Attackers cannot steal funds from Russians' bank accounts using a voice recording or facial image. This is technically impossible. The main security risks are related not to vulnerabilities in biometric systems, but to the human factor, Sber reported.
Fraudsters cannot steal money by recording the victim's voice (for example, the word "yes") or obtaining a facial image. A simple photo from the Internet does not give access to money and banking services. This is technically impossible for many reasons.
The bank reported that attackers will not be able to use this data in the banking system, since the bank works with vectors of the Unified Biometric System (UBS), which are stored in encrypted form.
In addition, to use biometric data, you must first register with the UBS. This can be done in person at a bank branch or other accredited organization, as well as through the "Gosuslugi Biometria" mobile application.
Even with a photo or voice recording, the system checks for Liveness (determines whether the person in front of it is alive). In addition, for critical or sensitive operations, an additional confirmation factor is always required (SMS, push, control word, etc.).
In addition, banks usually have additional levels of protection. For example, they can link accounts to devices to provide additional authentication when logging in from a new device for the first time, as the bank said.
The main security risks are due not to vulnerabilities in biometric systems, but to the human factor - cases of voluntary transfer of access to fraudsters through phishing or social engineering.
Earlier, Russians were warned that fraudstersare using a new tactic: they call victims and introduce themselves as employees of the Central Bank. The attackers offer to close the "international account", promising to transfer a large sum of money to it.
Read materials on the topic:
CB: Fraudsters began to use virtual images of their victims' bank cards
Pseudo-lawyers deceive Russians on forums for protection against fraud
Wireless headphones can become a tool for surveillance