pk.org: Computer Security/Lecture Notes

Part 6 - Biometric Authentication

Approximate matching, error rates, spoofing, and the limits of biometrics

Paul Krzyzanowski – 2026-09-24

A password check requires an exact match. A fingerprint check must allow for changes in angle, pressure, and skin condition. Two scans of the same finger can differ, so the system must decide whether their features are similar enough to accept a match.

Biometric authentication checks identity using physical or behavioral characteristics. Biometrics provide the “something you are” factor, often as a local check before a device uses a cryptographic key. The traits in use fall into two groups:

Voice reflects both physical characteristics and learned behavior.

Matching Against a Threshold

A biometric system compares features from a new sample with a stored template, a representation created during enrollment. A matcher can compute a distance between them, with a smaller distance indicating a closer match:

features = extract_features(scan)
if distance(features, stored_template) <= threshold:
    accept()

Choosing the threshold determines how much variation the matcher accepts. A loose threshold accepts more legitimate scans, but also more impostors. A strict threshold reduces false matches at the cost of rejecting legitimate users more often.

Error Rates

The quality of a biometric system is described by how often it makes each kind of mistake:

These rates are properties of the whole system: the trait being measured, the sensor that captures it, and the software that extracts and compares features. A small, low-resolution fingerprint sensor with a basic matcher makes more mistakes than a larger sensor with a better algorithm, and fingerprints, faces, irises, and voices each behave differently. Changing a setting can trade one rate for the other, but it cannot lower both.

A receiver operating characteristic (ROC) curve shows every combination of errors a system can reach.1 It plots the correct acceptance rate against the false accept rate as the threshold varies. For a given system tested under given conditions, choosing a threshold picks one point on it: a stricter threshold moves toward fewer false accepts and more false rejects, and a looser one moves the other way. A better sensor or matcher, better enrollment, or better capture conditions can move the curve itself. Measured rates also depend on the population tested, as the demographic differences described below show.

The equal error rate (EER) is the error rate at the threshold where FAR and FRR are equal. It reduces a system’s curve to one number for comparing systems. A lower EER indicates a better system when both were tested on the same data under the same conditions, but it does not guarantee better performance at every threshold.

A deployment chooses an operating point, the threshold and resulting error rates, based on what each kind of mistake costs. A fingerprint reader on a car door favors convenience. The owner expects the door to open on the first try, in the cold or with wet hands, and repeated rejections would send owners back to the key. A reader controlling a gate into a high-security facility, or a safe, favors security. A rejected employee can try again or call a guard, but an impostor must not get in. The same sensor and matcher can serve both, with different thresholds.

One device can also apply different policies to different actions. In March 2018, Samsung’s Galaxy S9 introduced Intelligent Scan, which combined face and iris recognition to unlock the phone. Samsung did not allow it for Samsung Pay, its mobile payment service, which required the iris scanner alone or a fingerprint.

Apple reports a random person’s chance of matching one enrolled fingerprint as 1 in 50,000 for Touch ID, and one enrolled appearance as less than 1 in 1,000,000 for Face ID. These figures do not measure success against a targeted spoof. Face ID also has higher false-match risks for twins, similar-looking siblings, and young children. Both systems require the passcode after five failed biometric attempts.

Verification and Identification

Biometrics can answer two different questions, and the second is much harder than the first:

The larger search creates more opportunities for a false match. Suppose a matcher incorrectly matches two different people once per million comparisons. Searching a million unrelated templates would then produce about one false match per search on average, if that rate holds across the database.

Large fingerprint databases narrow the search before comparing minutiae. Prints are first sorted by their overall ridge pattern, such as arches, loops, and whorls, and a new sample is compared only with templates in its class.

India’s Aadhaar identity program performs biometric searches during enrollment to detect duplicate registrations. It collects ten fingerprints, two iris scans, and a facial photograph. Multiple biometric measurements help distinguish candidates when one measurement alone is not enough.

The Enrollment and Matching Pipeline

A typical system separates enrollment from the steps used for each later check:

  1. Enrollment captures several samples and builds a template from the features that are distinctive and stable across them. Poor enrollment produces poor matching for as long as the template is in use.

  2. Sensing captures a new sample. Lighting, focus, finger pressure, dry skin, and sensor quality all affect it.

  3. Feature extraction reduces the sample to features. Many fingerprint matchers use minutiae, the points where ridges end or split, and compare their positions and directions. A fingerprint system compares a few dozen minutiae, and a small phone sensor sees only part of the finger. Iris systems extract a few hundred features from the texture of the iris, which is one reason iris matching reaches much lower false-match rates.

  4. Matching computes a score between the extracted features and the template.

  5. Decision compares the score with the threshold.

Presentation Attacks

Biometric traits are often observable. Faces appear in photographs, voices in recordings, and fingerprints on touched surfaces. A presentation attack attempts to fool the sensor with a substitute such as a photograph, mask, molded finger, or recorded voice.

In September 2013, days after the iPhone 5s went on sale, the Chaos Computer Club, a German hacker association, demonstrated a Touch ID spoof. It photographed a fingerprint left on glass and used a printed reproduction to make an artificial fingerprint.

