Exposed passwords are bad enough. But fingerprint and facial recognition data? That’s terrifying.
Suprema's Biostar 2 biometric security system came under scrutiny after vpnMentor and two researchers -- Noam Rotem and Ran Locar -- uncovered a major flaw that exposed the biometric data of more than 1 million people, according to The Guardian.
Biostar 2 is a security platform that, in part, utilizes facial recognition and fingerprints to control access to buildings and other secure facilities. Making the potential breach even worse: Biostar 2 was recently integrated into Nedap's AEOS security platform, which is used for security by thousands of companies and organizations in more than 80 countries.
The researchers said not only was the database unencrypted, but was accessed by tweaking URL search criteria in Elasticsearch, a search and analytics engine. And it contained a lot of data.
The Guardianreported that the researchers "had access to over 27.8m records, and 23 gigabytes-worth of data including admin panels, dashboards, fingerprint data, facial recognition data, face photos of users, unencrypted usernames and passwords, logs of facility access, security levels and clearance, and personal details of staff."
According to vpnMentor, the exposed data was discovered on Aug. 5, 2019. Two days later, they notified Biostar 2 of the issue and by Aug. 13, the database was private. It's not known how long all of that information was accessible and if anyone, particularly bad actors, had gained access to the database.
What's more, vpnMentor reports that Biostar's office was "generally very uncooperative."
SEE ALSO: Amazon claims its Rekognition software can now detect fearAmong the U.S.-based businesses the researchers were able to access data for: co-working space Union and medical supply company Phoenix Medical. But The Guardian notes that organizations that are part of AEOS include "governments, banks and the UK Metropolitan police."
We've reached out to Suprema for additional comment but, for now, you can continue to rest, uh, uneasily knowing that your data will never be fully secure.
Copyright © 2023 Powered by
Major security flaw exposes fingerprints of more than 1 million people-山眉水眼网
sitemap
文章
2
浏览
3
获赞
6
Facebook tries to warn users about Apple 'tax,' Apple says no
Apple and Facebook are clashing heads again. Facebook recently tried to inform its users that AppleApple's new credit card gets compared to Billy McFarland's credit card scam
Someone didn't watch the Fyre Festival documentaries. Apple announced its groundbreaking new pay fea15 things that ALWAYS go wrong on Food Network's 'Chopped'
Food Network's Chopped invokes a certain kind of screaming-at-your-TV-screen carnal energy -- the baThe Google Fit health app is now on iOS
There's certainly no shortage of health-tracking options on iOS devices, between Apple Health, FitbiRobocalls, WeChat messages, and more spread misinformation on Election Day
It's Nov. 3, Election Day, and you know what that means: Misinformation will be flooding the interneThe viral 'Trashtag Challenge' encourages people to clean up litter
There's a new viral challenge spreading across social media, and it's making the world a cleaner plaElon Musk drops first SoundCloud track, 'RIP Harambe.' Yes, you read that right
Elon Musk just colonized a whole new world of WTF.The Tesla and SpaceX CEO dropped a track on SoundCBerlin zoo's new polar bear is the adorable ray of light we need
As we struggle our way through the cold mud towards spring amidst a barrage of awful news, it's goodBoomers killed the Facebook status
Few leisure activities bring boomers more satisfaction than complaining about millennials, but usingWatch these adorable dogs absolutely crush the cheese challenge
The cheese challenge is still going strong. People have been throwing cheese on cats, dogs, and mosWatch these adorable dogs absolutely crush the cheese challenge
The cheese challenge is still going strong. People have been throwing cheese on cats, dogs, and mosWhy Thursday's 'Superstore' is part of a pivotal Hollywood moment
To any viewer, Thursday's episode of Superstore("Cloud Green") was nothing overtly out of the ordinaDid Trump forget about his TikTok ban? TikTok would like to know.
President Trump has been very busy with his re-election campaign and, of late, dubious legal challenDating app reveals the best 'Game of Thrones' icebreakers
If you're trying to spark a conversation with a fellow Game of Thronesfan, open with... the Red WeddApple now lists 2013 MacBook Air and 2014 MacBook Pro as 'vintage products'
Apple laptops aren't cheap, so you expect to get a good few years out of them before upgrading again