Exposed passwordsKbad enough. But fingerprint and facial recognition data? That’s terrifying.
Suprema's Biostar 2 biometric security system came under scrutiny after vpnMentor and two researchers -- Noam Rotem and Ran Locar -- uncovered a major flaw that exposed the biometric data of more than 1 million people, according to The Guardian.
Biostar 2 is a security platform that, in part, utilizes facial recognition and fingerprints to control access to buildings and other secure facilities. Making the potential breach even worse: Biostar 2 was recently integrated into Nedap's AEOS security platform, which is used for security by thousands of companies and organizations in more than 80 countries.
The researchers said not only was the database unencrypted, but was accessed by tweaking URL search criteria in Elasticsearch, a search and analytics engine. And it contained a lot of data.
The Guardianreported that the researchers "had access to over 27.8m records, and 23 gigabytes-worth of data including admin panels, dashboards, fingerprint data, facial recognition data, face photos of users, unencrypted usernames and passwords, logs of facility access, security levels and clearance, and personal details of staff."
According to vpnMentor, the exposed data was discovered on Aug. 5, 2019. Two days later, they notified Biostar 2 of the issue and by Aug. 13, the database was private. It's not known how long all of that information was accessible and if anyone, particularly bad actors, had gained access to the database.
What's more, vpnMentor reports that Biostar's office was "generally very uncooperative."
SEE ALSO: Amazon claims its Rekognition software can now detect fearAmong the U.S.-based businesses the researchers were able to access data for: co-working space Union and medical supply company Phoenix Medical. But The Guardian notes that organizations that are part of AEOS include "governments, banks and the UK Metropolitan police."
We've reached out to Suprema for additional comment but, for now, you can continue to rest, uh, uneasily knowing that your data will never be fully secure.
Topics Cybersecurity Facial Recognition
(Editor: {typename type="name"/})
The State of 5G: When It's Coming, How Fast It Will Be & The Sci
People stood in line outside 'world's best' ramen restaurant for 10 days
Pepe the Frog cartoonist is trying to it back from the alt
The latest '4:44' teaser is called 'Kill Jay Z' and it's a doozy
Reality Distortion Field: 10 Things Apple Won't Directly Say But We'll Infer About the iPhone X
You can now make your own Snapchat filters without leaving the app
Pikachu chases down Team Rocket in a thrilling parkour sequence
Travelers into the U.S. just dodged an expanded electronics ban — for now
Norrie vs. Diallo 2025 livestream: Watch Madrid Open for free
Pepe the Frog cartoonist is trying to it back from the alt
Best travel deal: Score the Frontier Go Wild! summer pass for just $399
'Broad City' star Abbi Jacobson's new podcast will make you feel less dumb about art
接受PR>=1、BR>=1,流量相当,内容相关类链接。