Jump to content

Screen protector defeats Samsung Galaxy S10 fingerprint reader

porina
Quote

A flaw that means any fingerprint can unlock a Galaxy S10 phone has been acknowledged by Samsung.

 

It promised a software patch that would fix the problem.

 

The issue was spotted by a British woman whose husband was able to unlock her phone with his fingerprint just by adding a cheap screen protector.

https://www.bbc.com/news/technology-50080586

 

Well, that's a bit of an oversight on Samsung's part. It will be interesting to understand the technical reasons why this happens, unless it is just a massive flaw in the software somewhere. We rely on technology like fingerprint readers to limit access to our devices and associated services like payment authorisation, so anything that breaks it is a concern. Owners of the affected phone may want to exercise caution until the fix is in place. It will also be curious to see if a similar attacks also work on other manufacturer's implementations.

Main system: i9-7980XE, Asus X299 TUF mark 2, Noctua D15, Corsair Vengeance Pro 3200 3x 16GB 2R, RTX 3070, NZXT E850, GameMax Abyss, Samsung 980 Pro 2TB, Acer Predator XB241YU 24" 1440p 144Hz G-Sync + HP LP2475w 24" 1200p 60Hz wide gamut
Gaming laptop: Lenovo Legion 5, 5800H, RTX 3070, Kingston DDR4 3200C22 2x16GB 2Rx8, Kingston Fury Renegade 1TB + Crucial P1 1TB SSD, 165 Hz IPS 1080p G-Sync Compatible

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, VegetableStu said:

was the fingerprint registered before or after the screen protector? o_o

What I understand it , her right thumb was scanned before the protector. After the protector she could unlock it with her left thumb aswell as both thumbs of the husband

Link to comment
Share on other sites

Link to post
Share on other sites

18 minutes ago, VegetableStu said:

hmm, so is this a resolution thing through an extra layer? like would it also bug out when it's registered after applying? o_o

Good questions.

 

Some other sites have also covered it but I've not reviewed them to see if they have different information.

 

One way I could speculate about is what if some fingerprint residue was left before the screen protector was applied. Could that still be picked up after? I might have to ask around the office to see if anyone has one of these phones. If you don't pick an iPhone you get a Samsung, so there is a fair chance.

Main system: i9-7980XE, Asus X299 TUF mark 2, Noctua D15, Corsair Vengeance Pro 3200 3x 16GB 2R, RTX 3070, NZXT E850, GameMax Abyss, Samsung 980 Pro 2TB, Acer Predator XB241YU 24" 1440p 144Hz G-Sync + HP LP2475w 24" 1200p 60Hz wide gamut
Gaming laptop: Lenovo Legion 5, 5800H, RTX 3070, Kingston DDR4 3200C22 2x16GB 2Rx8, Kingston Fury Renegade 1TB + Crucial P1 1TB SSD, 165 Hz IPS 1080p G-Sync Compatible

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, porina said:

One way I could speculate about is what if some fingerprint residue was left before the screen protector was applied. Could that still be picked up after?

That is basically how fingerprints have been bypassed for decades now and it seems it still works to this day.

Hand, n. A singular instrument worn at the end of the human arm and commonly thrust into somebody’s pocket.

Link to comment
Share on other sites

Link to post
Share on other sites

35 minutes ago, Sauron said:

I've said for years that if you care about security you should use a normal password.

yeah but privacy is dead d-_-b

8086k

aorus pro z390

noctua nh-d15s chromax w black cover

evga 3070 ultra

samsung 128gb, adata swordfish 1tb, wd blue 1tb

seasonic 620w dogballs psu

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

So just don't use cheap screen protectors that are mushy? Haven't had any problems with mine, I've replaced my screen protector already,and will be a lot because of the inability to use a glass screen protector.

Corsair 4000D RGB

Asus B550 Tuf Gaming II

Asus 7700XT Tuf Gaming

AMD 5600x3d

32gb 3200mhz gskil 

 

Link to comment
Share on other sites

Link to post
Share on other sites

47 minutes ago, veldora said:

So just don't use cheap screen protectors that are mushy? Haven't had any problems with mine, I've replaced my screen protector already,and will be a lot because of the inability to use a glass screen protector.

I really wanted a glass one, but there's only one of the market that works with the built in finger print reader and it's because it uses either thinner glass or no glass at the spot where the scanner is. Currently I'm running without one at all, because i find any non-glass protector to feel sticky and add friction to swipes compared to glass.

"Put as much effort into your question as you'd expect someone to give in an answer"- @Princess Luna

Make sure to Quote posts or tag the person with @[username] so they know you responded to them!

