Skip to content

CategoryEvent

Security Analysis of Facial Recognition SDKs for Mobile App (29 Apr 2024)

[QR: bit.ly/pisa240429]

Date: 29-Apr (Mon)
Time: 7:15pm – 8:30pm
Venue: HKU SPACE, ADC 314, 3/F, Admiralty Centre (海富中心), Admiralty
Language: Cantonese
Fee: FREE
Register: https://bit.ly/pisa240429 (PISA and supporting members only)

Highlight

Speaker:
Professor Wing C. Lau, Department of Information Engineering and the Director of the Mobile Technologies Centre (MobiTeC), The Chinese University of Hong Kong.

Abstract:
Mobile apps are embracing facial recognition technology to streamline the identity verification procedure for security-critical activities such as opening online bank accounts. To ensure the security of the system, liveness detection plays a vital role as an anti-spoofing component, verifying that a selfie provided is from a live individual. Emerging facial recognition companies offer convenient integration services through mobile Software Development Kits (SDKs) / libraries that are widely utilized by numerous apps in practice. By analyzing 18 mobile facial recognition SDKs in the market, we reveal the protocol design and implementation intricacies of various systems.

Our investigation leads to the discovery of several system security issues in over half of the libraries, predominantly linked to the liveness detection module. These vulnerabilities can be exploited for low-cost identity forgery attacks without relying on media synthesizing technologies like Deepfake. We scan over 18,000 apps from an app market and identify 800+ of them incorporating recognized facial recognition libraries, with over 100 million total downloads. More than half of the libraries under study exhibit weak security, with about 40% downstream mobile apps being affected. Our study emphasizes the importance of system security in mobile facial recognition services, as the practical impact can be on par with or even surpass the extensively studied Machine Learning-based attacks.

With this talk, we hope to draw the security community’s attention back on to the system security in the era of AI.

Biography:
Wing C. Lau is a Professor in the Department of Information Engineering and the Director of the Mobile Technologies Centre (MobiTeC) at The Chinese University of Hong Kong. Wing received his B.S.(Eng) degree from the University of Hong Kong and M.S. and Ph.D. degrees in Electrical and Computer Engineering from the University of Texas at Austin. Before returning to academia, Wing worked in the US industry for a decade. He was a Member of the Technical Staff with the Performance Analysis Department, Bell Laboratories, Holmdel, New Jersey, where he conducted research in high-speed networking protocols and systems. Wing also had a stint with Qualcomm, San Diego, California where he designed the architecture and protocols for Next Generation Wireless services and actively contributed to their standardization in the Internet Engineering Task Force (IETF) and 3GPPs. Wing holds 19 U.S. patents and his research findings have culminated in more than 130 publications in major international conferences and journals. His recent research interests include: Security and Privacy of Online Social Networks, Single-Sign-On protocols and Mobile Payment Systems; Graph Neural Networks and their applications; Online Machine Learning algorithms; Resource allocation and Optimization for Cloud Computing/ Big Data Processing Systems; High-capacity Authenticated 2D barcodes. Dr. Lau is/ has been a Technical Program Committee member of ACM Sigmetrics, MobiHoc, IEEE INFOCOM, SECON, WiOpt, ICC, GLOBECOM, WCNC, VTC and the International Teletraffic Congress, etc. He also served as a Guest Editor for the Special Issue on High-speed Network Security of IEEE Journal of Selected Areas in Communications (JSAC). For their work on Single-Sign-On SDK security, Wing and his team received the Internet Defense Prize from USENIX and Facebook in 2018.

For any question, please send an email to info@pisa.org.hk or send a message via m.me/pisahkg to seek our support, thanks.

Supporting Event: Build a Secure Cyberspace 2024 “Together, We Create a Safe Cyberworld” Tram Body Design Contest (15 Apr 2024)

Date: 15 Apr 2023 (Mon) submission deadline
Venue: Online
Fee: FREE
Register: https://form.jotform.me/hkcert/securecyberspace2024

Highlight:
The Tram Body Design Contest – “Together, We Create a Safe Cyberworld” (“the Contest”) is jointly organised by the Office of the Government Chief Information Officer, the Hong Kong Police Force and the Hong Kong Computer Emergency Response Team Coordination Centre. The Contest aims to arouse public awareness of cybersecurity, so as to prevent them from falling into online traps, and strengthen city-wide defence against cyberattacks. The winning entry may be adopted as a promotional advertisement displaying on trams.

