Out of play: fingerprints failed to stop a fifth of black-listed volunteers entering stadia

Share

Related Stories

  • Biometrics: How and Now?
    Using biometric data for identity access and management can be a controversial move. Esther Shein examines the drawbacks, and looks at where and how biometrics are currently being used
  • Crimeware soaring says Anti-Phishing Working Group
    Research just released by the Anti-Phishing Working Group (APWG) says that crimeware usage by hackers and cybercriminals in the second half of 2010 soared to high levels.
  • In security, the basics are often overlooked
    The practice and execution of fundamental skills and processes are the keys to almost any successful endeavor, whether it is in sports or in the realm of security. Infosecurity recently chatted with Colonel Barry Hensley of Dell SecureWorks who revealed that, in many security breaches he’s examined, basic security practices were neglected.
  • Unsporting Espionage
    With the 2012 Olympics fast approaching, Davey Winder takes a look at the growing problem of IP espionage in the big, expensive world of sport…
  • Laptop users need to raise their encryption game
    Fresh from releasing a range of encrypted drive kits at last week's Infosecurity Europe show, Origin Storage says that the steady stream of advances in brute force decryption techniques – which started when Russia's Elcomsoft released the first versions of its Password Recovery suite of 'utilities' around 18 months ago – means that laptop users must now raise their game when it comes to encryption.

Top 5 Stories

News

Biometrics 2007: Fingerprints fail to tackle football ‘hooligans’

19 October 2007

A fingerprint recognition system failed to prevent black-listed fans from entering football grounds and was easily fooled by simple spoofing techniques, according to a trial by Dutch research organisation TNO.

Jurgen den Hartog, who undertook the research, said that with a false accusation rate of 0.1% – a low rate being a requirement for such a system, given the volume of supporters and the fact that false accusations could spark trouble – the fingerprint system failed to spot 15% to 20% of those on a volunteer black-list, recruited to test the technology, a level he described as “unexpected”.

“This has serious implications for a lot of other negative identification scenarios,” den Hartog told a session of the Biometrics 2007 conference in London on 18 October. “It’s very easy not to look like yourself, so I wonder what the impact of these results will be on other programmes.”

Negative identification fails if a black-listed person can fool the system into thinking they are not on that list, involving technically challenging one-to-many checks. Identity verification checks, such as with passports, require only a one-to-one check that the biometric recorded matches the individual, and fails only if someone else’s identity is hijacked.

Den Hartog said that fooling the fingerprint systems, LScan 100 scanners provided by NEC and HSB, proved easy for the volunteers, who were asked to attempt such spoofing. They used techniques including latent fingerprints on sticky tape and a layer of glue on fingers: “The trick is, do not press too hard,” he said of the latter. Both techniques also fooled a spoof-resistant scanner from Lumidigm in TNO’s labs.

Furthermore, the tests brought up other problems: the devices could check 12 fans a minute at best, but as few as four or five a minute on one occasion when it was in direct sunlight by Feyenoord’s ground. “The french fries stand outside the stadium couldn’t do business any more, because of the queue for our gate,” den Hartog said.

“The live system did not meet important requirements of speed, accuracy and robustness against manipulation,” den Hartog concluded. “I think speed and accuracy can be solved, but robustness against manipulation really remains a challenge.”

The research involved 6400 checks at 26 matches at three Dutch football clubs. TNO chose fingerprints in preference to iris or facial recognition, on a range of criteria including speed, reliability and proof against being fooled.

This article is featured in:
Biometrics

 

Comment on this article

You must be registered and logged in to leave a comment about this article.