CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
biometrics

Biometric Verification vs Biometrics: Facial Recognition Catches 326 Fake IDs

biometric verification skin appear too smooth close-up of MyKad card with QR code and chip under scanner light
Malaysia's redesigned MyKad shows off its biometric QR code and embedded chip under scanner light. Illustration: CaraComp

Here's a number that should stop you mid-scroll: between 2021 and August 2025, Malaysian authorities arrested people in 795 separate National Registration Department fraud cases. Of those, 326 involved counterfeit or misused ID cards. That's not a rounding error. That's roughly one in three fraud cases where a fake or stolen card looked real enough to get through the door. These cases show why biometric verification requires more than a card that scans successfully, and why biometric authentication depends on more than one working part.

TL;DR: Biometric verification requires three separate steps, reading a credential, validating it hasn't been altered, and matching the person to their stored data, and a QR code on an ID card only ever completes step one.

TL;DR

Biometric verification means confirming a code, checking it's legitimate, and matching the actual person, all three, not just a successful scan.

Malaysia just rolled out a redesigned MyKad, the national ID card every citizen carries, and it's a genuinely interesting case study for a mistake almost everybody makes without realizing it. The new card has 53 physical security features, up from 23 on the old one. Holograms. Microtext you need a magnifier to read. Laser engraving. Ultraviolet ink that only shows under special light. And a QR code that, here's the twist, your phone camera can't even read. It's restricted to certified enforcement devices only.

Sounds like Fort Knox, right? Except that restricted-access QR code is exactly where the misunderstanding starts. A lot of people, including some who should know better, assume that if a QR code scans successfully on a special device, the identity behind it has been verified. It hasn't. Not even close. And understanding why is the kind of thing that makes you look at every ID check you've ever had for the rest of your life a little differently.

Biometric Identification, Biometrics, and Biometric Authentication: What a QR Scan Isn't

Biometric verification is the process of confirming that a real, physical person matches biological data that's already on file, things like a face, a fingerprint, or an iris pattern (the colored ring around your pupil, which turns out to be as unique as a fingerprint). Biometrics like these work because a person can be uniquely identified from physical traits that are extremely hard to copy, since a person's identity using unique physical traits is much harder to forge than a printed surface. It's not a single action. It's a sequence. And the Malaysia MyKad rollout happens to lay that sequence out in public, almost like a diagram, if you know what to look for.

Think about what actually happens when an officer scans that new MyKad QR code. The scanner reads the data encoded in the little black-and-white grid. That's it. That's the whole action. It's the digital equivalent of opening an envelope and reading the letter inside. You now know what the letter says. You do not yet know if the letter is real, if someone tampered with it, or if the person handing it to you is the person named in it.

That's the gap. And according to Biometric Update, Malaysia's redesign is built specifically to close it, by layering the QR code together with an embedded chip, stronger encryption, and biometric electronic Know Your Customer (eKYC) capability, meaning the system can pull up your stored facial data and compare it live to the face standing in front of the officer. The QR code doesn't do that job. The face match does, and this facial recognition step is what turns a readable card into confirmed biometric identity verification for the customer standing at the counter. This article is part of a series, start with Age Verification Roblox 31 Lawsuits Test Section 230.

326
counterfeit or misused ID cards found among 795 fraud arrests, Malaysia, 2021 to August 2025
Source: Malaysian National Registration Department, via Biometric Update

Biometric Verification Steps: The Three Jobs Nobody Talks About

Security researchers who study Three-Factor Authentication (a system where you need three separate proofs before access is granted) describe it as sequential and independent. Each factor gets checked on its own. If any single one fails, the whole thing fails, no exceptions, no partial credit. Apply that same logic to an ID card and you get three distinct jobs, and a QR code scan only ever completes the first.

Job one: read the credential. The scanner extracts whatever data is packed into the code. Name, ID number, maybe a photo reference. This step answers exactly one question: can the code be read? It says nothing about whether the data is current, unaltered, or attached to a real person standing nearby.

Job two: validate the credential. This is where the system checks the code against the issuer, meaning it confirms the data hasn't been faked, edited, or copied from a legitimate card onto a fraudulent one. Malaysia's MyKad uses a standardized specification (sometimes referenced as MOSIP Claim 169) that supports this kind of offline validation, even without a live internet connection to a government database. That's clever engineering. It's also easy to mistake for the finish line, when it's really just the middle step.

Job three: match the holder. The person in front of you gets compared to the biometric record on file, usually a face, sometimes a fingerprint, and this comparison is what document verification and identity verification actually rely on. This is the step that actually answers the question everyone assumes the QR scan already answered: is this person who the card says they are, and it depends on biometric authentication working correctly every single time.


