Samsung Galaxy S5 Flaw Allows Hackers To Clone Fingerprints, Claim Researchers
Biometric information is about as personal as data gets. But Google's Android partners are still failing to protect it, as researchers from security firm FireEye will discuss this week at RSA …
Context & Ripple Effects
Samsung had already conceded the point on hardware by early 2015: it announced the Galaxy S6 would drop the S5's swipe-style reader for a Touch ID-like press-based fingerprint sensor. FireEye's RSA presentation explains why — the researchers claim the swipe sensor's design lets attackers clone enrolled fingerprints rather than just spoof a scan.
The finding lands in the middle of a longer pattern in this corpus: within months, researchers showed fingerprints could be remotely stolen from Samsung, HTC, and Huawei phones via an image-processing flaw for which vendors shipped patches (remotely stealing Android fingerprints). Biometric unlock was becoming table stakes across Android while its attack surface kept widening.
First-order effects
- Galaxy S5 owners using the fingerprint reader for device unlock and payments are exposed if an attacker gains local access, since a cloned print defeats the biometric gate itself.
- Samsung and Google face immediate reputational and engineering pressure at RSA, where FireEye's disclosure forces a public response on Android's biometric stack.
Second-order effects
- Vendors respond with patches rather than redesigns — the same playbook seen when the later cross-vendor fingerprint theft was fixed after disclosure — leaving the underlying question of sensor trust boundaries unresolved.
- Each replacement modality inherits the problem: Samsung's own follow-ons were beaten too, from the Galaxy S8 facial recognition fooled by a photo to the Chaos Computer Club defeating Galaxy S8 iris recognition with a photo of the victim's eye.
Third-order effects
- If the pattern holds, biometric data becomes a liability class unlike passwords — fingerprints and irises cannot be rotated once extracted, so every shipped flaw is permanent exposure for affected users.
- The corpus points toward structural cost: Samsung's cadence of biometric and cryptographic defects culminates in researchers finding [[a:976293|~100M phones, including the Galaxy S21, shipped with flaws allowing extraction of secret cryptographic keys]] — suggesting speed-to-market on sensors repeatedly outruns security review.
The trend: Android OEMs are racing biometric features into market faster than they can secure them, with independent researchers — not vendors — setting the security agenda for fingerprint, face, and iris authentication.