Skip to main content

Hackers manage to fool the Galaxy S8’s iris scanner with a photo

Samsung says tricking the Galaxy S8's iris scanner is 'unrealistic'

Germany’s venerable Chaos Computer Club (CCC) takes no prisoners — especially when it comes to smartphone security. After successfully fooling a fingerprint sensor using high-resolution images of a hand, specialized computer software, and a standard printer last year, the hacker collective set their sights on a new target: The Galaxy S8’s iris scanner.

In a video released on Monday, the white-hat team of hackers demonstrated how Samsung Galaxy S8’s iris sensor, supplied by security firm Princeton Identity, can be tricked into unlocking the phone with a cropped picture of a person’s irises and a pair of contact lenses. After toying around with the photo’s brightness and color contrast, printing out a high-resolution copy, and placing the contact lenses on top of the print, the CCC was able to unlock the Galaxy S8.

Recommended Videos

A spokesperson for Samsung told The Korea Herald that fooling the Galaxy S8’s iris sensor is “unrealistic,” and that it would require a “camera that can capture infrared light” and a photo of the owner’s iris. “It is difficult for the whole scenerio to happen in reality.”

Please enable Javascript to view this content

It was a little more challenging than it looks. In a blog post, CCC spokesperson Dirk Engling conceded that most selfies won’t fool the Galaxy S8’s iris scanner — a hacker would have to capture a person’s iris with a digital camera in night-shot mode or the infrared filter removed.

“In the infrared light spectrum — usually filtered in cameras — the fine, normally hard to distinguish [sic] details of the iris of dark eyes are well recognizable,” Engling wrote. “[We were] able to demonstrate that a good digital camera with 200mm-lens at a distance of up to five meters is sufficient to capture suitably good pictures to fool iris recognition systems.”

Still, the CCC’s workaround would appear to contradict Samsung and Princeton Identity’s messaging. In marketing materials, Samsung’s highlighted the Galaxy S8’s iris scanner as a “secure” alternative to PINs and passcodes. In an interview with Business Insider in April, Princeton CEO Mark Clifton characterized the Galaxy S8’s iris scanner as “better” than the FBI’s fingerprinting technology.

“[The FBI] uses 13 points of identification per fingerprint, so with all 10 finger you might have 130 unique identifiers,” Clifton said. “[The] Galaxy S8’s iris scanner can register up to 200 identifying features from a single iris.”

It is not the first time the CCC has demonstrated flaws in iris-scanning technologies. In March, the group fooled a commercial system with a 75-pixel image of an iris printed at a resolution of 1,200 dpi (dots per inch).

“If you value the data on your phone, and possibly want to even use it for payment, using the traditional PIN-protection is a safer approach than using body features for authentication,” Engling said.

Article originally published on 05-23-2017. Updated on 05-25-2017 by Kyle Wiggers: Added statement from Samsung spokesperson. 

Kyle Wiggers
Former Digital Trends Contributor
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
A new Samsung phone just leaked, and it’s a lot different from the Galaxy S24 Ultra
Samsung Galaxy A06 render.

Samsung Galaxy A06 render. GizNext via Onleaks

A new Samsung phone has just gotten a pretty substantial leak, and surprisingly, it isn’t a flagship. The leak comes from GizNext (via Onleaks), which has revealed everything there is to know about the Samsung Galaxy A06 in painstaking detail. Notably, this is a fairly entry-level phone that’s expected to have budget pricing characteristics of the Galaxy A-series and serve as a successor to the Galaxy A05.

Read more
5 phones you should buy instead of the Samsung Galaxy S23 FE
Samsung Galaxy S23 FE Mint Green color along with a Samsung notebook and a cermaic bowl with lemons.

The Samsung Galaxy S23 FE has much going for it -- including a bright AMOLED display, four promised Android upgrades, fast wireless charging, and a competitive price. And yet, the Android landscape is filled with excellent alternatives to it, many of which are even more compelling purchases. With that in mind, before you pull the trigger on an S23 FE, we'd recommend shopping around a bit first.

The following alternatives have various features that make them suitable substitutes for the Galaxy S23 FE. Some are less expensive, others offer more features, and some are newer. With that in mind, here are a few phones with think you should buy instead of the Samsung Galaxy S23 FE.
Samsung Galaxy S24

Read more
Your Galaxy S22 is about to get an important security update
Samsung Galaxy S22 held in hand.

If you own a Samsung Galaxy S22, you should be on the lookout for a critical security update. Currently making its way to European users, the update should soon arrive for U.S. folks, too. The same June 2024 update was sent to Galaxy S24 and Galaxy S23 owners earlier this year.

The new update addresses 59 security vulnerabilities and is tailored for the Galaxy S22 series, including the Galaxy S22, Galaxy S22 Plus, and Galaxy S22 Ultra. These smartphones bear model numbers SM-S901B, SM-S906B, and SM-S908B.

Read more