Are you using an HTC device? Researchers at security firm FireEye have discovered a way to steal fingerprints from Android devices that have biometric sensors, such as the Samsung Galaxy S5 and HTC One Max.
But the team was in for a big surprise when they discovered that the fingerprints stored on the HTC One Max exist as image files (dbgraw.bmp) in a folder open to the world, and without any encryption.
“Any unprivileged processes or applications can intercept the user's fingerprints by reading this file,” the team says, adding that the images can be easily printed.
Yulong Zhang, Zhaofeng Chen, Hui Xue, and Tao Wei presented their research Fingerprints On Mobile Devices: Abusing and Leaking [PDF] at the Black Hat conference held in Las Vegas last week.
Most device manufacturers, the researchers report, are unable to use Android Trust Zone protection to protect biometric data.
“To make matters worse, every time the fingerprint sensor is used for an auth operation, the auth framework refreshes the fingerprint bitmap,” the team says.
“So the attacker can sit in the background and collect all the victim’s fingerprint images.”
The team also added that attackers with some remote code execution could collect these fingerprints en masse, since they don't even need root privileges.
