read.cash Log in
@Unity more from that month

Biometrics in Banking and Cryptocurrency Payments is a Problem

After working for more than a decade on hands-on research projects in biometrics recognition technology, I decided to quit because biometrics recognition is inherently probabilistic and can NOT yield deterministic 'yes/no' results in authentication like text passwords and PINs. Moreover, biometrics spoofing technology has progressed at an alarming pace. There are so many other problems with biometrics recognition! Many inconvenient questions about biometrics remain unanswered! Is the security-lowering biometrics recognition fit to be used for KYC? Why are biometrics companies hiding the security-lowering traits in public statements? Maybe they invested too much money, so they can't come back and discard the business just because the technology is faulty! Why the mainstream news media are not making the facts public? Maybe, they got money from the biometrics companies, including the big tech corporations that promote biometrics because they have stakes in the biometrics business! Why have most governments in the world adopted biometrics despite biometrics being a security-lowering authentication system? Maybe, they are allies to the big tech corporations promoting biometrics! Why the banks and some cryptocurrency payment systems adopted biometrics as a parallel authentication factor? Because they know biometrics can create problems, and thus passwords/PINs remained the default authentication system! There is no doubt that biometrics recognition in banking and cryptocurrency payments may create catastrophic problems! Aadhaar is a broken digital identity project in India that uses biometrics! Adopting biometrics as an authentication factor made Aadhaar a pain for Indian citizens! They lose money almost every day from their bank accounts! Daily, poor citizens lose money from their bank accounts by fraudulent Aadhaar Enabled Payment System (AEPS) transactions authenticated by fingerprint spoofs! We may call it Aadhaar-enabled biometrics theft and biometrics spoof based banking fraud. https://www.youtube.com/watch?v=gNcDcCWJIcE Unfortunately, Aadhaar has been causing plenty of harm to Indian citizens, such as fraudulent banking transactions and money withdrawals through Aadhaar-enabled Payment System (AePS), biometrics theft, and fingerprint spoofs. Citizens suffer frequent errors in Aadhaar's biometric authentication system due to high false rejections and false acceptances. Biometrics is a security hole in every authentication system that adopted it. Biometrics makes the Worldcoin crypto project inherently security vulnerable. Biometrics is inherently probabilistic and hence unreliable and lowers the security of authentication of humans. https://www.linkedin.com/pulse/biometrics-fallacy-can-lower-security-debesh-choudhury-phd/ https://www.linkedin.com/pulse/biometrics-authentication-reliable-because-debesh-choudhury-ph-d-/ As a result, biometrics technology makes the Worldcoin crypto project inherently security vulnerable. In my humble fifteen-plus years of hands-on research investigations in different biometrics modalities, I consider the biometrics crypto project Worldcoin a big mistake. https://www.linkedin.com/pulse/biometrics-fallacy-can-lower-security-debesh-choudhury-phd/ **If the biometric data are stolen or hacked?** The biometric database may be leaked or stolen, as in the case of the Aadhaar project in India. Then, the biometric signatures in that database are in the hands of the criminals. They can make use of that data. They can try to create duplicate biometric objects for use. https://www.linkedin.com/pulse/privacy-protection-could-have-saved-aadhaar-data-choudhury-ph-d-/ **Duplicate fingerprints created on thumb like objects can be used to fake as real thumb** https://www.wikihow.com/Fake-Fingerprints https://www.youtube.com/watch?v=If4-pJ4sfIQ The high-resolution pictures of fingerprints can be utilized to synthesize artificial thumb-like objects made up of rubber with exact copies of the 3D fingerprints. Not only that, the rubber thumbs can also be equipped with an electronic vibrator that can pass the liveness sensor of the fingerprint sensors. Thumb cloning is such an easy task that students in an Indian academic institute reported using cloned thumbs to cheat the fingerprint recognition system for recording class attendance. http://www.freepressjournal.in/mumbai/mumbai-pupils-cheat-biometric-attendance-system-at-ict/1055462 Face images may easily be grabbed/stolen from social media Face images are abundantly available on social media. So, criminals don't need any special tricks to hack face images. Face images may also be captured remotely from public places. Even a 3D face shape may also be sensed and reconstructed from suitably captured multiple face images. The stolen face images and 3D printed face masks may be used to beat the face recognition systems. Reports show that it is indeed possible to break the face recognition tests. Security researchers used 3D face masks to crack the 3D face ID of the iPhone X. https://www.linkedin.com/pulse/3d-face-id-cracked-hackers-debesh-choudhury-ph-d-/ https://www.youtube.com/watch?v=i4YQRLQVixM **Iris images may be extracted from HD images of faces for spoofing** https://www.biometricupdate.com/201503/spoofing-iris-recognition-technology-with-pictures It has been shown by a security researcher that high-resolution prints of face images can give an optimum resolution of iris images sufficient for spoofing iris recognition systems.  https://www.biometricupdate.com/201503/spoofing-iris-recognition-technology-with-pictures Samsung Galaxy S8 iris scanner has been defeated by a group of German hackers. Here, an artificial eye is created using a print of the eye and a contact lens, which is used to match the curvature of the eye. So, the iris recognition system may easily be fooled by faking iris images. https://www.theguardian.com/technology/2017/may/23/samsung-galaxy-s8-iris-scanner-german-hackers-biometric-security Are the behavioral biometric traits safe and secure? Behavioral biometrics, such as voice and speaker recognition systems, may appear safe.  However, research reports say that mimicry attacks may act as threats to voice and speaker recognition. http://ieeexplore.ieee.org/document/4492601/ HSBC Bank tried voice recognition as security in 2016, which failed miserably. Behavioral biometrics, such as voice and speaker recognition systems, may appear as safe. However, research reports say that mimicry attacks may act as threats to voice and speech recognition. In 2017, **according to a news report by BBC, HSBC’s voice ID authentication software, designed to prevent bank fraud, was broken by BBC Click reporter Dan Simmons and his non-identical twin**. https://www.bbc.com/news/technology-39965545

