312-50V10 · Question #266
What is the main reason the use of a stored biometric is vulnerable to an attack?
The correct answer is D. A stored biometric can be stolen and used by an attacker to impersonate the individual identified. A stored biometric is vulnerable primarily because the digital representation can be stolen and replayed by an attacker to impersonate the legitimate user.
Question
What is the main reason the use of a stored biometric is vulnerable to an attack?
Options
- AThe digital representation of the biometric might not be unique, even if the physical characteristic
- BAuthentication using a stored biometric compares a copy to a copy instead of the original to a
- CA stored biometric is no longer "something you are" and instead becomes "something you have".
- DA stored biometric can be stolen and used by an attacker to impersonate the individual identified
How the community answered
(44 responses)- A2% (1)
- B7% (3)
- C14% (6)
- D77% (34)
Why each option
A stored biometric is vulnerable primarily because the digital representation can be stolen and replayed by an attacker to impersonate the legitimate user.
Biometric representations are designed to be highly unique; non-uniqueness is not the primary vulnerability of stored biometrics.
While comparing copies introduces some risk, the more critical issue is that a stolen copy gives an attacker persistent, unrevocable impersonation capability.
Although this is a valid conceptual argument about authentication factors, it describes a theoretical classification concern rather than the direct technical attack vector.
Unlike a physical biometric characteristic such as a fingerprint or iris that remains with the person, a stored digital template can be extracted from a database, intercepted in transit, or captured from a sensor and then replayed or injected into an authentication system. Because the system compares templates rather than performing live verification of a physical trait, a stolen template can be used by anyone to authenticate as the victim indefinitely, since biometrics cannot be revoked and reissued like passwords.
Concept tested: Stored biometric template theft and replay attacks
Source: https://www.nist.gov/publications/biometric-standards-and-guidelines
Topics
Community Discussion
No community discussion yet for this question.