Hi

I know biometrics are very experimental and hacked under linux but
maybe somebody did some mod like this.
What I need is to access my crypted hard disk by my fingerprint. It
uses standard luks encryption.

The problem is that currently it's only possible by creating a program
which if my fingerprint is accepted (compared with the one on the
disk),
sends a key to luks which is embedded in the program. In case the
binary compromised an attacker can reverse it and gain access
to my drive later.

But even if I go ahead with this hack and protect the embedded key
with AES or other algo (to make it impossible to figure out for
someone
who don't know how to reverse apps) the other issue is the integrity
of the picture file which is used for the comparison.

An attacker wouldn't even need to hack the program but enroll his own
fingerprint and replace my fingerprint's picture file and that's it.
_______________________________________________
fprint mailing list
[email protected]
http://lists.reactivated.net/mailman/listinfo/fprint

Reply via email to