Ethical Hackers Crack Samsung Galaxy S5 Fingerprint Sensor

Researchers have shown how simple it is to bypass Samsung Galaxy S5 fingerprint authentication, less than a week after the device’s official release.

The researchers from Security Research Labs (SRLabs) re-used a fingerprint mould from their exploitation of the Apple iPhone 5S from last year, requiring “no additional effort whatsoever”. The fake print was based on a camera phone photo “of an unprocessed latent print on a smartphone screen”.

Samsung Galaxy S5 hacked

It appeared Samsung has allowed for unlimited attempts to access the device, meaning hackers could try numerous times to bypass the fingerprint authentication, without ever being locked out, the researchers said.

They showed how an attacker could hack a Samsung Galaxy S5 to gain access to a PayPal app to make purchases and unsolicited transfers.

When the Samsung Galaxy S5 was announced earlier this year, it was revealed a deal with PayPal would make it simpler to authenticate payments using fingerprints. But SRLabs has voiced concern over the decision to widen the application of biometrics, due to the apparent ease of exploitation.

“Samsung’s implementation of fingerprint authentication leaves much to be desired,”

“The fingerprint scanner in Samsung’s Galaxy S5 raises additional security concerns to those already voiced about conquerable implementations.”

Samsung had not responded to a request for comment at the time of publication.

A PayPal spokesperson said: “While we take the findings from Security Research Labs very seriously, we are still confident that fingerprint authentication offers an easier and more secure way to pay on mobile devices than passwords and PINs. PayPal never stores or even has access to your actual fingerprint with authentication on the Galaxy S5. The scan unlocks a secure cryptographic key that serves as a password replacement for the phone.

“We can simply deactivate the key from a lost or stolen device, and you can create a new one. PayPal also uses sophisticated fraud and risk management tools to try to prevent fraud before it happens. However, in the rare instances that it does, your eligible transactions are covered by our purchase protection policy.”

See the video below for the SRLabs demonstration:

Love security? Try our quiz!

Samsung Galaxy S5 MWC 2014

Image 10 of 20

Samsung Galaxy S5
Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

Recent Posts

Binance’s Changpeng Zhao Sentenced To Four Months In Prison

US judge sentences Binance founder, Changpeng Zhao, to four months in prison for ignoring money…

2 hours ago

OpenAI Hit By Austrian Complaint Over ChatGPT ‘False Data’

Rights group argues ChatGPT tendency to generate false information on individuals violates GDPR data protection…

1 day ago

EU Designates Apple’s iPad OS As DMA ‘Gatekeeper’

European Commission says Apple's iPadOS is 'gatekeeper' due to large number of businesses 'locked in'…

1 day ago

Beating the Barbarians in the Cloud

As the cloud continues to be an essential asset for all businesses, developing and maintaining…

1 day ago

Austria Conference Calls For Controls On ‘Killer Robots’

Internatinal conference in Vienna calls for controls on AI-powered autonomous weapons to ensure humans remain…

1 day ago

US Probes Ford BlueCruise Driver Assistance Over Crashes

US highway safety agency opens formal investigation into Ford BlueCruise following two fatal crashes in…

1 day ago