Digital Authentication and Identity Authentication: Why Malaysia's Restricted QR Code Creates a False Sense of Security

Here's where it gets interesting, and a little counterintuitive. You'd think making a QR code harder to scan, restricting it to certified enforcement equipment instead of any old smartphone, would make people trust it more. And it does. That's precisely the problem. The restriction feels like proof that something serious happened during the scan. In reality, restricting access just controls who can read the data. It doesn't upgrade what reading the data proves, and it doesn't perform identity authentication on its own, no matter how secure the digital encryption behind it looks on paper.

This is the misconception at the center of the whole story: people assume a scan that "worked" on a special device must have done something extra, some invisible verification magic, simply because regular people can't do it. But a locked door isn't the same as a security guard checking your ID at the door. One controls access. The other confirms identity. Malaysia's restricted QR code is the locked door. The biometric eKYC face match is the guard, and this face match is a form of facial verification built into the broader identity verification chain.

It's an easy trap to fall into, honestly. We're conditioned by years of tapping cards at checkout counters and scanning boarding passes to associate "beep, it worked" with "verified, you're good." Most of the time that shortcut is harmless for the individual user involved. But identity systems are exactly the place where the shortcut breaks, because the whole point of a fake ID is to make the beep happen while the person behind the counter is not who the card says. Even liveness detection, which checks that a real live face is present rather than a photo or video, can't help if nobody runs it in the first place, and liveness detection matters just as much for a still photo as it does for video footage. A secure system needs all three jobs running, not just the one that happens to beep.

A QR code scan starts the authentication process, but the user still needs a trusted device, an active account session, a biometric check, or another form of proof to validate identity, the QR code is only one part of the process. Previously in this series: Uk Age Verification Pubs Now Legal To Take Phone Id Podcast.

summarized from research compiled by QR Code Generator

Malaysia MyKad Biometric QR: A Package, Not a Guarantee

Picture a sealed package left on your porch. The seal tells you something was packaged, and if the seal is intact, you know it hasn't been opened since it left the warehouse. But the seal says absolutely nothing about whether the contents match the label, and it says nothing about whether you're the intended recipient. Opening the box and checking what's inside, that's a separate action from checking the seal. Malaysia's MyKad QR code is the seal. Biometric verification is opening the box and confirming the contents belong to the person holding it, confirming a person's identity using unique physical traits rather than a printed label.

This is why treating "the QR code scanned" as the end of the story is like trusting a delivery just because the tape wasn't cut. Technically true, practically incomplete. A secure identity check needs the box opened, every single time.


What a QR code scan provesWhat biometric verification provesStatus
The credential can be read by a deviceThe credential was issued by a legitimate authorityReading only, not secure on its own
Data extraction succeededData has not been altered since issuance, confirmed through digital signature checksValidation step, biometric data untouched
The card format is recognizedThe face or fingerprint on record matches the person present, using facial recognition or fingerprint verificationBiometric authentication complete
Access was granted to view stored dataIdentity is actually confirmed, not just displayed, satisfying secure customer verification standardsFully verified and secure
Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

Biometric Recognition in Practice: How Fingerprints and Facial Detection Make Biometric Verification Work When It's Done Right

So what does a complete check actually look like, step by step, when nobody skips a stage? First, the scan. A device reads whatever's encoded, the QR data, the chip data, whatever format the card uses. Second, validation. The system checks that data against the issuing authority, confirming the credential is genuine and hasn't been tampered with, sometimes doing this offline through pre-loaded cryptographic signatures, sometimes by pinging a government database live. Third, the biometric match. A camera or scanner captures the live face or fingerprint of the individual present and compares it against the stored template tied to that credential, using biometric recognition software tuned for accuracy under real-world lighting and angles, often combining facial detection with fingerprint checks for a stronger result.

Every one of those three steps can fail independently, which is exactly what makes fraud possible even with Malaysia's redesigned MyKad. A stolen but genuine card passes step one and step two easily, it's a real card with real data. It only fails at step three, when the face doesn't match. The 326 counterfeit and misused card cases show why a readable or genuine card cannot by itself establish that the holder is the registered person, and why fingerprint verification and facial checks, including basic facial detection, both matter as backups to a simple document scan.

