GCN Home > March 19, 2001 issue
Biometric devices improve but still need more work
There are many ways to defeat these devices, so you need to consider their weak points

BY CARLOS A. SOTO | GCN STAFF

Call me paranoid, but I have some good company.
Most biometric security programs store the users unique physical characteristics on a hard drive, and Robert Flores, the CIAs chief technology officer, says its easy to defeat them by hacking into the middleware [see story at www.gcn.com/vol1_no1/daily-updates/3618-1.html].

When I quoted Flores statement to the five biometric vendors in this review, they either changed the subject or essentially said, Well, nothing is foolproofexcept for one company.
Net Nanny Software Inc.s representative not only agreed with Flores but also said that middleware vulnerability is what makes the companys BioPassword effective.

BioPassword is the first behavioral biometric product Ive tested that is not for password replacement but rather for password security enhancement. It compares a users log-in attempt against the users typing template in Microsoft Windows NTs SAM database on the primary domain controller.

Password flaw

Most other biometric products, such as fingerprint or voice readers, give the option of defaulting to a password instead of a biometric log-in. This is a failsafe way to admit users in case of device malfunction or finger injury or laryngitis. A hacker wouldnt have to worry about the biometric portion of the log-in so long as the user name and password were known.

But say the hacker breaks into the BioPassword code and learns the user name and password. How does the hacker then reproduce the typing pattern? Its next to impossible.

On the downside, theres no BioPassword for standalone computers, and the version for Microsoft Windows 2000 just came out. You pretty much need an NT network with a talented administrator to install and run it.

More news on related topics: Product Reviews