Vulnerability Development mailing list archives

Re: Hacking USB Thumbdrives, Thumprint authentication


From: Robin <robin () technophobia co uk>
Date: Tue, 27 Jan 2004 09:41:55 +0000

That is why I said based on the print, you could incorporate some other values such as a pin.

David Schwartz wrote:

I don't know how much consistant unique detail theire is in a thumb
print, but if the encryption key was built up based on the print then
none of these would matter.

        If the thumbppring is the key, then you're sunk. After all, the person's
thumbprint is going to be on the pad unelss they carefully wipe it off after
every time they use it. Even if they do wipe it off or the surface of the
device is carefully designed to make lifting a print difficult, all you have
to do is dust their phone, desk, or glass.

        DS



--
--------------------------------------------
Robin Wood
TechnoPhobia Limited
--------------------------------------------
Phone: +44 (0)114 2212123
Fax: +44 (0)114 2212124
Email: robin () technophobia co uk
WWW: http://www.technophobia.com
Registered in England and Wales Company No. 3063669
VAT registration No. 5987858 42

The contents of this e-mail are confidential to the addressee and are
intended solely for the recipients use.
If you are not the addressee, you have received this e-mail in error. Any
disclosure, copying, distribution or action taken in reliance on it is
prohibited and may be unlawful.
Any opinions expressed in this e-mail are those of the author personally and
not TechnoPhobia Limited who do not accept responsibility for the contents
of the message.
All e-mail communications, in and out of TechnoPhobia, are recorded for
monitoring purposes.



Current thread: