Jump to content

Banks ban Galaxy S10 Fingerprint Reader - Fingerprint log in removed from banking apps

yolosnail

Related to the recent security flaw found with the Galaxy S/Note 10 series, which you can read more about below 

Banks in the UK have decided that the flaw with the fingerprint reader is too much of a compromise for its customers and have started removing the fingerprint option for the app. 

At the moment it's just Nationwide and Natwest that have done so, but I wouldn't be surprised if others followed suit.

 

Quote

UK bank Nationwide Building Society has disabled the fingerprint login option in its app for owners of Samsung Galaxy S10 phones. Another, NatWest, has completely removed support for S10 phones.

It's not just banks in the UK, Bank of China, Hapoalim Bank and KaKao Bank have either removed support or send out a notice to customers telling them to disable it.

Quote

It looks like the Bank of China has dropped support for Galaxy S10, Note10 and Tab S6 owners. Hapoalim Bank, one of Israel’s largest banks, sent out a notice to its customers who use an S10 or Note10 that it has removed support for fingerprint authentication as well. South Korea’s KaKao Bank (an online-only bank) has warned its users to disable fingerprint authentication.

 

I'm honestly surprised they didn't pull the support sooner, with mobile banking it's easy for someone to empty your account and because it was authenticated biometrically I'd imagine there'd be very little chance of you getting your money back.

 

Condiment: https://www.gsmarena.com/banks_around_the_world_are_removing_support_for_the_galaxy_s10_and_note10_from_their_apps-news-39756.php

https://9to5google.com/2019/10/22/s10-fingerprint-banks/

 

Note to mods - feel free to merge with the previous topic if you don't think it's worthy of it's own

 

also, sorry for the clickbait, I couldn't help myself

Laptop:

Spoiler

HP OMEN 15 - Intel Core i7 9750H, 16GB DDR4, 512GB NVMe SSD, Nvidia RTX 2060, 15.6" 1080p 144Hz IPS display

PC:

Spoiler

Vacancy - Looking for applicants, please send CV

Mac:

Spoiler

2009 Mac Pro 8 Core - 2 x Xeon E5520, 16GB DDR3 1333 ECC, 120GB SATA SSD, AMD Radeon 7850. Soon to be upgraded to 2 x 6 Core Xeons

Phones:

Spoiler

LG G6 - Platinum (The best colour of any phone, period)

LG G7 - Moroccan Blue

 

Link to comment
Share on other sites

Link to post
Share on other sites

Good. Though I presume this is more to protect them from someone claiming their phone was stolen than really customer security. 

Retried Battlefield Moderator EA Star Wars Battlefront Senior Moderator  Battlefield Moderator and EA Champion

Link to comment
Share on other sites

Link to post
Share on other sites

I still don't get it how can a layer of silicone/TPU unlock the phone with any fingerprint. Or is having existing fingerprint from former scans on a glass over the fingerprint sensor and extra layer on top of it makes scanner think it's obtaining legit fingerprint? I couldn't find any info on details. Coz just matching any fingerprint with one stored because some layer is in between makes absolutely no sense. If anything it would or at least should cause even actualowner having problems logging in, not the opposite...

Link to comment
Share on other sites

Link to post
Share on other sites

My work phone gets shared with multiple people. It doesnt have a finger print reader, and if it did i bet we wouldnt use it. It would be cool to have a ring that unlocks things instead of a fingerprint.

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, VegetableStu said:

frankly that should extend to the Pixel 4's faceID ._.

frankly we should all just be forced to remember a 25 digit number 

or a random string of 25 symbols

Link to comment
Share on other sites

Link to post
Share on other sites

22 minutes ago, RejZoR said:

Coz just matching any fingerprint with one stored because some layer is in between makes absolutely no sense.

The screen protector was just how the bug was found but i believe it actually will unlock with any finger print regardless of a screen protector.

                     ¸„»°'´¸„»°'´ Vorticalbox `'°«„¸`'°«„¸
`'°«„¸¸„»°'´¸„»°'´`'°«„¸Scientia Potentia est  ¸„»°'´`'°«„¸`'°«„¸¸„»°'´

Link to comment
Share on other sites

Link to post
Share on other sites

6 minutes ago, vorticalbox said:

The screen protector was just how the bug was found but i believe it actually will unlock with any finger print regardless of a screen protector.

But how? And how it doesn't affect other phones from Samsung? And how it can't be easily fixed is also weird...

Link to comment
Share on other sites

Link to post
Share on other sites

The sensor used on these is likely just crappy/buggy...

