Biometric mobile security a way off: Telstra

Thumb scanners for mobile phone security are a while off, according to Telstra's chief technology officer Dr Hugh Bradlow, who said that his security team managed to best a "Russian mafia-proof" scanner in just one day.

Hugh Bradlow

Hugh Bradlow (Credit: Telstra)

Speaking at a CEDA CIO event in Sydney this afternoon, Bradlow repeated his belief that it was just a matter of years before people replace their keys and cards with mobile phones using radio frequency identification (RFID) technology, such as that already in use by companies like Visa and Mastercard.

When he was questioned as to whether this would have security implications if someone's phone was stolen, Bradlow said research showed that people in general were more aware of their phone than their keys and wallet. Such awareness could be of more use than other protective measures, according to Bradlow.

"We a few years ago got one of these thumbprint recognition things that was supposed to be Russian mafia-proof. In other words, if they cut your thumb off and put it on the device, it was supposed to not respond because it required a live thumb with blood flowing through it," he said.

"Now my guys defeated that in one day with $2 worth of equipment they bought at Coles. They lifted a fingerprint from glass, got a piece of gelatin, transposed the fingerprint onto the gelatin, and put the gelatin on their thumb ... and it worked," he added. "So would you rely on that for your banking? No. You might rely on it to open your email or something less precious to you."

"You're still going to have multi-factor authentication for things that are important."

Bradlow said he was less concerned about potential privacy or security breaches through the increased use of RFID technology than he was about the information people handed over willingly to social-networking websites.

"I don't think things like RFID change privacy implications that much. The things that are really changing the privacy implications are the social-networking sites which lull people into a false sense of security and get them to elicit a whole lot of information about themselves ... They haven't thought about the consequences," he said.

"I feel uncomfortable with Facebook because every now and then I get tagged," he added. "My daughter takes a picture of me when I'm visiting her in Oxford and it's tagged on Facebook. I'm not sufficiently self-indulgent to think that people care about where I am though."

NBN and God

Bradlow indicated that speeds achieved using wireless broadband tended to be around five to eight years behind fixed-line speeds, but he said this did not mean wireless would one day replace fixed-line services such as the National Broadband Network (NBN).

"If God had not meant us to have fixed networks he wouldn't have constrained spectrum in the way he has done. Or she's done, should I say," Bradlow said.

"The fact is that mobile access is constrained as a shared medium in the sense that your first point of interconnect is shared at the radio base station. That shared capacity is constrained by spectrum."

Bradlow said that if he wanted to stream high-definition video at 10Mbps over a long-term evolution network with a total average speed of 100Mbps, he could only share that network with 10 people.

"And that's not nearly enough to build a network around," he said.

The two technologies were meant to be complementary, Bradlow said, and he didn't expect wireless technologies to be able to achieve the same speeds as a fixed-line service.

"The answer is no because of the capacity issue," he said. "I'll stake my reputation on it and I'll probably be dead before anyone tests this, but you do need high-speed fixed networks in developed countries."

Talkback

What a lot of rubbish... from the leading technologist at Telstra - give me strength... I'm switching my service provider tomorrow...

Their security engineer defeated biometrics "a few years ago" using gelatine from Coles... How clever and I have no doubt that there has been absolutely no advance in that technology since.

And God is constraining spectrum? This guy is a nutter. When I was a telecom engineer - some 20 years ago - transmitting broadband speeds over copper - like we do today - was impossible. Then God suddenly blessed us with the knowledge to create DSL...

When God is ready - he will undoudtedly bless us with the knowledge to massively increase spectrum and wireless transmitting speeds too....

...and with any luck he'll strike down the idiots with bolts of lightening at the same time....

Maybe Telstra and Hugh should be investing in some serious R&D instead of sending his guys up to Coles to buy gelatine....

What Rot.What Rot. November 11th, 2010
Report offensive content Reply (+1) (0)

Here we have a CTO of a major telco telling us how a long time ago, in a far distant R&D lab, someone broke a simple and now obsolete form of security. How is that relevant to today? I'd rather hear about recent technical achievements that don't involve gelatine.

Using mobile phones as part of any RF based biometric security is stupid. As soon as you turn a 'biometric signature' into an electronic form, there will be someone who'll try to capture, copy, and break it. Throw that out via RF and you're simply inviting disaster no matter how wonderful you think your encryption is.