What You Just Learned About Biometric Verification

  • 🧠 A scan reads, it doesn't verify, extracting data is a completely different action from confirming that data is genuine
  • 🔬 Validation checks the issuer, confirming the credential itself hasn't been altered or faked, separate from reading it
  • 💡 Matching checks the human, comparing the live person to the biometric record on file is the step that actually confirms identity through biometric identity verification
  • 🔐 Restricted access isn't the same as verified, a scanner only certified devices can use still just performs step one

This is a big part of what we focus on when we talk about facial recognition systems at CaraComp: the interesting engineering problem was never getting a scanner to read a code fast. It's building the third step, the live comparison between a face and a stored template using biometric data, with enough accuracy and spoof resistance to work quickly at a checkpoint. That third step is where the system determines whether the cardholder and the record match, and it's the same digital comparison logic that powers biometric authentication in banking apps, phones, and workplace security systems that rely on a person's facial data, fingerprints, or other unique markers to keep every user's account secure.

Biometric Data and Biometric Verification Systems in Everyday Places, Not Just Airports

This three-step logic shows up everywhere once you start noticing it, banking apps that ask for a selfie after you type your password, phone unlock features, workplace badge systems. Anywhere someone says "we verify identity," ask yourself which of the three jobs they're actually describing. Usually it's job one. Sometimes job two. The full stack, all three, together, that compares biometric data against a stored record and confirms security at every step, is rarer than the marketing suggests, and every user deserves to know which level of check they actually got.


Key Takeaway

Biometric verification is not a single beep or scan, it's three separate checks stacked on top of each other, reading, validating, and matching, and the Malaysia MyKad biometric QR rollout proves that even a card with 53 security features can be reduced to a rubber stamp if only the first step ever gets done. Up next: Age Verification Roblox 31 Lawsuits Test Section 230 Podcast.

So here's the question worth sitting with the next time someone hands you an ID and it scans without a hitch. Did that beep actually confirm anything about the human in front of you, or did it just confirm the plastic in their hand? Malaysia built a card with holograms, microtext, laser engraving, and a QR code so restricted your own phone can't even open it, and the fraud numbers still show a third of cases getting through on cards that scanned just fine. The card was never the weak point. The assumption that scanning equals verifying, that's the weak point, and it's sitting in your pocket right now every time you hand someone your license and expect them to actually be checking your identity using unique physical traits, not just a plastic surface.

Biometric Verification, Biometric Authentication, and Video: Frequently Asked Questions

What is the difference between biometric verification and biometric identification?

Verification confirms a one-to-one match, is this person the specific individual their ID claims they are, like comparing a live face to the single photo stored on a MyKad. Identification is one-to-many, searching a whole database to figure out who an unknown person is using biometric identification techniques, facial recognition, and stored biometric data. Malaysia's biometric eKYC feature is verification, matching a presented card to a known face through biometric authentication, not scanning crowds or video footage to identify strangers.

Can a QR code on an ID card be faked or copied?

Yes, if the code is only being read and not validated against the issuing authority. A photocopied or digitally cloned QR code can still produce readable data when scanned, whether from a printed image or a video recording of the original. That's why validation, checking the code's cryptographic signature or database record against the original issuer, matters just as much as the scan itself. Reading alone cannot tell a genuine code from a well-made copy, which is exactly why secure biometric verification adds the extra digital layer a QR code cannot provide on its own.

Why does Malaysia's new MyKad restrict QR code scanning to special devices?

Restricting the QR code to certified enforcement equipment limits who can pull the encoded data, reducing casual misuse or copying by ordinary smartphone apps. But restriction only controls access to the reading step. It does not add validation or biometric matching on its own, those still have to happen separately through the card's chip and the eKYC facial comparison system, which relies on biometric authentication rather than the QR code alone, giving the customer a genuinely secure result only once all three steps run.

Does a QR code scan mean someone's identity has been confirmed?

No. A successful scan only proves the code could be read and the data extracted, nothing more. Confirming identity requires two more separate steps, checking that the credential itself hasn't been altered or faked, and matching the person physically present against a stored biometric record like a photo or fingerprint using facial verification, facial detection, or fingerprint verification. Skipping either of those steps leaves identity technically unverified even if the scan worked perfectly.

What happens if a stolen ID card passes the QR scan and validation steps?

A stolen but genuine card will usually pass both the reading and validation steps without any problem, since the card itself is authentic and unaltered. It only gets caught at the third step, biometric matching, when the live face or fingerprint of the person presenting it fails to match the record on file, a job liveness detection helps confirm by ruling out photos or recorded video. This is likely why a portion of Malaysia's 326 counterfeit and misused card cases involved cards that scanned fine despite lacking real biometric recognition at the final step.

Is offline biometric verification as secure as online verification?

Offline systems, like the MOSIP-style specification supporting Malaysia's MyKad, can validate a credential without an internet connection by checking pre-loaded cryptographic signatures. This is convenient in areas with poor connectivity, but it means the system can't check a live government database for card revocations or updates in real time. It still requires a separate biometric match step, backed by identity authentication and solid security practices, to confirm the holder and keep the individual's data secure, offline or online.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search