Thales launches payment card with onboard fingerprint scanner
- Reference: 1626942611
- News link: https://www.theregister.co.uk/2021/07/22/thales_fingerprint_payment/
- Source link:
The Thales Gemalto Biometric Sensor Payment card (BSPC), the company explained, replaces the traditional PIN with an on-card fingerprint sensor and requires no modifications to existing point-of-sale (POS) payment terminals. Banks signing up to use it, though, will need to implement a procedure for enrolling users' fingerprints onto the card's secure element.
Thales claimed to have implemented the card with banks worldwide, boasting of 30 months of live trials and 10,000 users across nine countries including the UK. "Over 80 per cent of users interviewed confirmed they love it and feel it's more convenient and provides greater security," Frédéric Martinez, product line manager for biometric and advanced payment at Thales, told The Register .
[1]
"In terms of security, the biometric card ultimately means that a lost or stolen card is useless without the owner's fingerprint to authenticate a contactless transaction. In such trustworthy payment environments, there is no need to set any payment limit.
[2]
[3]
"What's more, whenever the cardholder's fingerprint can't be used – such as for ATM cash withdrawals – use of a PIN code is still possible as a fallback solution."
[4]Mastercard launches card that replaces PIN with fingerprint sensor
[5]German minister fingered as hacker 'steals' her thumbprint from a PHOTO
[6]Teen turned away from roller rink after AI wrongly identifies her as banned troublemaker
[7]McDonald's AI drive-thru bot accused of breaking biometrics privacy law
It's not just about convenience, though. Thales claims the system offers vastly enhanced security over the traditional PIN. "The probability of another user being recognised as the genuine user by the Thales Gemalto BSPC is less than the chance of another user guessing the card's PIN code," Martinez pointed out. "Fingerprint verification on the card has a False Acceptance Rate (FAR) of <1/10,000."
There are concerns over using fingerprints as an authentication system. For starters, if the biometric data is leaked you can't change your fingerprints as easily as a PIN or password. Criminals have also demonstrated how they can produce a replica fingerprint good enough to fool commercial sensors from a [8]photo of someone waving – creating a mould which can be used in place of the target digit.
Martinez is unconcerned. "The biometric system on the card includes anti-spoofing features," he told us, "making any mould based on a photograph of the fingerprint (even high resolution) not able to fool the system.
[9]
"When registering the customer's fingerprint, the reference data of their fingerprint is only stored in the secure chip of the card. This does not include any biometric data per se, but is a mathematical conversion of single points that represent your fingerprint reference data. In addition, no personal data is stored in the services of the financial institution or sent to any other centralised database. Even if the card is lost or stolen, the data cannot be recovered by a third party."
Thales's biometric cards aren't the first, despite the company's claims to the contrary: Mastercard launched one of its own [10]back in 2017 , though its plan to follow trials with a commercial launch by the end of that year came to naught.
Martinez told us that Thales had implemented the card "with banks worldwide, including in Cyprus, the Middle East, France, Italy, Switzerland, and the UK," but there's no word yet on when eager punters can start paying with a poke. ®
Get our [11]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YPlBuM9mmZno6zTXpOBttgAAABg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YPlBuM9mmZno6zTXpOBttgAAABg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YPlBuM9mmZno6zTXpOBttgAAABg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.theregister.com/2017/04/20/mastercard_launches_fingerprint_sensor_to_replace_pins_with_cards/
[5] https://www.theregister.com/2014/12/29/german_minister_fingered_as_hackers_steal_her_thumbprint_from_a_photo/
[6] https://www.theregister.com/2021/07/16/facial_recognition_failure/
[7] https://www.theregister.com/2021/06/10/mcdonalds_ai_lawsuit/
[8] https://www.theregister.com/2014/12/29/german_minister_fingered_as_hackers_steal_her_thumbprint_from_a_photo/
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YPlBuM9mmZno6zTXpOBttgAAABg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2017/04/20/mastercard_launches_fingerprint_sensor_to_replace_pins_with_cards/
[11] https://whitepapers.theregister.com/
Your first point is addressed by RTFA.
Your second point is valid but despite google/apple pay systems basically doing the same thing, I haven't heard of a spate of phone+finger thefts
"Police described the attacker as wearing a balaclava and holding a bloody paper bag"
Can you fit a Touch-ID sensor into the thickness of a credit card? Can the power requirements of a Touch-ID sensor be met by the wireless power transmitted by a card reader?