F@H
Desktop: i9-13900K, ASUS Z790-E, 64GB DDR5-6000 CL36, RTX3080, 2TB MP600 Pro XT, 2TB SX8200Pro, 2x16TB Ironwolf RAID0, Corsair HX1200, Antec Vortex 360 AIO, Thermaltake Versa H25 TG, Samsung 4K curved 49" TV, 23" secondary, Mountain Everest Max

Mobile SFF rig: i9-9900K, Noctua NH-L9i, Asrock Z390 Phantom ITX-AC, 32GB, GTX1070, 2x1TB SX8200Pro RAID0, 2x5TB 2.5" HDD RAID0, Athena 500W Flex (Noctua fan), Custom 4.7l 3D printed case

 

Asus Zenbook UM325UA, Ryzen 7 5700u, 16GB, 1TB, OLED

 

GPD Win 2

Link to comment
Share on other sites

Link to post
Share on other sites

As a nationwide customer and S10+ owner it looks as though you can still use the fingerprint scanner when you log into the app you just get this message afterwards (can't take a screenshot of this unfortunatly)"Fingerprint log in on this Samsung Device You may have seen some news coverage about Samsung S10 fingerprint security. Samsung have said a software patch is on its way. Until then, if you haven't done so already, we recommend you disable fingerprint login which you can do via Settings in the app" 

So it looks to only be a recommendation

Edit: I'll just use my webcam for a picWIN_20191023_14_05_38_Pro.jpg.9993cfe7cf22806219bf54b137e38b7b.jpg

Processor: i7 7700k@Stock GPU: GTX 1080 MSI Armor OC  Mobo: Asus Prime Z270-A RAM: Corsair LPX 16GB 3200 MHz CPU Cooler: be quiet! Dark Rock 3 SSD: Sandisk Ultra 2 960GB Case: Phanteks P400s PSU: Gigabyte B700H Monitor: AOC G2460PF 1080p 144Hz Mouse: Logitech G900 Keyboard: Corsair Strafe w/ MX Blues

Link to comment
Share on other sites

Link to post
Share on other sites

55 minutes ago, yolosnail said:

also, sorry for the clickbait, I couldn't help myself

@yolosnail I've edited the title slightly to more accurately reflect the topic. As others have pointed out it was a little too confusing calling it a "Nationwide ban" referring to the bank "Nationwide".

CPU: Intel i7 6700k  | Motherboard: Gigabyte Z170x Gaming 5 | RAM: 2x16GB 3000MHz Corsair Vengeance LPX | GPU: Gigabyte Aorus GTX 1080ti | PSU: Corsair RM750x (2018) | Case: BeQuiet SilentBase 800 | Cooler: Arctic Freezer 34 eSports | SSD: Samsung 970 Evo 500GB + Samsung 840 500GB + Crucial MX500 2TB | Monitor: Acer Predator XB271HU + Samsung BX2450

Link to comment
Share on other sites

Link to post
Share on other sites

Yeah, the headline was (unintentionally) misleading.

 

With that said: what is it with Android vendors being unable to make biometric security that can actually be used for secure tasks?  It seems like it's either wildly insecure, should be secure but has a flaw, or isn't quite secure enough to be trustworthy for payment apps.  Even the Pixel 4 can log you in when your eyes are closed (i.e. against your will).

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, RejZoR said:

But how? And how it doesn't affect other phones from Samsung? And how it can't be easily fixed is also weird...

because finger print readers are a "that's close enough" as you have very limited space, and in this case everything was good enough. its a software bug where anything matches to the scanned finger print stored on the device.

 

The more worrying part is that no one at Samsung went "hey Jeff can try your finger on my phone"

                     ¸„»°'´¸„»°'´ Vorticalbox `'°«„¸`'°«„¸
`'°«„¸¸„»°'´¸„»°'´`'°«„¸Scientia Potentia est  ¸„»°'´`'°«„¸`'°«„¸¸„»°'´

Link to comment
Share on other sites

Link to post
Share on other sites

I have had an S10 and a Note 10 and I haven't been able to replicate this "bug" with my other fingers or my GF's fingers. ¯\_(ツ)_/¯

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, vorticalbox said:

because finger print readers are a "that's close enough" as you have very limited space, and in this case everything was good enough. its a software bug where anything matches to the scanned finger print stored on the device.

 

The more worrying part is that no one at Samsung went "hey Jeff can try your finger on my phone"

You can't have something this roughly defined. Especially not something as specific as fingerprint. If anything it would just refuse to match, not match with anything...

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, RejZoR said:

You can't have something this roughly defined. Especially not something as specific as fingerprint. If anything it would just refuse to match, not match with anything...

but if you make it exact then people would have to reinput their fingerprint every time their hand grows and it doesnt work if their finger isnt perfectly clean or the sensor

Link to comment
Share on other sites

Link to post
Share on other sites

Welp, thank goodness I got the S10e. Uses the old school capacitive scanner. *wipes sweat* Not gonna lie, I enjoy the finger print convenience. 

- Fresher than a fruit salad.

