Live data from Hacker News

Understanding the ginormous Philippines data breach

troyhunt.com

41–50 of 93 posts

Re: Understanding the ginormous Philippines data breach

#41

> somehow, last week’s news that 55 million Filipino voters’ data was now out in the wild went largely unnoticed > ... > There’s voting history against names (it appears to just be dates rather than the candidate voted for). So, the data leaked was voter registration info. Actual votes were not in this database. Other headlines would lead a reader to believe actual votes were leaked. For example, "Megabreach: 55 MILL…

Maybe in principle, but I think most people would be more upset over personal details and biometric information than they would be over votes.

Re: Understanding the ginormous Philippines data breach

#42
post #27

Earlier quoted context omitted.

The whole notion of using fingerprints for authentication is weird. Essentially something that's akin to a username is being used as a password. I've wrote about this practice the other day[0]. It's interesting to observe that when Apple announced Touch ID for example it was presented as something with improved security. 0: https://hugotunius.se/2016/04/11/why-i-disabled-touch-id-and...

Touch ID is like a bike lock. It won't stop a sophisticated attacker, but it's enough to stop your coworkers from reading your messages, and it makes the phone worthless for thieves. The biggest advantage of Touch ID is that people who never had a passcode on their phone now use it.

Problem with passcodes on mobile phone is that you need enter them so often that shoulder surfing becomes a problem.

Re: Understanding the ginormous Philippines data breach

#43
post #27

> As serious as the info above is, it’s only scratching the surface. Per the reports linked to earlier, there’s also biometric data relating to fingerprints in the system. This contains columns names such as these: > PRINT_FLAG, FINGER_INFO, FINGER_TOPO_COORD, QUALITY, MATCHING_FINGER > The values within there can be quite detailed and I’ve no reason to think that this isn’t indeed legitimate print data uniquely and…

The whole notion of using fingerprints for authentication is weird. Essentially something that's akin to a username is being used as a password. I've wrote about this practice the other day[0]. It's interesting to observe that when Apple announced Touch ID for example it was presented as something with improved security. 0: https://hugotunius.se/2016/04/11/why-i-disabled-touch-id-and...

As other responders pointed out, Touch ID is definitely an improvement over the status quo, and strikes a reasonable balance between security and convenience. But more relevant to the GP's point in re Touch ID is that Apple doesn't have a database anywhere of fingerprints, and the Secure Enclave is very difficult if not impossible to retrieve data from. In other words, this is biometric ID done as rightly as possible with today's technology.

Re: Understanding the ginormous Philippines data breach

#44
post #27

> As serious as the info above is, it’s only scratching the surface. Per the reports linked to earlier, there’s also biometric data relating to fingerprints in the system. This contains columns names such as these: > PRINT_FLAG, FINGER_INFO, FINGER_TOPO_COORD, QUALITY, MATCHING_FINGER > The values within there can be quite detailed and I’ve no reason to think that this isn’t indeed legitimate print data uniquely and…

The whole notion of using fingerprints for authentication is weird. Essentially something that's akin to a username is being used as a password. I've wrote about this practice the other day[0]. It's interesting to observe that when Apple announced Touch ID for example it was presented as something with improved security. 0: https://hugotunius.se/2016/04/11/why-i-disabled-touch-id-and...

I think Touch ID does improve security in practice for most people, because it makes it practical to use a proper password for your phone, rather than a four-digit passcode or no passcode at all, as most people did before.

You have to consider the limitations it has as well. An attacker could potentially lift your fingerprints and use it to unlock your phone. But they only get five chances to fool the sensor before Touch ID disables itself, and they have to do their work within 48 hours of when you last entered your password.

As with all things security, the important question is what sort of threats your defending against. For the scenario where I lose my phone or I get mugged, Touch ID is fine. If I'm defending against police seizing it as evidence, it's probably fine. I'd be surprised if the police could move quickly enough to make the deadline. For police encounters I know about ahead of time (like passing through customs), it's easy to shut the phone off to temporarily disable Touch ID. The only scenario where it likely fails is a targeted attack by someone with sophistication, like if the FBI thinks I'm a terrorist, and I'm not particularly worried about defending against that.

Note that your six-digit PIN doesn't necessarily save you here either, although it would buy time. Whatever the FBI did to the infamous San Bernardino iPhone would probably work on yours in a longer but practical amount of time.

People often say that fingerprints are usernames, not passwords. I don't think that's very useful. A fingerprint doesn't fit inside the old username/password ideas, it's something different from both, with its own unique properties.

Re: Understanding the ginormous Philippines data breach

#45
post #35
post #33

Earlier quoted context omitted.

Though nothings perfect. Has anyone in practice managed to steal anything at all by hacking Touch ID?

