It would probably be useful for Ubuntu to have an apparmor profile there
** Changed in: fprintd (Ubuntu)
Importance: Undecided => Low
** Changed in: fprintd (Ubuntu)
Status: New => Triaged
** Also affects: fprintd via
https://gitlab.freedesktop.org/libfprint/fprintd/issues/16
Importance: Unknown
Status: Unknown
** Also affects: apparmor (Ubuntu)
Importance: Undecided
Status: New
--
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to fprintd in Ubuntu.
https://bugs.launchpad.net/bugs/1822590
Title:
Found storing user fingerprints without encryption
Status in fprintd:
Unknown
Status in apparmor package in Ubuntu:
New
Status in fprintd package in Ubuntu:
Triaged
Bug description:
Dear all,
I would like to report a new issue as follows.
‘fprintd’ saves a fingerprint data, ISO/IEC 19794-2 formatted, to a file on
the host without any encryption.
Though fprintd generates fingerprint image with root permission for
protecting the file from attackers, it is not of itself sufficient.
It is well known threat model that a formatted fingerprint data can be
restored to original image about a decade ago.
[1-4] are presented to create sophisticated and natural-looking fingerprints
only from the numerical template data format as defined in ISO/IEC 19794-2.
They also successfully evaluated these approaches against a number of
undisclosed state-of-the-art algorithms and the NIST Fingerprint Image Software.
We need improvements of those issues.
[1] R. Cappelli et al., “Fingerprint Image Reconstruction from Standard
Templates”, IEEE Trans. on Pattern Analysis and Machine Intelligence, vol.29,
no.9, pp.1489-1503, 2007.
[2] A. Ross et al., “From template to image: Reconstructing fingerprints from
minutiae points”, IEEE Trans on Pattern Analysis and Machine Intelligence,
vol.29, no.4, pp.544-560, 2007.
[3] R. Cappelli et al., “Can Fingerprints be reconstructed from ISO
Templates?”, IEEE ICARCV 2006.
[4] J. Feng et al., “Fingerprint Reconstruction: From Minutiae to Phase”,
IEEE Trans on Pattern Analysis and Machine Intelligence, vol.33, no.2,
pp.209-223, 2011.
Sincerely,
Seong-Joong Kim
To manage notifications about this bug go to:
https://bugs.launchpad.net/fprintd/+bug/1822590/+subscriptions
--
Mailing list: https://launchpad.net/~desktop-packages
Post to : [email protected]
Unsubscribe : https://launchpad.net/~desktop-packages
More help : https://help.launchpad.net/ListHelp