Exposed passwords are bad enough. But fingerprint and facial recognition data? That’s terrifying.
Suprema's Biostar 2 biometric security system came under scrutiny after vpnMentor and two researchers -- Noam Rotem and Ran Locar -- uncovered a major flaw that exposed the biometric data of more than 1 million people, according to The Guardian.
Biostar 2 is a security platform that, in part, utilizes facial recognition and fingerprints to control access to buildings and other secure facilities. Making the potential breach even worse: Biostar 2 was recently integrated into Nedap's AEOS security platform, which is used for security by thousands of companies and organizations in more than 80 countries.
The researchers said not only was the database unencrypted, but was accessed by tweaking URL search criteria in Elasticsearch, a search and analytics engine. And it contained a lot of data.
The Guardianreported that the researchers "had access to over 27.8m records, and 23 gigabytes-worth of data including admin panels, dashboards, fingerprint data, facial recognition data, face photos of users, unencrypted usernames and passwords, logs of facility access, security levels and clearance, and personal details of staff."
According to vpnMentor, the exposed data was discovered on Aug. 5, 2019. Two days later, they notified Biostar 2 of the issue and by Aug. 13, the database was private. It's not known how long all of that information was accessible and if anyone, particularly bad actors, had gained access to the database.
What's more, vpnMentor reports that Biostar's office was "generally very uncooperative."
SEE ALSO: Amazon claims its Rekognition software can now detect fearAmong the U.S.-based businesses the researchers were able to access data for: co-working space Union and medical supply company Phoenix Medical. But The Guardian notes that organizations that are part of AEOS include "governments, banks and the UK Metropolitan police."
We've reached out to Suprema for additional comment but, for now, you can continue to rest, uh, uneasily knowing that your data will never be fully secure.
Copyright © 2023 Powered by
Major security flaw exposes fingerprints of more than 1 million people-粲然可观网
sitemap
文章
1
浏览
3
获赞
4233
The FBI must be stoked about Zoom's encryption policy
Zoom has big privacy plans — for its paying customers, that is.After getting caught falsely clPeople keep dropping their AirPods onto subway tracks
The embodiment of the tech industry is firmly planted in one ear — and falling right out the oReview: The Forest app helps you go phone
I'm obsessed with my phone. Addicted to it, really. It's not something I'm proud of, but alas, it'sCarrie Underwood and Brad Paisley brilliantly trolled Donald Trump at the CMAs
It seems like trolling POTUS is a trendy celebrity activity to do these days.Last night at the CountBitcoin wipes coronavirus losses, passes $10,000 again
There's a popular meme that shows Bitcoin on a perpetual rollercoaster. It's true: The world's largeHow to watch Facebook's F8 2019 keynote live
Facebook's annual F8 developer conference is finally upon us, bringing plenty of new announcements aHow to watch Google I/O 2019 keynote and what to expect
Tech conference season is in full swing. Facebook had its F8 keynote earlier this week, and now GoogTwitter is celebrating the anniversary of Lenny Kravitz wearing a giant scarf
You were probably so distracted by Thanksgiving this weekend that you may have failed to mark a deepFacebook insists new Workplace tool was for 'preventing bullying,' not suppressing unions
Facebook wants to empower you to make the world more open and connected as you suppress your workersElon Musk's favorite Autopilot feature just got updated
Elon Musk let us know earlier this year that when he drives, he uses Tesla's semi-autonomous drivingJennifer Lawrence and Darren Aronofsky have broken up and everyone is making the same joke
Jennifer Lawrence and director Darren Aronofsky have had an "amicable split," Entertainment TonightrJennifer Lawrence and Darren Aronofsky have broken up and everyone is making the same joke
Jennifer Lawrence and director Darren Aronofsky have had an "amicable split," Entertainment TonightrArtists on Twitter are drawing their favorite shipping dynamics for this new meme
Once you've binge-watched enough Netflixshows, you start to see a pattern in the characters you getWhat dessert will Google name Android Q?
Let the speculation begin.As expected, Google announced more details about the next version of Andro2 women file class
Uber is facing a class-action lawsuit over sexual assaults by drivers.The lawsuit, filed in the Nort