Skip to main content

No vein, no gain: Wax hand beats the latest vein-recognition systems

Image used with permission by copyright holder

We’re bored by voice identification, fatigued by Face ID, and totally over fingerprint-reading technology. Here in the closing days of 2018, it’s all about unusual new biometric technologies like “vein authentication.” As its name suggests, this technology involves reading the unique pattern of veins on a person’s palm to confirm that they are who they say they are. Such technology is reportedly being increasingly used in high-security facilities around the world.

Only it might not turn out to be quite as secure as people think — at least if a recent demonstration at the hacker-centric Chaos Communication Congress is to be believed.

Recommended Videos

This week, a small team of security researchers showcased how the latest vein-reading security systems are no match for something as basic as a fake wax hand containing printed vein details.

Please enable Javascript to view this content

“We showed how to use a modified DLSR [camera] to capture hand vein patterns from a distance of around 5 meters,” security researcher Jan Krissler, aka Starbug, told Digital Trends. “After adjusting the contrast, we then printed the vein patterns with a standard laser printer and covered the print with a layer of bee wax to simulate human tissue. With those dummies, we were able to fool the latest systems of both major vendors of vein recognition systems, Fujitsu and Hitachi.”

As exploits go, it’s pretty ingenious — but also alarmingly straightforward. It’s not quite as easy as fooling a facial-recognition system by holding up a photograph of the person, but it’s not too far off. (Although actually getting a good photo of someone’s hand with their veins visible might be a little tough.) According to Krissler, until now the accepted wisdom was that veins are buried inside the body and were thought to be difficult to capture. Just as facial recognition has had to improve, however, it seems that vein authentication must also ramp up its efforts.

“There are ways to measure blood flow that would detect our dummy,” Krissler continued. Even then he thinks that there would be ways to fool the technology, though. It appears that there is more that needs to be done before we can rely on reading veins as a foolproof security system.

Hey, maybe one of these other oddball biometric technologies will have better luck.

Luke Dormehl
Former Digital Trends Contributor
I'm a UK-based tech writer covering Cool Tech at Digital Trends. I've also written for Fast Company, Wired, the Guardian…
Rivian tops owner satisfaction survey, ahead of BMW and Tesla
The front three-quarter view of a 2022 Rivian against a rocky backdrop.

Can the same vehicle brand sit both at the bottom of owner ratings in terms of reliability and at the top in terms of overall owner satisfaction? When that brand is Rivian, the answer is a resonant yes.

Rivian ranked number one in satisfaction for the second year in a row, with owners especially giving their R1S and R1T electric vehicle (EV) high marks in terms of comfort, speed, drivability, and ease of use, according to the latest Consumer Reports (CR) owner satisfaction survey.

Read more
Hybrid vehicle sales reach U.S. record, but EV sales drop in third quarter
Tesla Cybertruck

The share of electric and hybrid vehicle sales continued to grow in the U.S. in the third quarter, the Energy Information Administration (EIA) reported this month.

Taken together, sales of purely electric vehicles (EVs), hybrids, and plug-in hybrids (PHEVs) represented 19.6% of total light-duty vehicle (LDV) sales last quarter, up from 19.1% in the second quarter.

Read more
Tesla’s ‘Model Q’ to arrive in 2025 at a price under $30K, Deutsche Bank says
teslas model q to arrive in 2025 at a price under 30k deutsche bank says y range desktop lhd v2

Only a short month and half ago, Tesla CEO Elon Musk told investors that outside of the just-released driverless robotaxi, a regular Tesla model priced at $25,000 would be “pointless” and “silly”.

"It would be completely at odds with what we believe,” Musk said.

Read more