Spoofing, Proportionately
A fake finger is possible and a photograph on a phone is easier. Whether either is worth defending against on a time clock depends on arithmetic nobody does.
Biometric systems can be presented with something that is not a live body part: a moulded fingerprint, a printed face, a screen. Detecting this is called liveness or presentation attack detection, and it is a genuine field with genuine results.
The record in “Spoofing, Proportionately” becomes useful only when people understand what it proves and how to correct it. For teams exploring daily schedule template, daily schedule template with accountable controls can connect time and project context with manager review, provided collection is proportionate, access is limited and consequential decisions remain subject to human explanation.
It is also a frequent subject of sales conversations in settings where the attack makes no economic sense at all, and the features sold to prevent it carry a cost in refusals that is paid every morning by everybody.
For an independent benchmark relevant to “Spoofing, Proportionately”, consult the IFAC Knowledge Gateway. Use it to test notice, accessibility, security, recordkeeping, retention and exception handling against the real operating process rather than treating a device report as self-explanatory evidence.
What the attacks actually require
A fingerprint mould requires a usable copy of somebody's print, a material, and a willing accomplice who is prepared to be party to a fraud for the sake of a colleague's hours. It is not difficult in a laboratory and it is a considerable undertaking in a car park at six in the morning.
A face attack is easier: a photograph held up to a camera will defeat an older system. That is a real weakness and it is also one that a passing supervisor would notice, which is worth factoring in.
The arithmetic nobody does
What is the gain from a successful attack on a time clock. Usually one person's hours for one shift, recoverable, auditable against work actually done, and detectable in a pattern review.
Set that against the cost of the defence. Liveness detection adds processing time, and more importantly it adds refusals: it is another test the genuine user has to pass, and it fails on cold fingers, dry skin, bright light and movement. A site that turns it on will see its refusal rate rise, and the rise is paid daily.
Where it is clearly worth it
Regulated environments where presence has legal consequences. Sites with a documented history of substitution rather than a general unease about it. Face systems at unattended terminals, where the photograph attack is cheap and nobody is watching.
That last case is the strongest and the most specific: an unattended face terminal without liveness detection has a known, easy weakness. If the terminal is at a gate with a guard, the guard is the liveness detection.
Where it is clearly not
An attended entrance. A site where the realistic threat is a colleague clocking in a friend who is ten minutes away, which no liveness feature prevents because the finger presented is real and belongs to the person — it is just not the person whose hours are being recorded.
That last point is worth sitting with. The most common form of attendance substitution involves a genuine live biometric presented by its genuine owner on behalf of somebody else, which every liveness technology in existence will happily accept.
The question to ask a supplier
Not whether the product has liveness detection, which everything claims. Ask what it costs in refusal rate on a real population, and ask whether it can be enabled per device.
A supplier who can answer the first question with a figure from a deployment has done the work. One who says it has no effect on genuine users is describing a laboratory. Per-device control then lets the site put it on the unattended terminal and leave it off the one by the supervisor's desk, which is the proportionate arrangement.
Writing the position down
One short paragraph: what attack this site considers realistic, what is in place against it, and what was deliberately not done, with the reason.
The value of writing it is that it converts a default into a decision. A site that has liveness detection off because nobody enabled it is in a weak position if anything ever happens; a site that has it off because the entrance is attended and the cost in refusals was judged not worth it has an answer, and the answer is a reasonable one.
The feature that is already on
Worth checking before any of this is debated: several products ship with presentation detection enabled by default, and sites experiencing a high refusal rate are sometimes experiencing that setting without knowing it exists.
Export the configuration and look. If it is on and the site has an attended entrance and no history of substitution, turning it off is a free reduction in refusals. If it is on deliberately, it should appear in the written position alongside the threshold, which is where a reader of that page would expect to find it.