Skip to main content

HTC left unsecured fingerprint data on the One Max

HTC-One-Max-back-camera-macro
Image used with permission by copyright holder
The HTC One Max was one of the first modern Android smartphones to feature a fingerprint sensor, but it appears HTC didn’t take security of those fingerprints very seriously, and stored some data related to them unencrypted on the device. This means if it fell into the hands of a talented hacker, a copy of your fingerprint could be easily created.

Evidence was presented by a team of experts from security company FireEye Labs at the Black Hat conference in Las Vegas recently, where the authentication and authorization systems used for mobile phone fingerprint analysis were examined. The team wanted to highlight the need for strong security measures to keep fingerprint data safe, because unlike a traditional password, once a fingerprint has been stolen — it’s out there forever, and cannot be changed.

Recommended Videos

HTC was alerted to the flaw prior to the conference, and sent out an update to fix it before the findings were presented, so if you own a One Max and regularly use the fingerprint sensor — don’t worry, it’s secure now. FireFly Labs also identified other problems related to security issues with sensors, which affected phones other than the One Max — the Samsung Galaxy S5 is mentioned specifically — and these problems have also been patched by their respective manufacturers.

Please enable Javascript to view this content

Fingerprint sensors as a way to secure our mobile devices and authorize mobile payments are becoming more common, particularly as new systems such as Samsung Pay and Android Pay emerge. FireFly Labs says owners can help protect themselves by choosing smartphones with up-to-date software, and apply new updates when they arrive, plus to use apps from reliable, known sources. It also urges manufacturers to improve security around sensors and the data collected.

The news comes shortly after Android was affected by the Stagefright bug, which threatened to disable smartphones with a simple message. The seriousness of the alert prompted companies to not only rapidly send out a software fix, but also to promise regular security updates for devices in the future.

Andy Boxall
Andy is a Senior Writer at Digital Trends, where he concentrates on mobile technology, a subject he has written about for…
I tracked my sleep with a smart display, ring, and watch. This is my favorite
The Oura Ring app on an iPhone 16 Pro Max, showing the Sleep screen.

Since I had a heart attack four years ago, I’ve been on a journey to understand my health. A crucial part of my recovery and focus has been my sleep, and it'smade even more important by the fact that my heart attack took place in the middle of the night while I was fast asleep. Thankfully, I woke up, but our sleep can tell us a lot about our underlying health.

Virtually every wearable now offers some form of sleep tracking, but like most things in technology, not all devices are created equal. Beyond just data, there’s also the question of which is most comfortable to track your sleep, which device gives you the most reliable data, and ultimately, how you can ensure you track your sleep wherever you are.

Read more
How to transfer your books from Goodreads to StoryGraph
Front page of a book on Onyx BOOX Go 10.3 tablet.

Goodreads has been the only game in town for Android and iOS book-tracking for a long time now, and like most monopolies, it has grown old and fat. Acquired by Amazon in 2013, avid book readers have had lots to complain about in recent years, with the service languishing unloved, with no serious updates and an aging interface. It's been due some serious competition for a long time, and lo and behold, some has arrived. StoryGraph is a book-tracking app that offers everything you'll find on Goodreads but with an algorithm that lets you know about what you might love, and adds features any bibliophile will know are essential — like a Did Not Finish list.

Read more
The next iOS 18 update is on its way. Here’s what we know
The iPhone 16 sitting on top of orange mums.

When iOS 18.2 released just over a week ago, it unlocked a lot of long-awaited features like Image Playground, Visual Intelligence, and improvements to writing tools. Now, it seems like another update could be just around the corner: version 18.2.1.

MacRumors found evidence of the update in their analytic logs, a source that has supposedly revealed quite a few iOS versions before release. Given that this is a minor update, it isn't likely to come with new features or anything groundbreaking. Instead, it will most likely be targeted at bug fixes, although no specific problems have been named. You should expect this update to drop either in late December or early January, but a year-end release is more likely.

Read more