new phone. From there, the attacker could access financial products and carry out operations from their own device.
The telephone as a weak point
The two works agree that the problem is not in facial recognition as an isolated technology, but in how it is integrated into an application and in the degree of trust that banks and fintech place in the controls executed on the user’s device. The telephone is, today, the device we use for everything we do and this, while convenient, is a potential security problem.
Many applications receive a series of data from the phone and assume that it is authentic: an image captured by the camera, a head movement, a blink, or a video sequence. But if an attacker manages to modify the application or intervene in that journey, they can try to replace the real information with prepared content.
“When validation occurs primarily on the client side, the environment is outside the entity’s control and there is a possibility that the captured data may be manipulated before being processed,” Riofrío explained.
Added to this is the rapid improvement of artificial intelligence systems capable of creating realistic images and videos. Biometric providers incorporate models to detect this content, but they face permanent competition between the tools that generate deepfakes and those that try to identify them.
Borgogno believes that training better detectors can help in the short term, although it does not solve the structural problem. “There will come a point at which image and video models will be able to overcome any detection and what is real will be indistinguishable from what is generated,” he warns.
And this, without a doubt, is going to make the situation much worse.
What do you suggest to improve the systems?
For specialists, the first measure is to prevent face validation serves as the only requirement to open, recover or move an account to another device. Biometrics should be combined with passwords, temporary codes, pre-authorized devices and controls that detect unusual changes in customer behavior.
There is a maxim in security that is to combine factors: something you know (a password, a PIN, a phrase), something you have (a token, a security key, confirming a message on the phone). The more these variables are combined to log in, more robust is an online ecosystem.
Borgogno recommends that each user has a trusted deviceand any phone change requires additional verification using a one-time code. That way, even if an attacker manages to fool facial recognition, they would still need to overcome a separate barrier.
Riofrío also proposes moving a greater part of the validation from the phone to the bank’s servers. Among the alternatives are the live video streaming and challenge-response systems, which request unpredictable actions generated in the moment.
These controls may ask the user to follow random changes in lighting, colors, movements, or instructions that cannot be prepared in advance. The server then analyzes whether the response matches the stimulus sent in real time.
Of course, none of these measures completely eliminates the risk. The objective is to prevent that a single weakness allows the entire system to go through. “The problem appears when organizations assume that a solution or a supplier is infallible,” said Riofrío. “Trust should not be based on a single validation, but on layers of protection and continuous verification.”
For the average user, the research does not mean that facial recognition should be abandoned or that all banking applications are exposed in the same way. They do show that the face does not function as a key that is impossible to copy either.
When, instead, an application turns biometrics into its only security barrier, a technology designed to simplify access can also become what is known as a “SPOF”: a single point of failure.
As with passwords, text codes and other security mechanisms, its effectiveness depends on it being just one piece of a larger system.
There is very little the user can do at this point: it depends on the application they use to combine factors and handle security from a more robust place.
The responsibility, ultimately, lies with the companies and the policies they adopt to protect their users. There appears a common tension within the industry: while product and business areas seek to reduce friction and make applications increasingly simpler to use, cybersecurity teams try to add barriers that make an attack more difficult and costly.
The challenge is to find that balance without the user’s comfort ending up becoming an advantage for the attacker.
Крупные раки Майкоп — купить свежих крупных раков с доставкой от 3000 руб/кг
Крупные раки – РАКИДАР
Отборные раки в Сочи — премиальные свежие раки с доставкой
Средне-крупные раки в Сочи — свежие варёные раки с доставкой на дом
Средние раки в Сочи купить — свежие варёные раки с доставкой от 2300 руб./кг
Условия доставки раков в Краснодаре и Краснодарском крае
Отборные раки «САМОЧКИ» – РАКИДАР
Отборные раки – РАКИДАР
Средние раки – РАКИДАР
Мелкие Раки – РАКИДАР
Средне-крупные раки – РАКИДАР
Контакты RAKIDAR — заказать раков в Краснодаре | Телефон, доставка
tg账号购买|telegram账号购买|飞机账号|电报账号购买批发
tg账号购买|telegram账号购买|飞机账号|电报账号购买批发 – Telegram 成品号
tg账号购买|telegram账号购买|飞机账号|电报账号购买批发 – Telegram 账号批发
tg账号购买|telegram账号购买|飞机账号|电报账号购买批发 – Telegram 协议号
tg账号购买|telegram账号购买|飞机账号|电报账号购买批发 – 美国 Telegram 账号购买
Ariana Grande Tickets הפרופיל של — The Movie Database (TMDB)
Ticketwhiz919
ticketwhiz919, Author at aboutcasemanagerjobs.com
Profile
Ticket Whiz | Profile
Cannabis.net
Ticketwhiz919
ticketwhiz919 | aboutpharmacistjobs.com