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, spartaman64 said:

but if you make it exact then people would have to reinput their fingerprint every time their hand grows and it doesnt work if their finger isnt perfectly clean or the sensor

Lol? You do know things can be adaptive? Just because your finger grows, your pattern is the same, it just expands at certain ratio. And one thing is if there are some cuts in your finger it can still have certain level of sensitivity that's not 100%.

Link to comment
Share on other sites

Link to post
Share on other sites

Just Tried on my S10, First direct have disabled fingerprint login, Santander hasn't but a warning screen does pop up suggesting I disable the feature.

 

 

CPU: i7 5820k @4.4GHz | MoboMSI MPower X99A | RAM: 16GB DDR4 Quad Channel Corsair LP | GPU: EVGA 1080 FTW Case: Define R5 Black Window | OS: Win 10 Pro

Storage: SanDisk Ultra II 960GB 2x WD Red 4TB | PSU: EVGA 750W G2 | Display:Acer XF270HU + Dell U2515H | Cooling: Phanteks PH-TC14PE

Keyboard: Ducky One  TKL Browns | Mouse: Steel Series Rival 300 | Sound: DT990s

 

Link to comment
Share on other sites

Link to post
Share on other sites

i'd say google is happy they didn't include a finger print scanner, but you can literally unlock your phone with closed eyes or a lookalike or even a pic of you, so there's that. 

 

Spoiler
Spoiler

AMD 5000 Series Ryzen 7 5800X| MSI MAG X570 Tomahawk WiFi | G.SKILL Trident Z RGB 32GB (2 * 16GB) DDR4 3200MHz CL16-18-18-38 | Asus GeForce GTX 3080Ti STRIX | SAMSUNG 980 PRO 500GB PCIe NVMe Gen4 SSD M.2 + Samsung 970 EVO Plus 1TB PCIe NVMe M.2 (2280) Gen3 | Cooler Master V850 Gold V2 Modular | Corsair iCUE H115i RGB Pro XT | Cooler Master Box MB511 | ASUS TUF Gaming VG259Q Gaming Monitor 144Hz, 1ms, IPS, G-Sync | Logitech G 304 Lightspeed | Logitech G213 Gaming Keyboard |

PCPartPicker 

Link to comment
Share on other sites

Link to post
Share on other sites

Hopefully US banks retain support for TouchID devices and don’t go all McCarthy on fingerprint readers just because Samsung has a bad implementation. 

Laptop: 2019 16" MacBook Pro i7, 512GB, 5300M 4GB, 16GB DDR4 | Phone: iPhone 13 Pro Max 128GB | Wearables: Apple Watch SE | Car: 2007 Ford Taurus SE | CPU: R7 5700X | Mobo: ASRock B450M Pro4 | RAM: 32GB 3200 | GPU: ASRock RX 5700 8GB | Case: Apple PowerMac G5 | OS: Win 11 | Storage: 1TB Crucial P3 NVME SSD, 1TB PNY CS900, & 4TB WD Blue HDD | PSU: Be Quiet! Pure Power 11 600W | Display: LG 27GL83A-B 1440p @ 144Hz, Dell S2719DGF 1440p @144Hz | Cooling: Wraith Prism | Keyboard: G610 Orion Cherry MX Brown | Mouse: G305 | Audio: Audio Technica ATH-M50X & Blue Snowball | Server: 2018 Core i3 Mac mini, 128GB SSD, Intel UHD 630, 16GB DDR4 | Storage: OWC Mercury Elite Pro Quad (6TB WD Blue HDD, 12TB Seagate Barracuda, 1TB Crucial SSD, 2TB Seagate Barracuda HDD)
Link to comment
Share on other sites

Link to post
Share on other sites

9 minutes ago, DrMacintosh said:

Hopefully US banks retain support for TouchID devices and don’t go all McCarthy on fingerprint readers just because Samsung has a bad implementation. 

US banks have apps? I thought they were stuck with 1970s technology!

Laptop:

Spoiler

HP OMEN 15 - Intel Core i7 9750H, 16GB DDR4, 512GB NVMe SSD, Nvidia RTX 2060, 15.6" 1080p 144Hz IPS display

PC:

Spoiler

Vacancy - Looking for applicants, please send CV

Mac:

Spoiler

2009 Mac Pro 8 Core - 2 x Xeon E5520, 16GB DDR3 1333 ECC, 120GB SATA SSD, AMD Radeon 7850. Soon to be upgraded to 2 x 6 Core Xeons

Phones:

Spoiler

LG G6 - Platinum (The best colour of any phone, period)

LG G7 - Moroccan Blue

 

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, yolosnail said:

US banks have apps? I thought they were stuck with 1970s technology!

See, you have US banks mistaken for US government agencies. By that, I mean the ATF still uses good ol' paper and the FBI uses god-knows-what ancient hardware alongside bleeding edge hardware.

Check out my guide on how to scan cover art here!

Local asshole and 6th generation console enthusiast.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×