A Geek With Guns

Chronicling the depravities of the State.

Your Fingerprint Sensor Sucks But You Shouldn’t Feel Bad

with 10 comments

Kai Kloepfer’s fingerpint based firearm access control system is back in the news:

Presented at the 2016 International San Francisco Smart Gun Symposium (ironic, considering the city shuttered its last gun shop in 2015), then 18-year-old Kai Kloepfer presented a new handgun design that incorporates a fingerprint reader. Young Mr. Kloepfer is sponsored by angel investor Ron Conway, who’s Smart Tech Challenges Foundation is spending $1.5 million for the development of “firearms safety technology.” Kloepfer is one of about 15 start-ups that Conway is sponsoring.

The design has been in skunk-works for over four years. Kloepfer’s start-up, Biofire, is “just a few months from a live-firing prototype, which assuming it works, will be the first gun to unlock like an iPhone.” This is untrue, as multiple finger-print reader base firearms have existed before, specifically Kodiak Industries with their Intelligun

Needless to say, the Internet gun community is flipping its shit again (in the comments sections of gun sites). A lot of valid criticisms have been made against Kloepfer’s technology. Some of those criticisms are the fact that his prototype isn’t lefthand friendly, people don’t always grip guns in the same way, fingerprint readers aren’t 100 percent reliable, batteries die, etc. I won’t go into detail on those. What I will go into detail on is the fact fingerprint sensors suck for access control.

As far back as 2013 the Chaos Computer Club (CCC) was bypassing Apple’s TouchID by obtaining a photograph of an authorized user’s fingerprint from a glass surface. No big deal, right? After all, somebody would have to find something you touched to lift your fingerprint from to bypass Kloepfer’s authentication system. That would require either breaking into your home or following you around in the hopes that you will touch something that your fingerprint can be reliably lifted from. Of course you also have the fact that in 2014 a member of the CCC was able to replicate a politician’s fingerprint from a photograph. You don’t need to follow somebody around to lift their fingerprint. You can just take a high resolution photograph of their hand when they’re out and about. And unlike Touch ID, which allows you to use any finger for authentication, the position of Kloepfer’s sensor means you know exactly what fingerprint you need to bypass the mechanism.

I’ve said this before but it bears repeating, fingerprints suck as authentication mechanisms. There are two reasons for this. First, you leave your fingerprints everywhere. Second, if your fingerprints are obtained by somebody you can’t change them.

With that said, I think criticisms against Kloepfer have been unnecessarily harsh. While his product is defective he should receive credit for trying to create something new. I know many gun owners like to scream “Never!” whenever somebody mentions firearm authentication systems but I believe there is a market for such products. Households with small children or mentally disturbed individuals, for example, could benefit from firearms with authentication systems (I know, people should lock up their firearms, but shit happens and having another barrier between a child or mentally disturbed individual and a functional firearm isn’t a bad thing). Kloepfer shouldn’t receive a bunch of hatred for exploring a market. And I say this as somebody who isn’t even in that market (I have no interest in complicating my firearms with access control technology but different strokes for different folks).

This is where some gun owner usually brings up New Jersey’s law that will mandate all firearms sold in the state be equipped with access control mechanisms once the technology is available. In response I will point out that the anger should be directed at the government of New Jersey, not Kloepfer and other people trying to bring access control technology to firearms. They’re building a product that may be useful to people even in the absence of such a law, they didn’t pass the law and aren’t sending goons out to enforce it.

In summary Kloepfer’s technology sucks but he shouldn’t feel bad for developing it. Also, governments suck but that’s more of a summary of this entire blog than this specific post.

Written by Christopher Burg

October 19th, 2016 at 10:30 am