Your fingerprints can be lifted from photos. Here's what to actually do about it.
1. Be mindful of hand photos. high-resolution photos of your fingertips at close range are the risk. a normal selfie or group photo is not. The concern is clear: close shots of your fingers, peace signs, hands holding items, and typing shots.
2. Don't rely on fingerprint authentication alone for high-stakes accounts. Use a strong PIN or password as your primary unlock method. fingerprint as convenience, not as your only lock.
3. Use a passkey or hardware security key for your most sensitive accounts. These cannot be spoofed from a photo.
4. For banking apps: enable a secondary PIN in addition to biometric. Most banking apps support this. Use it.
5. Know your threat model. For most people, a spoofed fingerprint attack requires physical access to your device afterward. The photo gets the print. The attacker still needs to be holding your phone. If you're not a high-value target, your risk is low.
If you are a high-value target:
Disable fingerprint authentication entirely on your most sensitive devices. Use a long alphanumeric PIN. Assume any high-resolution photo of your hands is a liability.
Your fingerprint is the one password you can never change.
treat it accordingly.
Scam Wednesday
QR codes aren't automatically safe.
Attackers can place malicious QR codes over legitimate ones.
Before entering credentials or payment details:
• Check the website address
• Verify the source
• Be cautious of QR codes in public places
A QR code is just a shortcut to a link.