As for the NBN and other technologies, unless you're a religious leader stating that God supports your technical arguments isn't going to win you a pay rise or promotion...at best you'll get a trip to the asylum.

Scott WScott W November 11th, 2010
Report offensive content Reply (0) (0)

Who needs gelatin? I have modern fingerprint readers on some of my PCs and they can't even tell WHICH finger they're supposed to be scanning!

TreknologyTreknology November 11th, 2010
Report offensive content Reply (0) (0)

If officials say Russian every time they say mafia then I have all moral rights to say Australian when I say idiot. Like: this Austrlian-idiot proof device....

DimitriAuDimitriAu November 12th, 2010
Report offensive content Reply (0) (0)
Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

Tech Blueprint

ZDNet Australia Live

The implications of NZ school Principals demanding access to student mobile devices | ZDNet http://t.co/jMSJXzpT

michael kors purse http://www.michaelkorshandbags-online.com/#37 ZLlrPzyxFdu

43 minutes ago by YJyqTygeShm on Kodak files for bankruptcy, sues Samsung

Google closes Motorola buy: http://t.co/9ezoLnSg

War talk dominates #AusCERT 2012 - http://t.co/WbuTt174 - #security #cyber

Nuance launches in car voice activated platform (Zack Whittaker ZDNet) http://t.co/9mFEA93c

Sage simplifies SMB payment management http://t.co/gbAKq1ku

A farewell to democracy: Kaspersky http://t.co/zE2SAGol via @zdnetaustralia

Private Cloud: 'Everyone’s got one. Where's yours?': Promising the business a cloud delivered within your own ... http://t.co/jCsDqPlj

BYOD: What the people think http://t.co/hR1pokPG

@ZDNet
R they joking? iPhone only way 2 go!
New 5 out in October (we think) & will kill all copycat phones, AGAIN!!

Android's biggest security flaws - Security - News - ZDNet Australia http://t.co/6nYZRvhh
@sjshock

Google: We now own Motorola Mobility http://t.co/oeFgovzl

@dougsteelman RT @dellsecureworks : Security researcher Tim Vidas of Dell SecureWorks outlines problems with the Androi…http://t.co/BE4LmItr

EMC hones focus on hybrid cloud, big data http://t.co/To6Qpsz4 #bigdata #XBRL #GRC $$

#Security researcher Tim Vidas of @DellSecureworks outlines some concerns with the #Android operating system: http://t.co/gV8MgCiN

Article and Infographic: Retailers attracting the next-gen customer http://t.co/UL3E2Fct #socialmedianews

adgtqMkWiDg //www.2012chanelbagsforsale.com]chanel handbags RKaOBd krFiudOGrBw //www.2012chanelbagsforsale.com]chanel outlet GQXRRYsDNI...

5 hours ago by rfcdvpmubn on Deakin Uni opts for Cisco Unified Computing

“@Techmeme: TiVo streaming coming to iOS this summer (@jasonogrady / ZDNet) http://t.co/07L0ndoD ” < wonder if it will work in AU

Security researcher Tim Vidas of Dell SecureWorks outlines problems with the Android operating system: http://t.co/lA4t9ffu

Why I (now) hate Apple | ZDNet - http://t.co/f5v6BWxu

A farewell to #democracy: (according to)> #Kaspersky http://t.co/82GeK5Ik via @zdnetaustralia

I am not sure how this issue becomes an attack on Mr Turnbull. But I guess he is fair game. In any event I would have thought a Ddos woul...

6 hours ago by Doubt on National Botnet Network coming: Earthwave

RT @JamesVickery: Westpac board goes paperless with iPads http://t.co/L8V05zFs

I still use 98SE. Windows ME was an abortion in a bucket and Vista was ME without the bucket. My screen may look boring, but I jumped str...

6 hours ago by Treknology on Microsoft admits Vista was 'cheesy'

What is it [url=http://vintage-erotic.com/] retro xxx movies [/url]? And why all this it is possible to look free of charge?

6 hours ago by Drienlyinhibe on Australian police swoop on Warez community

Windows 8 includes enhanced multi-monitor support http://t.co/ZVfVHntw

This story has been voted 10 times in the last 24 hours!

6 hours ago, CeBIT 2012 opens: photos

Android users, you think only Apple are having security problems. See what is your major problem.
http://t.co/cjJYSOJw #infosec

RT @my_CISB: Android users, you think only Apple are having security problems. See what is your major problem.
http://t.co/cjJYSOJw #infosec

This story has been voted 15 times in the last 24 hours!