Yes, I had a biometric Mastercard 2 years ago. The print is only stored on the card, not centrally. And is powered from the card reader, both when inserted and when used for Contactless. The contactless limit when authorised by print was £100 and unlimited when inserted into the Chip & Pin Device. The look on a lot of staff when I didnt need to enter a PIN was fantastic, as was going over the £30 limit back then for contactless without having to insert the card. The only issue was petrol pumps which have to be inserted so far that you couldn't keep your finger on the card. The easiest print to use was the thumb, as it naturally sits over the print reader when holding the card, numbers up. The card was normal thickness. Overall a fantastic item and would have one again if possible. Lastly, when you receive the card, you had it supplied with a local power supply - battery which supplied power to the chip and register your print... in a similar way to adding your print to a phone... touching your print off and on. Then it was good to go!
My credit cards have my dabs all over them
Whilst I know nothing about this technology, it does occur to me that a stolen card is likely to have the fingerprints of the real owner physically all over it. Unless the owner was the sort of person who always wears latex gloves. This is in contrast to a PIN, which is not usually written on the surface of the card.
Consequently, there a new cottage industry may arise of picking physical fingerprints off of stolen cards and encoding them in a way that fools the card into believing that they are attached to a real person. Fingerprints are certainly [1]portable , although I am sure some more sophisticated technology would be needed to make them fool the card. However, this doesn't have to be done by the thief themselves, but a specialist in "processing" stolen credit cards.
[1] https://sciencing.com/transfer-fingerprints-8351332.html
Re: My credit cards have my dabs all over them
A card that only needs the pawprints that are already on it sounds like a bit of a dodgy idea, then!
"There are concerns over using fingerprints as an authentication system"
So there should be.
A non-rescindable and unalterable token can only ever legitimately be an identifier - never an authenticator . A fingerprint has both these attributes.
This is such an established principle that it amazes me the banks haven't yet caught on to it.
Apart from which, if, as is suggested, the system can "fall back" to a PIN, the entire supposed improvement in security is nullified, just as fallback to magnetic strip nullifies PIN.
My conclusion is that this is a combination of "security theatre" and revenue stream generation. Indeed security theatre can generate billions in revenue - just look at the support provision for the US TSA.
Re: "There are concerns over using fingerprints as an authentication system"
A non-rescindable and unalterable token can only ever legitimately be an identifier - never an authenticator. A fingerprint has both these attributes.
Totally agree.
I'm still buying shares in Haribo though, their Gummi Bears are very appealing! (I'll give a fair share to Herr Riegel of course!)
Re: "There are concerns over using fingerprints as an authentication system"
Let’s get real, this isn’t to get you into the bowels of the NSA or MI6, we’re really talking convenience and reduced crime & fraud.
Your card has a pin 1 in 10000 of a correct guess, that’s the “gold” standard here. Only that’s not the really what you have to beat, since tap & pay requires nothing more than possession of the card.
I’m already on board, I hardly ever tap, I much prefer fingerprint + tap via my phone.
1. "In such trustworthy payment environments, there is no need to set any payment limit."
2. "...if the biometric data is leaked you can't change your fingerprints as easily as a PIN or password."
3. "Even if the card is lost or stolen, the data cannot be recovered by a third party."
1. Madness. Will the card issuers guarantee 100% refunds on fraudulent transactions? With the onus on them to prove the transaction wasn't fraudulent. (Not just "It can't be...".)
2. I love the understatement. +1 Mr Halfacree!
3. Possibly just semantics, but does that imply the data can be recovered by the second party (ie. card issuer)?
Obviously (?) they're confident the data can't be re-engineered. Hmmmm, not sure I am.
However, as Mike 137 says above, it's just not the right way of going and must agree with the "security theatre" conclusion.
What you have
But fingerprint is what you have. To authenticate you also need what you know.
This means (at least in the EU), you still will have to enter pin every 5 transactions or 100 EUR accumulated since last check (or whatever amount they set), whichever comes first.
In other words, interesting novelty, but largely useless.
Instinctively, it doesn't sound as a good idea.
First, I don't want my bank to store my biometric data. Next, I want to keep my fingers if someone steals my payment card.