It's not really about hacking Touch ID. Apple has published a really thorough whitepaper[0] on the security of Touch ID and the secure enclave. I don't really think that hacking the Secure Enclave to extract fingerprints is even possible. The problem I see is using fingerprints which are unique to your person, unchangeable, and spread around us in a very liberal fashion as passwords. Imagine for a second that the San…

Do you think they would have figured all of that out before the phone disabled Touch ID at the 48-hour mark? I'm rather doubtful myself.

Re: Understanding the ginormous Philippines data breach

#46
post #44
post #27

Earlier quoted context omitted.

The whole notion of using fingerprints for authentication is weird. Essentially something that's akin to a username is being used as a password. I've wrote about this practice the other day[0]. It's interesting to observe that when Apple announced Touch ID for example it was presented as something with improved security. 0: https://hugotunius.se/2016/04/11/why-i-disabled-touch-id-and...

I think Touch ID does improve security in practice for most people, because it makes it practical to use a proper password for your phone, rather than a four-digit passcode or no passcode at all, as most people did before. You have to consider the limitations it has as well. An attacker could potentially lift your fingerprints and use it to unlock your phone. But they only get five chances to fool the sensor before T…

https://xkcd.com/538/

Re: Understanding the ginormous Philippines data breach

#47
post #27

Earlier quoted context omitted.

The whole notion of using fingerprints for authentication is weird. Essentially something that's akin to a username is being used as a password. I've wrote about this practice the other day[0]. It's interesting to observe that when Apple announced Touch ID for example it was presented as something with improved security. 0: https://hugotunius.se/2016/04/11/why-i-disabled-touch-id-and...

As other responders pointed out, Touch ID is definitely an improvement over the status quo, and strikes a reasonable balance between security and convenience. But more relevant to the GP's point in re Touch ID is that Apple doesn't have a database anywhere of fingerprints, and the Secure Enclave is very difficult if not impossible to retrieve data from. In other words, this is biometric ID done as rightly as possible…

I'm inclined to agree that it's an improvement over the status quo for people that didn't use passcodes from before.

I do trust Apple more than many other entities and as you say they don't have a database with fingerprints. Further the secure enclave is definitely a secure piece of engineering.

As evident by the linked article though the problem isn't Apple the problem is all the other databases that will have your fingerprints. As Troy says in the article

> The values within there can be quite detailed and I’ve no reason to think that this isn’t indeed legitimate print data uniquely and biologically identifying the owner. You don’t get to reset that stuff once it’s been released into the wild!

Once your fingerprints leak somehow there's no way to reset or change them. To me at least is seems like a really poor idea to use something with those properties as passwords.

Re: Understanding the ginormous Philippines data breach

#48
post #45
post #35

Earlier quoted context omitted.

It's not really about hacking Touch ID. Apple has published a really thorough whitepaper[0] on the security of Touch ID and the secure enclave. I don't really think that hacking the Secure Enclave to extract fingerprints is even possible. The problem I see is using fingerprints which are unique to your person, unchangeable, and spread around us in a very liberal fashion as passwords. Imagine for a second that the San…

Do you think they would have figured all of that out before the phone disabled Touch ID at the 48-hour mark? I'm rather doubtful myself.

You are right, that's an oversight of mine. Didn't keep the 48 hour thing in mind when writing that comment. My bad

Re: Understanding the ginormous Philippines data breach

#49
post #27

Earlier quoted context omitted.

The whole notion of using fingerprints for authentication is weird. Essentially something that's akin to a username is being used as a password. I've wrote about this practice the other day[0]. It's interesting to observe that when Apple announced Touch ID for example it was presented as something with improved security. 0: https://hugotunius.se/2016/04/11/why-i-disabled-touch-id-and...

Touch ID is like a bike lock. It won't stop a sophisticated attacker, but it's enough to stop your coworkers from reading your messages, and it makes the phone worthless for thieves. The biggest advantage of Touch ID is that people who never had a passcode on their phone now use it.

It doesn't on its own, but the secure enclave (that was created, in part, to keep biometrics data secured) sure does.

Re: Understanding the ginormous Philippines data breach

#50

Earlier quoted context omitted.

You can require biometrics and still not record them. Just use them as a hash lookup into a keystore. The biometric itself would only exist on the server for a few cycles while the key was being looked up. (Very similar to the way credit cards are done)

Just use them as a hash lookup into a keystore. This is intuitively appealing, but do biometrics really boil down to an exact number that we could hash like this? (Genuine questions; I don't know.) It seems more likely to me that biometric measurements would be considered to "match" when they're within particular tolerances. This is an operation you can perform on the original measurements, but not on hashes of those…

It is, effectively, what Touch ID does. (It's an over simplification but as an analogy it works)
Post reply on HN