Добавить новость
News in English


Новости сегодня

Новости от TheMoneytizer

UK Biometrics Firm Failed To Protect Sensitive Data

A large breach of personal data, including one million fingerprints, facial recognition info, passwords and other sensitive information, was found to be publicly accessible by a company that provides centralized data access for security organizations, according to a report by The Guardian.

The company, called Suprema, created the biometrics-based Biostar 2 lock system. It offers centralized control that enables people to access secure buildings using facial recognition and fingerprints for identification.

Suprema announced in July that it was integrating into a different control system called AEOS, which is used in 83 countries by around 5,700 organizations including police stations, banks and governments.

Two researchers, Noam Rotem and Ran Locar, work with a venture called vpnMentor, which assesses virtual private network (VPN) services. They have been working to find vulnerabilities in corporate systems that could lead to data breaches. They found one last week in Biostar 2; they were able to locate the database by changing URL data. Once they got in, they gained access to almost 28 million records and 23 gigabytes of data that included photos of faces, fingerprints, unencrypted passwords and personal details. Much of the information was unencrypted.

“We were able to find plain-text passwords of administrator accounts,” Rotem said. “…Millions of users are using this system to access different locations and see in real time which user enters which facility or which room in each facility, even. We [were] able to change data and add new users.”

The researchers noted that while passwords can be changed during a data breach, fingerprints cannot. “Instead of saving a hash of the fingerprint (that can’t be reverse-engineered), they are saving people’s actual fingerprints that can be copied for malicious purposes,” they said.

The researchers said they tried to get in touch with Suprema, but were not successful. Andy Ahn, Suprema’s head of marketing, told The Guardian it had fully evaluated the issue and would let people know if there was a problem. “If there has been any definite threat on our products and/or services, we will take immediate actions and make appropriate announcements to protect our customers’ valuable businesses and assets,” he said, adding that the problem had been fixed.

Читайте на сайте


Smi24.net — ежеминутные новости с ежедневным архивом. Только у нас — все главные новости дня без политической цензуры. Абсолютно все точки зрения, трезвая аналитика, цивилизованные споры и обсуждения без взаимных обвинений и оскорблений. Помните, что не у всех точка зрения совпадает с Вашей. Уважайте мнение других, даже если Вы отстаиваете свой взгляд и свою позицию. Мы не навязываем Вам своё видение, мы даём Вам срез событий дня без цензуры и без купюр. Новости, какие они есть —онлайн с поминутным архивом по всем городам и регионам России, Украины, Белоруссии и Абхазии. Smi24.net — живые новости в живом эфире! Быстрый поиск от Smi24.net — это не только возможность первым узнать, но и преимущество сообщить срочные новости мгновенно на любом языке мира и быть услышанным тут же. В любую минуту Вы можете добавить свою новость - здесь.




Новости от наших партнёров в Вашем городе

Ria.city
Музыкальные новости
Новости России
Экология в России и мире
Спорт в России и мире
Moscow.media










Топ новостей на этот час

Rss.plus