The iris-recognition feature in Samsung’s new Galaxy S8 smartphone has been defeated by German hackers, less than a month after the device hit shelves around the world.
p
A video posted by the Chaos Computer Club, a long-running hacker collective formed in Berlin in 1981, shows the security feature being fooled by a dummy eye into thinking that it is being unlocked by a legitimate owner.
p
The artificial eye — which is made using just a printer and a contact lens to match the curvature of the eye — can be created using pictures of the owner’s eye taken from social media, the group said, though for highest quality fake irises, a digital photograph taken in night mode works best.
p
The security risk to the user from iris recognition is even bigger than with fingerprints, as we expose our irises a lot, said the group’s spokesperson, Dirk Engling. If you value the data on your phone — and possibly want to even use it for payment — using the traditional pin-protection is a safer approach than using body features for authentication.
p
The Galaxy S8 also ships with a facial recognition feature, which was defeated before the phone was even on sale : it can be tricked with something as simple as a printed-out picture of the owner. The ill-fated Note 7 also had the same infrared iris scanner as the Galaxy S8.
p
CCC is the same group that first fooled Apple’s TouchID fingerprint sensors, just weeks after the first iPhone 5s hit the market. That hack was carried out with graphite powder, a laser etching machine and wood glue, all to trick Apple’s systems for ensuring that a real finger was being used, but required physical access to something the target had touched (a year later, another hacker demonstrated a way to generate working fingerprints from…