The use of facial recognition technology has become prolific, and with the rise of Wi-Fi and virtual private networks (VPNs), their security has become a hot-button topic. Two research teams from The Chinese University of Hong Kong (CUHK)’s Department of Information Engineering have recently revealed security vulnerabilities in mobile facial recognition software and enterprises’ Wi-Fi and VPN setups that have a real-world impact.
Bypassing facial identification in mobile apps is easier than previously thought
Users’ identity documents and selfies are easily stolen and sold on the black market, allowing them to be used for identity fraud. To prevent this from happening, most facial recognition systems require users to perform actions such as blinking or shaking their heads, known as liveness detection. While many researchers have studied deepfake or 3D mask attacks that target machine learning models, few have addressed the protocol design or implementation issues in facial recognition systems that can enable low-cost, easy-to-scale attacks.
A research team led by Professor Lau Wing-cheong from the Department of Information Engineering analysed 18 mobile facial recognition software development kits (SDKs), including those from industry leaders, and revealed security flaws in 11 of them that can result in liveness detection bypasses. After building an automatic app analyser to scan more than 18,000 apps, CUHK researchers found that around 300 contained at least one of the vulnerable facial recognition libraries. By exploiting design flaws in the SDKs, an attacker can circumvent facial identification using only static photos of the victim.
The research team has provided security tips for the design of app facial recognition systems and contacted the software companies about the vulnerabilities. The team recently presented its findings at the Black Hat USA 2023 conference, under the title “The Living Dead: Hacking Mobile Face Recognition SDKs with Non-Deepfake Attacks”.
Safety tips for the design of facial recognition systems:
Insecure enterprise Wi-Fi & VPNs allow attackers to compromise passwords and devices
Many employers provide their employees with enterprise Wi-Fi and VPN services, making it easier for them to use mobile devices such as laptop computers and smartphones to work on the go. To better understand their security issues, a research team led by Professor Chau Sze-yiu from the Department of Information Engineering conducted in-depth testing and analysis of enterprise Wi-Fi and VPNs.
With enterprise Wi-Fi, the research team discovered several design and implementation flaws in mainstream operating systems, which force users to adopt insecure wireless network settings, making them susceptible to attacks. The team also analysed more than 7,000 Wi-Fi setup guides from more than 2,000 colleges and universities around the world and found that about 86% instruct users to adopt unsafe Wi-Fi settings on at least one mainstream operating system. Due to these unfortunate oversights from software vendors and IT admins, attackers can steal users’ passwords using low-cost Wi-Fi impersonators.
With VPNs, the research team tested 132 front-end applications used around the globe and found serious yet previously unknown vulnerabilities in 63. These vulnerabilities allow hackers to steal user passwords easily and stealthily. In addition, the front-end applications of some VPN products allow a network attacker to execute arbitrary malicious code with high privileges on the user’s device, compromising the entire system. The research team also analysed about 2,000 VPN user manuals from universities worldwide and found configuration issues in more than 300 of them, which could make users fall into traps and have their passwords stolen by hackers.
Given the severity of these findings, the research team has made various safety recommendations to people affected and informed a number of local and foreign institutions about the defects. This research has led to the publication of three papers at well-known international academic conferences. The team was given the Best Paper Award at the 16th ACM Conference on Security and Privacy in Wireless and Mobile Networks (ACM WiSec 2023).
Safety tips for enterprise Wi-Fi and VPNs.
Please click the links below for the conference briefing and papers.