meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, January 2nd 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 2 January 2019

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Vein Scanner Bypass; Lightbulb Bots; EU Open Source Bug Bounty

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, January 2nd, 2019 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich.

0:09.8

And I'm recording from Jacksonville, Florida.

0:13.9

One of the events of note each year around New Year is the Chaos Communication Congress that happens in Germany and this year

0:23.5

again it doesn't disappoint. I just want to highlight a couple of talks from this conference

0:30.6

and as usual the conference website itself has videos and such of many of the talks.

0:38.6

First, there was one talk that looked at vein identification.

0:43.7

Now, this is less commonly used biometrics where you're using the entire hand to identify

0:51.3

yourself.

0:52.3

It doesn't use fingerprints, but instead it uses the patterns

0:57.0

of the veins in your hand in order to identify a particular user.

1:03.0

Now, in order to fool one of these biometric systems, there are really two components that

1:08.5

are needed. First of all, you do need a copy of the vein pattern of the target that you're trying to impersonate.

1:15.6

And then secondly, you have to find a way to duplicate that.

1:19.6

Now, in order to obtain the pattern, you need an infrared camera, a fairly cheap camera, does work.

1:27.8

They used one of those little pie cameras that you can connect to a Raspberry Pi and sort of

1:32.9

as a proof of concept they actually installed it in one of those hand-triers that you often

1:37.6

find in public restrooms and that gave them a reasonably good pictures of these main patterns in people's hands as they tried their hands.

1:48.0

Now, in order to then emulate the hand and the human tissue, what they actually came up with was to use yellow bees wax.

1:56.0

And that worked sufficiently enough to fool these hand scanners with about 80% reliability.

2:05.3

They did actually do a little demo sort of on stage.

2:09.1

They had some problems with the demo on stage.

2:11.7

But that was then based on the big lights they had shining in there, which interfered with the hand scanner.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.