Menu

IoT FEATURE NEWS

Hole in Android Biometric Security Found, and HYPR Fixed

By

The Black Hat conference in Las Vegas just wrapped, and the attendees as usual showed off dozens of huge and scary vulnerabilities in many systems (including several IoT connectivity platforms). One particularly terrifying hack revealed was that crackers could use Android phones to steal users’ fingerprints.

Luckily, in addition to showing off the vulnerability, the researchers also unveiled a repair.

HYPR Corp. identified the increasing availability of fingerprint scanners on mobile devices as a risk, and to secure these biometric markers on mobile devices, the company has released a biometric tokenization platform that will augment these systems with strong cryptographic security.

“Biometric authentication provides a much-needed solution to the problem of insecure passwords, but it is not a panacea. As we have seen, when executed poorly, biometric authentication can put sensitive data at risk,” said George Avetisov, CEO, HYPR. “That is why enterprises must ensure they have implemented a robust, multifaceted security solution that ensures biometric signatures and user data is stored safely and isn't transmitted across the Internet. This is where biometric tokenization comes into play.”

Image via Shutterstock

Security concerns identified by HYPR, and findings from the research revealed at Black Hat, include: that by 2019, more than half of all smartphones will include a fingerprint sensor; most device manufacturers fail to use available protection to safeguard biometric data in the Android OS; hackers have found a means to steal fingerprint data thanks to fingerprints being stored as an image file in an open, readable, folder.

To address these problems, HYPR advised that users leverage biometric tokenization to enable the safe transmission of a fingerprint image or template to the cloud using trusted public key cryptography; fingerprints should be stored as a mathematical representation in a trusted environment separate from the device OS; and secure processors should be deployed that are designed for the storage of sensitive data.

Register now for the IoT Evolution Expo to learn more about how to secure data in the IoT. It will be next week, August 17 to 20 at Caesars Palace in Las Vegas. 




Edited by Dominick Sorrentino
Get stories like this delivered straight to your inbox. [Free eNews Subscription]

Editorial Director

SHARE THIS ARTICLE
Related Articles

The Digital Supply Chain: Resilience, Visibility, and the End of Flying Blind

By: Carl Ford    5/26/2026

Digital supply chain transformation is helping enterprises replace fragile, efficiency-only models with resilient, real-time operations powered by end…

Read More

The CIO Reimagined: From IT Keeper to Digital Business Leader

By: Carl Ford    5/26/2026

The modern CIO is evolving from an IT operations leader into a strategic digital business executive, responsible for driving AI governance, cloud stra…

Read More

Industrial IoT and the Rise of Smart Level Monitoring

By: Contributing Writer    5/18/2026

Industrial operations are becoming increasingly data-driven. From manufacturing plants and oil terminals to water treatment facilities and agricultura…

Read More

How Does Anthropic's Mythos Foretell the Post Quantum Nightmare?

By: Carl Ford    5/14/2026

AI security tools like Anthropic's Mythos are exposing hundreds of exploitable flaws in legacy software stacks, underscoring the urgent need for bette…

Read More

Why Industry Recognition Makes a Difference in the IoT Market Now More Than Ever

By: TMCnet Staff    5/11/2026

In today's crowded IoT market, industry awards and third-party recognition help vendors boost credibility, improve shortlist placement, strengthen sal…

Read More