Biometric database with 27.8 million entries unsecured on the net
Summary
In 2019 researchers from vpnMentor found the “Biostar 2” biometric database of the manufacturer Suprema largely unprotected on the net. Using a normal browser, they reached 27.8 million entries totalling 23 gigabytes, including unencrypted user names and passwords, more than a million fingerprints and facial images. The system controlled access control, including via Nedap’s AEOS platform at more than 5,700 organisations in 83 countries.
Ideas
- Simple port scans were enough to find the open database.
- Manipulated search parameters in the URL released the data.
- With admin access, attackers could have locked people out of buildings or tracked entries.
- Unlike passwords, biometric features cannot be changed.
Insights
- A biometric data leak is permanent, because fingerprints cannot be replaced.
- Physical security systems inherit the weaknesses of their cloud platform.
Facts
- The data comprised 27.8 million entries totalling 23 gigabytes.
- In Germany, the supplier Identbase is said to have been affected.
- Suprema stored complete biometric data instead of irreversible hash values.
- After being reported on 7 August, the hole was closed on 13 August 2019.
References
Critique
- The report is based mainly on information from the finders, who also market a VPN service.
Recommendations
- Store biometric data, if at all, only as irreversible features and locally.
- With cloud access control systems, check where the data is stored and how access is protected.
Links to the original source and the Web Archive open in a new tab.