Skip to main content
  1. Home
  2. Phones
  3. Android
  4. Mobile
  5. News

Hackers manage to fool the Galaxy S8’s iris scanner with a photo

Samsung says tricking the Galaxy S8's iris scanner is 'unrealistic'

Add as a preferred source on Google

Germany’s venerable Chaos Computer Club (CCC) takes no prisoners — especially when it comes to smartphone security. After successfully fooling a fingerprint sensor using high-resolution images of a hand, specialized computer software, and a standard printer last year, the hacker collective set their sights on a new target: The Galaxy S8’s iris scanner.

In a video released on Monday, the white-hat team of hackers demonstrated how Samsung Galaxy S8’s iris sensor, supplied by security firm Princeton Identity, can be tricked into unlocking the phone with a cropped picture of a person’s irises and a pair of contact lenses. After toying around with the photo’s brightness and color contrast, printing out a high-resolution copy, and placing the contact lenses on top of the print, the CCC was able to unlock the Galaxy S8.

Recommended Videos

A spokesperson for Samsung told The Korea Herald that fooling the Galaxy S8’s iris sensor is “unrealistic,” and that it would require a “camera that can capture infrared light” and a photo of the owner’s iris. “It is difficult for the whole scenerio to happen in reality.”

It was a little more challenging than it looks. In a blog post, CCC spokesperson Dirk Engling conceded that most selfies won’t fool the Galaxy S8’s iris scanner — a hacker would have to capture a person’s iris with a digital camera in night-shot mode or the infrared filter removed.

“In the infrared light spectrum — usually filtered in cameras — the fine, normally hard to distinguish [sic] details of the iris of dark eyes are well recognizable,” Engling wrote. “[We were] able to demonstrate that a good digital camera with 200mm-lens at a distance of up to five meters is sufficient to capture suitably good pictures to fool iris recognition systems.”

Still, the CCC’s workaround would appear to contradict Samsung and Princeton Identity’s messaging. In marketing materials, Samsung’s highlighted the Galaxy S8’s iris scanner as a “secure” alternative to PINs and passcodes. In an interview with Business Insider in April, Princeton CEO Mark Clifton characterized the Galaxy S8’s iris scanner as “better” than the FBI’s fingerprinting technology.

“[The FBI] uses 13 points of identification per fingerprint, so with all 10 finger you might have 130 unique identifiers,” Clifton said. “[The] Galaxy S8’s iris scanner can register up to 200 identifying features from a single iris.”

It is not the first time the CCC has demonstrated flaws in iris-scanning technologies. In March, the group fooled a commercial system with a 75-pixel image of an iris printed at a resolution of 1,200 dpi (dots per inch).

“If you value the data on your phone, and possibly want to even use it for payment, using the traditional PIN-protection is a safer approach than using body features for authentication,” Engling said.

Article originally published on 05-23-2017. Updated on 05-25-2017 by Kyle Wiggers: Added statement from Samsung spokesperson. 

Kyle Wiggers
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
Google Photos on Android finally gives your custom stickers a home
A new dedicated Stickers folder in Collections saves every custom sticker you create, so you never have to hunt for them again.
Google Photos Stickers folder on phoneGoogle Photos Stickers folder on phone

After debuting a nifty sticker-creating feature on iOS last year, Google Photos extended it to Android users this February. The feature lets you quickly create stickers with a simple long-press gesture, making it incredibly easy to share custom stickers with friends and family. Now, Google is adding one more layer of polish to the experience: a dedicated folder that automatically stores every sticker you've ever made.

Where to find the Stickers folder

Read more
Leaked Pixel 11 wallpapers hint at what color options you’ll likely get to choose from
The full wallpaper collection for the Pixel 11, Pro, Pro XL, and Pro Fold has leaked, offering clues about the colorways Google may announce at launch.
Google Pixel 10 Pro in the official silicon case

The Pixel 11 series isn't due until August, but a steady stream of leaks has already revealed details ranging from design to specs across all four upcoming devices. The latest addition gives us a look at the wallpapers Google may ship with the lineup, and they offer a strong hint at the color options likely at launch.

A toned-down palette across the board

Read more
Got a missed call from an unknown number? Malwarebytes’ new free tool will tell you if it’s a scam
With $21 billion stolen from Americans last year through phone scams, a free no-friction reverse lookup removes the guesswork entirely.
Business Card, Paper, Text

Missed calls from unknown numbers used to be easy to ignore, but now they’re harder, especially since scammers spoof real local numbers and clone familiar voices with AI. Malwarebytes has launched a direct answer to that problem.

A free, standalone reverse phone lookup tool that tells you whether a number is safe, suspicious, or a known scam, so that you don’t call it back unnecessarily. It’s called Scam Number Check and it is available now at malwarebytes.com/scam-check/phone. The best part is that you don’t need an account or subscription to access it. 

Read more