Detail: https://www.cybersecurity.hk/en/contest-2024.php

Sangfor Visit (2 Dec 2023)

Date: 2-Dec (Sat)
Time: 9:00am – 3:00pm
Venue: 深信服科技股份有限公司深圳總部 / 紅磡站出發
Language: 所有講者皆以普通話講解
Fee: FREE (HK$100 for deposit)
Register: https://forms.gle/pzrWNw2RyBbUUFwTA (priority for PISA members)

Highlight

網絡攻防交流團-訪問深信服科技股份有限公司深圳總部
主辦單位 : Sangfor (深信服), PISA, HK CTF Association
出團日期 : 2023年12月2日(星期六)
集合時間 : 2023年12月2日(星期六)早上9時正
集合地點 : 紅磡站(*** 需確認持有有效旅行證件 ***
語言:所有講者皆以普通話講解
費用:全免(需繳付港幣100元按金)
出席人數:約20人,會員優先,先到先得。(PISA保留最終決定權)

行程
09:00 紅磡站上旅遊車 (經深圳灣口岸)
10:30 到達深信服深圳總部
10:30 – 11:30 公司參觀及介紹
11:30 – 12:30 攻防、IR服務
12:30 – 14:00 午飯
14:00 – 15:00 Sangfor XDR+GPT
15:00 回港(經深圳灣口岸到紅磡站 或 自行回港)

費用安排
行程費用全免。需於11月25日前繳付港幣100元按金(合資格參加者將被加入 WhatsApp 群組,並收取進一步付款方法通知),於12月2日登上旅遊車後退回全數按金;缺席者將不獲發還。(缺席者之按金將歸入PISA賬目。)

聲明
是次交流活動只屬結伴同行,主辦單位只負責聯絡工作,本行程之參加者應對自身及財物之安全負責,主辦單位不負上有關是次行程之任何責任及並不會作出任何之賠償。凡參加上述網絡攻防交流團者,即自動同意本項聲明,不得異議。建議各參加者自行購買適合之旅遊保險。

For any question, please send an email to info@pisa.org.hk or send a message via m.me/pisahkg to seek our support, thanks.

Hong Kong Cyber Security New Generation Capture the Flag Challenge 2023 Seminar & Award Presentation Ceremony (19 Dec 2023)

Date: 19 Dec 2023 (Tue)
Time: 09:15 – 17:00 HKT
Venue: Conference Hall, 4/F, HKPC Building, 78 Tat Chee Avenue, Kowloon Tong
Language: Cantonese
Fee: FREE
Register: https://alt.jotfor.ms/hkcert/capture-the-flag-2023-seminar231219

Highlight:

HKPC and HKCERT, and PISA as one of the Co-organisers, organised the “Capture the Flag (CTF) Challenge 2023” (the “Programme”), in November with seven information security organisations. The Programme aims to raise security awareness of the education sector and the public. Through a challenging competition, the CTF tries to stimulate proactive learning of cyber security skills and encourage problem solving and creative thinking among students and information security practitioners. ​

The award presentation ceremony will be held on 19 December 2023. Apart from presenting the awards to the winners, cyber security experts will also be on hand to share their views on cyber security and how to leverage vulnerability management solutions to improve security and security risk management. Besides, there will be two panel discussions on attack and defense techniques.​

Detail: https://www.hkcert.org/event/hong-kong-cyber-security-new-generation-capture-the-flag-challenge-2023-seminar-and-award-presentation-ceremony

Supporting Event: The 6th CISO Executive Summit 2023 (7 Dec 2023)

Date: 7 Dec 2023 (Thur)
Time: 10:00 – 16:15 HKT
Venue: Cordis Hotel @ Langham Place
Fee: Complimentary registration is only applicable to first 150 Senior Executives from end user side. A fee of USD850 would be charged otherwise.
Register: https://form.mig-events.com/ciso2023/

Highlight:

We are in a new era of cyberattacks with massive social, business & economic impacts and ramification. All are happening at a time of rapid digital adoption exposing more attack surfaces and vulnerability to cyber threat actors. On the other hand, as enterprises are becoming more fragmented and inter-dependent in the post pandemic digital world, CISOs and cybersecurity leaders have less control over decisions around cyber risk than ever before. How can modern CISOs navigate through these challenges and stay secure and compliant?

Carrying the theme of “Prevent, Detect, Respond – The Rhythm of Global Security” this year, the 6th CISO Executive Summit will provide answer to these. Bringing together 150+ Enterprises CISOs, IT and Network Security leaders and decision makers across industries, this premier event will provide visibility to the latest threat landscapes, cyber risk intelligence and cybersecurity capabilities, and provide the opportunity for CISOs meet with their peers and discuss proactive strategies to manage risk, address the evolving cyber threats, and discover new and innovative solutions for Cyber Security. The summit features Visionary Keynote Presentations, Thought Leadership sessions and Experts Sharing on the future cybersecurity imperatives and address Tomorrow’s Top CISO Challenges.

Detail: https://www.mighkevents.com/ciso2023