 RGB Build Post 2019 --- Rainbow 🦆 2020 --- Velka 5 V2.0 Build 2021

Purple Build Post ---  Blue Build Post --- Blue Build Post 2018 --- Project ITNOS

CPU i7-4790k    Motherboard Gigabyte Z97N-WIFI    RAM G.Skill Sniper DDR3 1866mhz    GPU EVGA GTX1080Ti FTW3    Case Corsair 380T   

Storage Samsung EVO 250GB, Samsung EVO 1TB, WD Black 3TB, WD Black 5TB    PSU Corsair CX750M    Cooling Cryorig H7 with NF-A12x25

Link to comment
Share on other sites

Link to post
Share on other sites

Meanwhile the fp scanner on my Pixel 3 doesn't work with any prints at all, even ones registered.

Main Rig:-

Ryzen 7 3800X | Asus ROG Strix X570-F Gaming | 16GB Team Group Dark Pro 3600Mhz | Corsair MP600 1TB PCIe Gen 4 | Sapphire 5700 XT Pulse | Corsair H115i Platinum | WD Black 1TB | WD Green 4TB | EVGA SuperNOVA G3 650W | Asus TUF GT501 | Samsung C27HG70 1440p 144hz HDR FreeSync 2 | Ubuntu 20.04.2 LTS |

 

Server:-

Intel NUC running Server 2019 + Synology DSM218+ with 2 x 4TB Toshiba NAS Ready HDDs (RAID0)

Link to comment
Share on other sites

Link to post
Share on other sites

22 minutes ago, TVwazhere said:

I really wanted a glass one, but there's only one of the market that works with the built in finger print reader and it's because it uses either thinner glass or no glass at the spot where the scanner is. Currently I'm running without one at all, because i find any non-glass protector to feel sticky and add friction to swipes compared to glass.

Yeah they have a cut out where the scanner is, and to me that defeats the purpose of a screen protector. Even having a plastic screen protector seems trivial, because the oe one got scratched on everything.
 

Spoiler

We'll see how this gorilla one holds up. They have you spray the screen down with their water/detergent then apply the protector and squeegee the water out. Sounds like it'd void a warranty on the installation alone, but alright... The edges don't hold on well. Maybe I should've heated them up to adhere better. But it's too late now, they have lint in them.

 

Corsair 4000D RGB

Asus B550 Tuf Gaming II

Asus 7700XT Tuf Gaming

AMD 5600x3d

32gb 3200mhz gskil 

 

Link to comment
Share on other sites

Link to post
Share on other sites

I could understand if the fingerprint was setup AFTER the screen protector was installed due but not before...

PLEASE QUOTE ME IF YOU ARE REPLYING TO ME

Desktop Build: Ryzen 7 2700X @ 4.0GHz, AsRock Fatal1ty X370 Professional Gaming, 48GB Corsair DDR4 @ 3000MHz, RX5700 XT 8GB Sapphire Nitro+, Benq XL2730 1440p 144Hz FS

Retro Build: Intel Pentium III @ 500 MHz, Dell Optiplex G1 Full AT Tower, 768MB SDRAM @ 133MHz, Integrated Graphics, Generic 1024x768 60Hz Monitor


 

Link to comment
Share on other sites

Link to post
Share on other sites

This is why fingerprint scanners should stay where they belong, on the back!

Laptop:

Spoiler

HP OMEN 15 - Intel Core i7 9750H, 16GB DDR4, 512GB NVMe SSD, Nvidia RTX 2060, 15.6" 1080p 144Hz IPS display

PC:

Spoiler

Vacancy - Looking for applicants, please send CV

Mac:

Spoiler

2009 Mac Pro 8 Core - 2 x Xeon E5520, 16GB DDR3 1333 ECC, 120GB SATA SSD, AMD Radeon 7850. Soon to be upgraded to 2 x 6 Core Xeons

Phones:

Spoiler

LG G6 - Platinum (The best colour of any phone, period)

LG G7 - Moroccan Blue

 

Link to comment
Share on other sites

Link to post
Share on other sites

Should start investing hearbeat sensors for mobile phones.

Specs: Motherboard: Asus X470-PLUS TUF gaming (Yes I know it's poor but I wasn't informed) RAM: Corsair VENGEANCE® LPX DDR4 3200Mhz CL16-18-18-36 2x8GB

            CPU: Ryzen 9 5900X          Case: Antec P8     PSU: Corsair RM850x                        Cooler: Antec K240 with two Noctura Industrial PPC 3000 PWM

            Drives: Samsung 970 EVO plus 250GB, Micron 1100 2TB, Seagate ST4000DM000/1F2168 GPU: EVGA RTX 2080 ti Black edition

Link to comment
Share on other sites

Link to post
Share on other sites

This isnt a Samsung thing this is any under screen finger print reader. If you have a screen protector it can mess up the under screen finger print reader. Since alot of the protectors have almost a glue like substance this could reflect light and interfere with the scanner. So if they had the protector on before they scanned their finger print it could cause an issue. Since the scanner is scanning the screen protector substance and its not changing according to the phone its always correct so as far as I see the scanner is working? 

