Menu Close

FaceTec triples scope and payout in Spoof Bounty to thwart biometric liveness attacks

FaceTec has expanded its Spoof Bounty to both iOS and Android operating systems and tripled the total payouts available from $200,000 to $600,000 to help it identify potential vulnerabilities in biometric liveness detection.

Participants hunt for ways to defeat Facetec’s 3D Liveness software in real-world conditions, demonstrating and improving upon its security in real-world conditions, not just in the lab, the company says. Rewards are paid out for any spoof or camera bypass attack that beats the system.

The company informed Biometric Update that about 10,000 people have participated in the program, including professors, competitors, government agencies and hackers. Two $30,000 bounties were paid about two and a half years ago for Level 1 attacks.

They revealed that certain kinds of screens could pose a problem when manipulated in a certain way, so FaceTec retrained its neural network models to catch this particular attack. The company has also learned from unsuccessful attempts, mostly about the popularity of different attack methods.

“We put our AI to the test so that users of the FaceTec software can be shown – and not just told – just how secure FaceTec’s 3D Liveness Detection is,” says Kevin Alan Tussy, FaceTec CEO. “We don’t hide our product behind ‘Request A Demo’ forms. FaceTec stands behind its 3D Liveness software in a way that no 2D Liveness vendor will ever be able to replicate. After rebuffing more than 130,000 bounty program attacks over the last three years, we’ve learned a tremendous amount about potential threat vectors and how to stay ahead of them.”

The Spoof Bounty program operates at five levels, the first three covering spoof artefacts of increasing complexity, and the last two addressing bypasses. Level 4 is for decrypting and editing the contents of the 3D ‘FaceMap’ with synthetic data, while Level 5 is for successfully taking over the camera feed and injecting images, in each case leading to a Liveness Success response.

The program doubled in investment from $100,000 to $200,000 last year. FaceTec has expanded its Spoof Bounty to both iOS and Android operating systems and tripled the total payouts available from $200,000 to $600,000 to help it identify potential vulnerabilities in biometric liveness detection.

Participants hunt for ways to defeat Facetec’s 3D Liveness software in real-world conditions, demonstrating and improving upon its security in real-world conditions, not just in the lab, the company says. Rewards are paid out for any spoof or camera bypass attack that beats the system.

The company informed Biometric Update that about 10,000 people have participated in the program, including professors, competitors, government agencies and hackers. Two $30,000 bounties were paid about two and a half years ago for Level 1 attacks.

They revealed that certain kinds of screens could pose a problem when manipulated in a certain way, so FaceTec retrained its neural network models to catch this particular attack. The company has also learned from unsuccessful attempts, mostly about the popularity of different attack methods.

“We put our AI to the test so that users of the FaceTec software can be shown – and not just told – just how secure FaceTec’s 3D Liveness Detection is,” says Kevin Alan Tussy, FaceTec CEO. “We don’t hide our product behind ‘Request A Demo’ forms. FaceTec stands behind its 3D Liveness software in a way that no 2D Liveness vendor will ever be able to replicate. After rebuffing more than 130,000 bounty program attacks over the last three years, we’ve learned a tremendous amount about potential threat vectors and how to stay ahead of them.”

The Spoof Bounty program operates at five levels, the first three covering spoof artefacts of increasing complexity, and the last two addressing bypasses. Level 4 is for decrypting and editing the contents of the 3D ‘FaceMap’ with synthetic data, while Level 5 is for successfully taking over the camera feed and injecting images, in each case leading to a Liveness Success response.

The program doubled in investment from $100,000 to $200,000 last year.  Read More   

Generated by Feedzy

Disclaimer

Innov8 is owned and operated by Rolling Rock Ventures. The information on this website is for general information purposes only. Any information obtained from this website should be reviewed with appropriate parties if there is any concern about the details reported herein. Innov8 is not responsible for its contents, accuracies, and any inaccuracies. Nothing on this site should be construed as professional advice for any individual or situation. This website includes information and content from external sites that is attributed accordingly and is not the intellectual property of Innov8. All feeds ("RSS Feed") and/or their contents contain material which is derived in whole or in part from material supplied by third parties and is protected by national and international copyright and trademark laws. The Site processes all information automatically using automated software without any human intervention or screening. Therefore, the Site is not responsible for any (part) of this content. The copyright of the feeds', including pictures and graphics, and its content belongs to its author or publisher.  Views and statements expressed in the content do not necessarily reflect those of Innov8 or its staff. Care and due diligence has been taken to maintain the accuracy of the information provided on this website. However, neither Innov8 nor the owners, attorneys, management, editorial team or any writers or employees are responsible for its content, errors or any consequences arising from use of the information provided on this website. The Site may modify, suspend, or discontinue any aspect of the RSS Feed at any time, including, without limitation, the availability of any Site content.  The User agrees that all RSS Feeds and news articles are for personal use only and that the User may not resell, lease, license, assign, redistribute or otherwise transfer any portion of the RSS Feed without attribution to the Site and to its originating author. The Site does not represent or warrant that every action taken with regard to your account and related activities in connection with the RSS Feed, including, without limitation, the Site Content, will be lawful in any particular jurisdiction. It is incumbent upon the user to know the laws that pertain to you in your jurisdiction and act lawfully at all times when using the RSS Feed, including, without limitation, the Site Content.  

Close Bitnami banner
Bitnami