A screenshot from a news Source: BBC https://www.bbc.com/news/technology-39965545 You can view the video clip of how one of the twin-brother couples logged in to his brother's HSBC bank account, accessed funds, and executed a financial transaction. The voice of one brother broke open another brother's account by mimicking his brother's voice. Any expert voice mimicry artist probably can do it for several account holders! The future of digital identity is not as simple as the industry projects https://www.linkedin.com/pulse/digital-identity-assets-governance-debesh-choudhury-ph-d-/ A section of the FinTech industry is aggressively speaking for a "biometrics-only" system. Several use cases are being researched and tested with biometrics as passwords. Some results are positive because biometric technology is improving. But the biometrics spoofing technology is also improving at an alarming rate. https://www.linkedin.com/pulse/spoofing-biometrics-isnt-impossible-debesh-choudhury-ph-d-/ Newer and more innovative spoofing systems can break almost every type of biometrics, including iris scans, 3D face ID, or palm vein patterns. The only remaining technology is brain wave-based biometrics. However, brain wave sensing technology has not matured enough for reliable human identification and authentication. But, biometrics recognition is probabilistic, and can't yield deterministic "yes/no" results like text passwords. <> Initially posted on my Publish0x blog. https://www.publish0x.com/techfuture/biometrics-in-banking-and-cryptocurrency-payments-is-a-probl-xzqozrw ------------ About me I am a researcher and contribute to the overlapping areas of STEAM (Science, Technology, Engineering, Arts, and Mathematics). I am an active user and promoter of GNU/Linux, free and open-source software. I develop cybersecurity and information security solutions, specifically graphical authentication security.   ***Cheers!*** ***Debesh Choudhury*** https://twitter.com/debeshchoudhury/ *Text Copyright © 2025 Debesh Choudhury — All Rights Reserved* ***Join me at*** ***YouTube******,*** ***Twitch******,*** ***CashRain******,*** ***Odysee******,*** ***LinkedIn******,*** ***Twitter******,*** ***Publish0x******,*** ***ReadCash******, and*** ***Facebook******.*** https://www.youtube.com/@learningtimes https://www.twitch.tv/debeshchoudhury https://cashrain.com/LearningTimes https://odysee.com/$/invite/@debesh.choudhury:d https://www.linkedin.com/in/debeshchoudhury/ https://twitter.com/debeshchoudhury https://www.publish0x.com/@Debesh-Choudhury https://read.cash/@Unity https://www.facebook.com/debesh.choudhury/ *Earn passive income by sharing unused Internet bandwidth with* *Grass* *and* *Honeygain**.* https://app.getgrass.io/register/?referralCode=hejKsDZzzaNjRrT https://r.honeygain.me/CONSUC95E1 ***Cover Image:*** *I created a cover using my texts and a copyright-free image from Pixabay..* *All other images are either drawn/created/screenshots by me or credited to the respective artists/sources.* ***Disclaimer****:* This is not financial or technological advice. Cryptocurrency investments are speculative and volatile. Always consult a financial advisor and assess your risk tolerance before investing. *All texts are mine and original. Any similarity and resemblance to any other content is purely accidental. The article is not advice for life, career, business, or investment. Please do your research before you adopt any options.* ***Unite and Empower Humanity.*** #biometrics #cryptocurrency #banking #security #spoof #authentication #digitalidentity #learningtimes Wednesday, July 16, 2025

No comments yet

Log in to join in Reading is open to everyone. Replying needs an account.