 

Example of glue like substance that could easily interfere 

This is what BestBuy uses (as far as I am aware) where there is a fluid that keeps the plastic to the screen. 

Link to comment
Share on other sites

Link to post
Share on other sites

I doubt it’s as big of a deal as it seems. Most, if not all of these minor security concerns go untouched by the public. But I do feel obligated to plug TouchID which is only fooled by forensics. 

Laptop: 2019 16" MacBook Pro i7, 512GB, 5300M 4GB, 16GB DDR4 | Phone: iPhone 13 Pro Max 128GB | Wearables: Apple Watch SE | Car: 2007 Ford Taurus SE | CPU: R7 5700X | Mobo: ASRock B450M Pro4 | RAM: 32GB 3200 | GPU: ASRock RX 5700 8GB | Case: Apple PowerMac G5 | OS: Win 11 | Storage: 1TB Crucial P3 NVME SSD, 1TB PNY CS900, & 4TB WD Blue HDD | PSU: Be Quiet! Pure Power 11 600W | Display: LG 27GL83A-B 1440p @ 144Hz, Dell S2719DGF 1440p @144Hz | Cooling: Wraith Prism | Keyboard: G610 Orion Cherry MX Brown | Mouse: G305 | Audio: Audio Technica ATH-M50X & Blue Snowball | Server: 2018 Core i3 Mac mini, 128GB SSD, Intel UHD 630, 16GB DDR4 | Storage: OWC Mercury Elite Pro Quad (6TB WD Blue HDD, 12TB Seagate Barracuda, 1TB Crucial SSD, 2TB Seagate Barracuda HDD)
Link to comment
Share on other sites

Link to post
Share on other sites

47 minutes ago, williamcll said:

Should start investing hearbeat sensors for mobile phones.

Ever watched the Mythbusters? They once managed to break a multi thousand dollar fp lock which had moisture, temperature and heartbeat sensing.

 

They did it by creating an analog print out of ballistic gel then attaching it to a real finger and licking it for moisture.

 

No system is ever fool proof.

Main Rig:-

Ryzen 7 3800X | Asus ROG Strix X570-F Gaming | 16GB Team Group Dark Pro 3600Mhz | Corsair MP600 1TB PCIe Gen 4 | Sapphire 5700 XT Pulse | Corsair H115i Platinum | WD Black 1TB | WD Green 4TB | EVGA SuperNOVA G3 650W | Asus TUF GT501 | Samsung C27HG70 1440p 144hz HDR FreeSync 2 | Ubuntu 20.04.2 LTS |

 

Server:-

Intel NUC running Server 2019 + Synology DSM218+ with 2 x 4TB Toshiba NAS Ready HDDs (RAID0)

Link to comment
Share on other sites

Link to post
Share on other sites

2 hours ago, GodSeph said:

This isnt a Samsung thing this is any under screen finger print reader. If you have a screen protector it can mess up the under screen finger print reader. Since alot of the protectors have almost a glue like substance this could reflect light and interfere with the scanner. So if they had the protector on before they scanned their finger print it could cause an issue. Since the scanner is scanning the screen protector substance and its not changing according to the phone its always correct so as far as I see the scanner is working? 

 

Example of glue like substance that could easily interfere 

This is what BestBuy uses (as far as I am aware) where there is a fluid that keeps the plastic to the screen. 

Ah, so not only a risk of sticking an old print in place on the screen (grease/dirt imprint) but also registering the protector AS yourprints. XD

Link to comment
Share on other sites

Link to post
Share on other sites

I made a patch. Samsung can thank me in beer.

 

If(!finger.canRead()){ return REJECT_ACCESS; }

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, TechyBen said:

Ah, so not only a risk of sticking an old print in place on the screen (grease/dirt imprint) but also registering the protector AS yourprints. XD

I dont have a way to test and prove this is the case but as someone who has installed over 1000 of these for people that when you had covers for the back they always had a cutout for the finger print reader. Now that there are in screen finger print readers 1 could wonder if that gel with the plastic is having an affect on the scanner and its picking up hardend gel/plastic instead of your fingerprint. This would allow anyone to open the phone as the gel/plastic isnt moving and it technically correct according to the phone.  

Link to comment
Share on other sites

Link to post
Share on other sites

For those of you who want a demonstration of this, a Twitter user recorded this using a Note 10:

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

There is a chance that it is just a greasy print being trapped under the protector. The sensor is picking that up instead of the actual finger which is now further away.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×