In April 2020, researchers at Cisco Talos, Cisco’s threat intelligence group, made fake fingerprints by casting fabric glue in 3D-printed molds, working from prints collected by direct contact, from sensor images, and from photographs of prints on glass. The fakes unlocked most of the phones and laptops they tested at least once, with an overall success rate of about 80 percent.

Voice systems face the same problem, since recordings and AI-generated speech can imitate the enrolled speaker. In February 2023, a reporter at Vice, a news website, used a free voice-cloning service and about five minutes of recorded speech to pass the voice authentication of Lloyds Bank, a major British bank, and reach his own account. The bank also asked for his date of birth.

In October 2019, Samsung reported a different sensor failure. Certain silicone covers caused affected Galaxy S10 and Note10 models to recognize the cover’s pattern as the user’s fingerprint. Samsung advised removing the covers and re-enrolling fingerprints, and announced a software patch.

Liveness detection checks for evidence of a live person at the sensor. Some fingerprint sensors look for signs of living tissue, such as blood flow, the electrical properties of skin, or features beneath the surface. Face ID projects thousands of invisible dots to build a depth map of the face, so a photograph or a video on a flat screen does not match. Face unlock that relies on an ordinary camera image is weaker. In January 2019, Consumentenbond, a Dutch consumer organization, found that a photo of the owner unlocked 42 of 110 Android phones it tested. Other systems look for blinking or movement. These checks make particular spoofs harder, but their effectiveness must be tested against attacks, not inferred from ordinary matching accuracy. A thin artificial fingerprint worn over a real finger, for example, can pass a check for blood flow or warmth.

The path from the sensor to the matcher also needs protection. An attacker who can inject data between them may bypass the sensor’s anti-spoofing checks. Secure device designs protect that path and isolate templates and matching from the main operating system.

Protecting Templates

Passwords can be checked using salted hashes because verification requires an exact match. Ordinary hashing does not preserve the similarity between nearby biometric measurements. This is because the data from each new reading will be slightly different and thus produce a different set of values. Hashing each scan would therefore make legitimate variations look unrelated. Biometric template protection requires different techniques.

Depending on the application, systems use several protections:

A central database without these protections exposes every enrolled person at once. In August 2019, researchers found an exposed database belonging to BioStar 2, a building access-control system from Suprema, a South Korean security company, used by banks, police, and defense contractors. It held the fingerprints of about a million people, stored as the fingerprints themselves rather than in a protected form, along with unencrypted passwords.

Limits of Biometric Authentication

Biometrics differ from passwords and keys in three ways that limit where they can be used:

  1. A stolen biometric cannot be revoked. A leaked password can be changed. A leaked fingerprint stays leaked for life, and every system that accepts that finger is exposed to spoofs made from the copy. A person has ten fingers, two irises, and one face. If the right index fingerprint is stolen, the owner can enroll another finger, but has only nine left. If an iris pattern is stolen, that eye cannot be replaced. The 2015 breach of the U.S. Office of Personnel Management (OPM), which maintains federal personnel and background investigation records, exposed fingerprints belonging to 5.6 million people.

  2. Biometrics cannot be compartmentalized. A user can choose a different password for every service and keep track of them in a password manager, so a breach at one site exposes nothing at another. The fingerprint presented to a shopping site is the same one presented to a government service. Separate protected templates can reduce linkage, but exposure of the trait may help attacks against every system that uses it. For this reason, and because enrollment is easier on a device the user holds, biometrics are used mostly to unlock phones, laptops, and other local devices rather than to log in to remote services.

  3. Biometric samples lack a canonical form. Two scans of the same finger differ in rotation, position, pressure, and which part of the finger touched the sensor, and they cannot be reliably normalized into identical values. The matcher must align the samples and compute an approximate score rather than test for equality. That is why templates cannot be protected with an ordinary hash, and why identification with fingerprints or faces is expensive: a sample cannot be looked up directly, so it must be compared against many templates. Checking one template on a phone takes a fraction of a second, but searching millions of templates is a large computation. Iris recognition is a partial exception. The iris can be unwrapped into a standard layout and encoded as a fixed-length string of bits, and two codes are compared by counting the bits that differ, which is fast enough to search large databases. Two codes from the same eye are close rather than identical, so a threshold is still needed.

Biometric authentication also faces two practical limits:

Where Biometrics Fit

For online login, a biometric can authorize use of a key held on the device. The login then combines two factors: something the user is, which unlocks the key, and something the user has, the device that holds it. With a passkey, the device checks a fingerprint or face locally and the site verifies a signature. The biometric template stays on the device, and the site can revoke the public-key credential and register a replacement.

A stolen template does not reveal the passkey’s private key, though a successful spoof could unlock the device and allow its use.


Lecture 4: Part 1 | Part 2 | Part 3 | Part 4 | Part 5 | Part 6 | Appendix
Lecture 4 Study Guide | List of terms


  1. The name comes from radar and radio engineering, where the curve described how well a receiver separated real signals from noise at different detection thresholds. The term appeared in U.S. signal-detection research in the early 1950s. ↩