Exposed passwords are bad enough. But fingerprint and facial recognition data? That’s terrifying.
Suprema's Biostar 2 biometric security system came under scrutiny after vpnMentor and two researchers -- Noam Rotem and Ran Locar -- uncovered a major flaw that exposed the biometric data of more than 1 million people, according to The Guardian.
Biostar 2 is a security platform that, in part, utilizes facial recognition and fingerprints to control access to buildings and other secure facilities. Making the potential breach even worse: Biostar 2 was recently integrated into Nedap's AEOS security platform, which is used for security by thousands of companies and organizations in more than 80 countries.
The researchers said not only was the database unencrypted, but was accessed by tweaking URL search criteria in Elasticsearch, a search and analytics engine. And it contained a lot of data.
The Guardianreported that the researchers "had access to over 27.8m records, and 23 gigabytes-worth of data including admin panels, dashboards, fingerprint data, facial recognition data, face photos of users, unencrypted usernames and passwords, logs of facility access, security levels and clearance, and personal details of staff."
According to vpnMentor, the exposed data was discovered on Aug. 5, 2019. Two days later, they notified Biostar 2 of the issue and by Aug. 13, the database was private. It's not known how long all of that information was accessible and if anyone, particularly bad actors, had gained access to the database.
What's more, vpnMentor reports that Biostar's office was "generally very uncooperative."
SEE ALSO: Amazon claims its Rekognition software can now detect fearAmong the U.S.-based businesses the researchers were able to access data for: co-working space Union and medical supply company Phoenix Medical. But The Guardian notes that organizations that are part of AEOS include "governments, banks and the UK Metropolitan police."
We've reached out to Suprema for additional comment but, for now, you can continue to rest, uh, uneasily knowing that your data will never be fully secure.
Copyright © 2023 Powered by
Major security flaw exposes fingerprints of more than 1 million people-如火燎原网
sitemap
文章
879
浏览
7
获赞
29
The 'Creeper Challenge' has group chats fighting to finish song lyrics in the right order
There's nothing quite like trying to coordinate your group chat to complete any one, singular task.Best Black Friday TV deals at Amazon: A few cheap Fire TVs on sale
UPDATE: Nov. 26, 2024, 5:00 a.m. EST Amazon's Black Friday sale officially started on Thursday, Nov.Best Black Friday Sticker Printer deal: Save 43% at Amazon
SAVE 43%: As of Nov. 27, the Nelko Sticker Printer is available for $33.99 at Amazon, down from $59.Best iPad deals ahead of Black Friday 2024: iPad mini, Air, and Pro deals
UPDATE: Nov. 28, 2024, 3:00 a.m. EST This post has been updated with the best iPad deals available aThis is what it's like when a covert image of you goes viral online
When Rad Konieczny first saw a screenshot of the video, he felt physically sick.A friend of a friendBlack Friday Sonos deals: Era 300, Ace, Beam at record lows
The best Sonos Black Friday deals at a glance: BEST SPEAKER DEALBest Amazon Black Friday deals: Early savings on Kindles, air fryers, and robot vacuums
UPDATE: Nov. 27, 2024, 5:40 p.m. EST Amazon's Black Friday sale officially started on Thursday, Nov.Walmart Black Friday 2024: Ad and best deals
Walmart's second Black Friday Deals event started on Nov. 25, and its savings-packed ad includes somWatch Mariah Carey's incredibly, perfectly extra bottle cap challenge
Mariah Carey doesn't do anything without flair, and her attempt at the viral bottle cap challenge isBest Black Friday Sticker Printer deal: Save 43% at Amazon
SAVE 43%: As of Nov. 27, the Nelko Sticker Printer is available for $33.99 at Amazon, down from $59.Best Black Friday smartwatch deal: Get 52% off Samsung Galaxy Watch 6
SAVE $170:As of Nov. 27, the 44mm Samsung Galaxy Watch 6 is on sale for $159.99 in Amazon's Black FrBest Black Friday Vacuum Deal: 30% off Gtech AirRam 3 Cordless Vacuum
SAVE OVER $100:As of Nov. 25, the Gtech AirRam 3 Cordless Vacuum is on sale for $323.28 at Amazon. THere's what happened with Beyoncé at the NBA Finals
The Raptors beat the Warriors in Game 3 of the NBA Finals Wednesday night. More importantly, Beyonc&Apple iPad Mini Black Friday deal: $399.99 at Amazon
SAVE $99.01: As of Nov. 26, the Apple iPad Mini (A17 Pro) is just $399.99 at Amazon, $99.01 off theShop deals on unlocked phones ahead of Black Friday
SAVE UP TO 50%:Unlocked phones from Samsung, Apple, and other top brands are heavily discounted ahea