7 hours ago, Lenovo ThinkPad 3G tablet (32GB)

RT @aimee_maree: "For Buytaert, Drupal owes much of its success to being open source" http://t.co/RdnHB2y9 #Drupal

Malware charges users for free Android apps on Google Play - http://t.co/Zhnf2rtw

Well I don't know what they have done with their EFTPOS machines, local one in WA Coles Express I used this morning and I normally do "ch...

7 hours ago by harryinthesoup on Coles ditches PINs in payment pilot

@TaschaD More information: http://t.co/8rfUsQJ0 I guess I shall simply go without.

RT @zdnetaustralia: The Westpac board have gone paperless using iPads and a secure, home-grown app environment: http://t.co/F1d17bvF ^LH

Chrome overtakes IE: does it matter? http://t.co/JRvKsVdn

"For Buytaert, Drupal owes much of its success to being open source" http://t.co/RdnHB2y9 #Drupal

RT @JamesVickery: Westpac board goes paperless with iPads http://t.co/L8V05zFs

Microsoft's big bet: Windows 8's 'too many cooks' problem http://t.co/8AdrUAWA

RT @JamesVickery: Westpac board goes paperless with iPads http://t.co/L8V05zFs

Will Windows Phone's bumpy start eventually lead to success? http://t.co/OSmxT8k6

@Wellsie777 @zdnetaustralia can be done http://t.co/jIlgdXJ4 I once had 2 phones with the same number without even trying!

ルブタンは彼が彼の靴に女性が感じる方法を好む、 クリスチャンルブタンポンプ これは彼がそれらを...

8 hours ago by Coiffboarieri on Reservoir blogs: Fan fakes Tarantino diary

US, Australia team up on cybersecurity - Security - News - #ZDNet Australia http://t.co/rG2aTskD

6.7 M last ditch attempt - interesting - The Auckland region (population 1.4 mil) has estimated to have spent less than this in total ...

10 hours ago by debsteele on Vic scraps HealthSMART system

Interesting - no mention of Win 98/ME/2000 ... which heralded Internet access for millions of users ? I thought Win 98/ME would be the mo...

11 hours ago by gouranga on Microsoft admits Vista was 'cheesy'

An Application like Good from Good Technologies does the same thing, working with the enterprise email server and is off the shelf.

11 hours ago by Helpdesk123 on Westpac board goes paperless with iPads

Never mind a "B+" version, go for "C" and put in a few extras. I'd like a high speed ADC (100Msps) but that's just me... Final size? Equ...

12 hours ago by sa_penguin on Raspberry Pi architect mulls design change

what a non-story. these thing happen all the time. is zdnet short on material?

13 hours ago by paulwrussell on Spotify launch suffers redirect bungle

4 months old phone died. Took 6 weeks, three visits to the authorised repairer (Fonebiz) to "fix it". 2nd hand untested parts used, I say...

13 hours ago by paracin on Sony Ericsson Xperia Arc S

It's easy to rubbish an old operating system long after the rest of the world has already passed judgement upon it. I would be far more i...

14 hours ago by ramnet on Microsoft admits Vista was 'cheesy'

If Vista is cheesy, Metro is an over-ripe Stilton.

14 hours ago by meski on Microsoft admits Vista was 'cheesy'

you are kidding right - what qualification do you have to make such wildy stupid statements - do you really have customers who pay you fo...

15 hours ago by rant rant rant on National Botnet Network coming: Earthwave

Exactly. There are two topics of discussion, that are co-mingled; 1) Unauthorized software was put on the company device, by an IT person...

18 hours ago by lamont on ABC's Bitcoin miner tackled in minutes

First off, Bitcoin is not a virus. Second off, the only way to generate Bitcoins, is by using a Bitcoin miner. More information on this h...

1 day ago by rizowski on ABC's Bitcoin miner tackled in minutes

When an operating system is sold it should not launch until an approved security service is purchased online with a list of approved supp...

1 day ago by Kevin Cobley on National Botnet Network coming: Earthwave

Admits? Don't fall for their marketing. Vista was beautiful. Microsoft has a history of trashing their older OSes.

1 day ago by anonymuos on Microsoft admits Vista was 'cheesy'

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar