I recently found this in the LTKA website. It's research that was done in 2002 by the Fraunhofer Research Institute in collaboration with the German Federal Institute for Information Technology Security.
It is a lengthy article but worth reading. It details a variety of easy ways to fool biometric scanners and the simple ways that the systems could be hacked - see www.heise.de/ct/english/02/11/114/
A quote near the end of the article reads:
"With the aid of data packets gathered by eavesdropping and some lines of Perl script we were able to reconstruct complete fingerprints"
Clarification on whether the systems fooled are the ones used in UK schools URGENTLY needs checking. Thankfully my children's fingerprints aren't on any systems - what a relief!
Covering privacy and civil liberties issues with the use of biometrics in schools
Showing posts sorted by relevance for query reconstruct. Sort by date Show all posts
Showing posts sorted by relevance for query reconstruct. Sort by date Show all posts
Friday, October 20, 2006
Tuesday, July 31, 2007
Reverse-engineering digital fingerprints
One important point, that has been reiterated time and time again by biometric vendors, Jim Knight and the ICO, is that the biometric systems in schools cannot reverse-engineer a fingerprint.
This does not seem to be the case according to Kim Cameron's recent weblog, Architect of Identity and Access in the Connected Systems Division at Microsoft, entitled "Paper argues biometric templates can be reversed". It shows that reverse-engineering a digital fingerprint may just be possible. He cites this paper "Can images be generated from biometric templates" by Andy Adler, University of Ottawa, 2003.
Also see these Research discussions at West Virginia University from 2005 "We show that minutiae information can reveal substantial details such as the orientation field and the class of the associated fingerprint that can potentially be used to reconstruct the original fingerprint image."
Both of these papers are not too recent and since then one would presume that the technologies in this field have advanced.
However, even thought the possible reconstruction of a fingerprint seems relevant to the argument of biometric technology in schools, ownership and possible 'loss' of ones digital fingerprint is still very relevant... who has access to it, the systems it is on, how it can be used (or abused). These are the points that should be seriously considered by children (and parents) as they unwittingly give up their biometric data for systems in schools which are non essential for purchasing food or accessing library books.
This does not seem to be the case according to Kim Cameron's recent weblog, Architect of Identity and Access in the Connected Systems Division at Microsoft, entitled "Paper argues biometric templates can be reversed". It shows that reverse-engineering a digital fingerprint may just be possible. He cites this paper "Can images be generated from biometric templates" by Andy Adler, University of Ottawa, 2003.
Also see these Research discussions at West Virginia University from 2005 "We show that minutiae information can reveal substantial details such as the orientation field and the class of the associated fingerprint that can potentially be used to reconstruct the original fingerprint image."
Both of these papers are not too recent and since then one would presume that the technologies in this field have advanced.
However, even thought the possible reconstruction of a fingerprint seems relevant to the argument of biometric technology in schools, ownership and possible 'loss' of ones digital fingerprint is still very relevant... who has access to it, the systems it is on, how it can be used (or abused). These are the points that should be seriously considered by children (and parents) as they unwittingly give up their biometric data for systems in schools which are non essential for purchasing food or accessing library books.
Tuesday, April 24, 2007
Consent and Security
Futurelab published a well written article (Now archived here) in December last year, in their bi-annual magazine 'Vision', about surveillance in schools concentrating mainly on biometric systems. It clearly defines the two issues that concern parents and security experts:
First, the taking and storage of the biometric data itself. Second, the lack of consultation beforehand. The second of these issues is as contentious as the first, even though the DfES said in September 2006 that, in its view, schools do not need to ask permission.
The fingerprint module in Junior Librarian, for example, is bought in from a third-party company that supplies its technology to a range of other vendors for many other uses. Isn't it possible that today's database of children's fingerprints, sometime in the future, could unlock some completely different application and set of data?
This from Terence Boult on Bruce Schneier's blog from 2005.
"This obscure phrasing ["The data cannot be used to reconstruct the fingerprint"] is common among biometric vendors... to make people feel its more private and/or safer. Minutiae-based templates can be easily reused by the government, and there is an official interchange standard (M1) to help ensure systems can share and inter-operate... to ensure one company's templates work well in other peoples' matching."
One would presume that this side of biometric technology has matured even since then.
On issues of security, with no awareness at any level of how many regular schools computers currently store children's biometric data - how then do we know when their data gets stolen or compromised? For certain when schools get broken into it's not pens and paper that get stolen.
The issue of children's consent remains a contentious issue, especially when they are in a compliant environment. Systems in schools should be on an "opt in" basis, this would force a school to explain the technology thoroughly to parents and also give both parents and pupils time for research themselves. Without informed consent we stand a very real risk of teaching the next generation to be casual with their personal biometric data.
Futurelab, who received major start-up funding from the Department for Education and Skills, DfES, has this last comment on the subject:
Maybe the time has come for a debate on this issue so that we can all fully understand both the positive and negative aspects of using surveillance technology in schools - and then, at least, we can all make an informed choice as to whether or not to sign up.
First, the taking and storage of the biometric data itself. Second, the lack of consultation beforehand. The second of these issues is as contentious as the first, even though the DfES said in September 2006 that, in its view, schools do not need to ask permission.
The fingerprint module in Junior Librarian, for example, is bought in from a third-party company that supplies its technology to a range of other vendors for many other uses. Isn't it possible that today's database of children's fingerprints, sometime in the future, could unlock some completely different application and set of data?
This from Terence Boult on Bruce Schneier's blog from 2005.
"This obscure phrasing ["The data cannot be used to reconstruct the fingerprint"] is common among biometric vendors... to make people feel its more private and/or safer. Minutiae-based templates can be easily reused by the government, and there is an official interchange standard (M1) to help ensure systems can share and inter-operate... to ensure one company's templates work well in other peoples' matching."
One would presume that this side of biometric technology has matured even since then.
On issues of security, with no awareness at any level of how many regular schools computers currently store children's biometric data - how then do we know when their data gets stolen or compromised? For certain when schools get broken into it's not pens and paper that get stolen.
The issue of children's consent remains a contentious issue, especially when they are in a compliant environment. Systems in schools should be on an "opt in" basis, this would force a school to explain the technology thoroughly to parents and also give both parents and pupils time for research themselves. Without informed consent we stand a very real risk of teaching the next generation to be casual with their personal biometric data.
Futurelab, who received major start-up funding from the Department for Education and Skills, DfES, has this last comment on the subject:
Maybe the time has come for a debate on this issue so that we can all fully understand both the positive and negative aspects of using surveillance technology in schools - and then, at least, we can all make an informed choice as to whether or not to sign up.
Subscribe to:
Posts (Atom)