AskVantage

Security and privacy

Hackers have found a new way to hack Samsung’s iris security system

Biometric security systems are awesome, until they're hacked, and increasingly companies and individuals are finding that their latest and greatest biometric security systems are easier to hack than the password systems they replaced.

Key takeaways

  • In yet another stab in the back for biometric security hackers have published details of a method to break the iris based authentication in Samsung’s shiny new Galaxy S8 that involves the use of a number of basic, everyday items.
  • Published by German whitehat hacking group Chaos Computer Club (CCC), the hack involves the use of a digital camera, a laser printer, with Samsung models, ironically, working best, and a simple everyday contact lens.
  • The contact lens is then placed on top of the face to mimic an actual iris, held in front of the phone and bingo – the Galaxy S8 unlocks.
Cite or link to this article

Griffin, M. (2017) 'Hackers have found a new way to hack Samsung’s iris security system', 311 Institute, 8 June. Available at: https://www.311institute.com/hackers-have-found-a-new-way-to-hack-biometric-iris-security-systems/ (Accessed: 1 October 2026).

Criminals know you love taking selfies, and they love your selfies too – especially the ones where you’re holding your fingers up in a victory sign. They also love the fact that your photos are good enough quality for them to print out a high definition print of your eyes and fingerprints. And they especially love the fact that these alone are good enough to help them unlock all of your biometric protected stuff and gadgets.

I love your new galaxy smartphone by the way – great cat wallpaper.

In yet another stab in the back for biometric security hackers have published details of a method to break the iris based authentication in Samsung’s shiny new Galaxy S8 that involves the use of a number of basic, everyday items.

Published by German whitehat hacking group Chaos Computer Club (CCC), the hack involves the use of a digital camera, a laser printer, with Samsung models, ironically, working best, and a simple everyday contact lens.

To bypass the Iris scanning feature, they use a digital camera to take a picture of a phone owner’s face and print it out on the laser printer. The contact lens is then placed on top of the face to mimic an actual iris, held in front of the phone and bingo – the Galaxy S8 unlocks.

Whoohoo! By the way – I deleted all your cat videos. Sorry it was a mistake - honest!

While the hack is fairly simple, there are some provisos in its implementation, including, obviously, making sure the quality of the photo is good enough to capture the details of the iris.

When it was first introduced Samsung’s iris scanning feature, which is powered by a biometric scanner manufactured by Princeton Identity, promised to be an easier way for users to unlock their phones, and when the Galaxy S8 launched, Samsung said it offered “one of the safest ways to keep your phone locked.”

“Iris recognition may be barely sufficient to protect a phone against complete strangers unlocking it. But whoever has a photo of the legitimate owner can easily unlock the phone,” said CCC spokesman Dirk, “if you value the data on your phone – and possibly want to even use it for payment – using the traditional PIN protection is a safer approach than using body features for authentication.”

While the Galaxy S8 does offer fingerprint scanning as an alternative to iris scanning, and no one yet has published a way to hack it, fingerprint scanners themselves have already been shown to be vulnerable to duping which is why companies are now busy creating ultrasound based fingerprint scanners that move away from today’s more basic electro-sensitive scanners.

That said though, with new hacks and technologies such as Adobe Voco and LyreBird, which can copy and reproduce your voice print with just a minutes worth of audio, for example, off of YouTube, and new fingerprint and ‘Photo morph’ hacks that fool facial recognition systems I think some of today’s biometric security companies need to go back to the corner of the room and get back to the drawing board.

FAQ

Why does this matter?

Biometric security systems are awesome, until they're hacked, and increasingly companies and individuals are finding that their latest and greatest biometric security systems are easier to hack than the password systems they replaced.

Matthew Griffin

About the author

Matthew Griffin Founder, 311 Institute

Matthew Griffin is a multi-award winning Futurist and expert in Disruption and Innovation, Geopolitics, Leadership, and Technology, who NASA have described as a "walking encyclopaedia of the future" and a "futurist Polymath."

Read full bio

Matthew Griffin is a multi-award winning Futurist and expert in Disruption and Innovation, Geopolitics, Leadership, and Technology, who NASA have described as a "walking encyclopaedia of the future" and a "futurist Polymath." 15-time best selling author of the "Codex of the Future" series, Matthew is the Founder and Futurist in Chief of the 311 Institute, a global Futures and Deep Futures advisory firm working with royal households, world leaders, G7, G20, and G77 governments, NGOs, and multi-national mid and mega cap firms to help them explore, shape, and lead the next 50 years of business and society.

An award-winning YouTube creator with over a million followers, with an unrivalled global reach and impact, Matthew is a highly sought-after international keynote speaker, lecturer, and mentor who collaborates with global leaders through the United Nations Alliance of Civilizations (UNAOC) and United Nations General Assembly (UNGA) to shape pivotal initiatives such as the UN’s AI for Humanity program, the United Nations Conference of the Parties (UN COP), and the World Economic Forum in Davos.

As the former Global Head of Cloud, National Security, and Enterprise Sales for companies including Atos, Dell-EMC, and IBM, Matthew has a proven track record of building multi-billion dollar business units and turning failing divisions into market leaders. His ability to identify, analyse, and communicate the implications of hundreds of emerging technologies and trends is unparalleled, and his insights are trusted by many of the world’s most respected organisations, including ABB, Accenture, Adidas, AON, ARM, BCG, Centrica, Citi, Coca-Cola, Dentons, Deloitte, Dow Jones, EY, Google, KPMG, Lego, Legal & General, LinkedIn, Microsoft, PepsiCo, Qualcomm, RWE, Samsung, Siemens AG and Siemens Energy, T-Mobile, UBS, VISA, Walmart, Workday, Worldpay and many others.

Regularly featured in the global media including the AP, BBC, Bloomberg, CNBC, Discovery, Forbes, Khaleej Times, Telegraph, TIME, ViacomCBS, WIRED, and the WSJ, Matthews mission is to help organisations create a fair and sustainable future whose benefits are shared by everyone irrespective of their ability, background, or circumstances.

What future do you need to see?

Choose one to get started on security and privacy and the future of your organisation.

Where should Matthew reply?

Takes 30 seconds. No obligation. Matthew replies quickly. Privacy

Tag Cloud

Sources and further reading

  1. Chaos Computer Club ccc.de
  2. Princeton Identity princetonidentity.com

Source: first published by the 311 Institute on 8 June 2017. Cite as: Griffin, M. (2017). Hackers have found a new way to hack Samsung’s iris security system. 311 Institute. https://www.311institute.com/hackers-have-found-a-new-way-to-hack-biometric-iris-security-systems/

You are welcome to quote this article with credit and a link to the original.

Book a Keynote