Live data from Hacker News

Understanding the ginormous Philippines data breach

troyhunt.com

51–60 of 93 posts

Re: Understanding the ginormous Philippines data breach

#51

> somehow, last week’s news that 55 million Filipino voters’ data was now out in the wild went largely unnoticed > ... > There’s voting history against names (it appears to just be dates rather than the candidate voted for). So, the data leaked was voter registration info. Actual votes were not in this database. Other headlines would lead a reader to believe actual votes were leaked. For example, "Megabreach: 55 MILL…

Maybe in principle, but I think most people would be more upset over personal details and biometric information than they would be over votes.

Yeah I guess people will be upset about what they want. My opinion is the actual votes would be worse. Such data could be used to force someone to vote a certain way, which usurps individuals' freedom of speech.

Any leaked biometric data becomes unusable as an authenticator in the future.

Re: Understanding the ginormous Philippines data breach

#52
post #44
post #27

Earlier quoted context omitted.

The whole notion of using fingerprints for authentication is weird. Essentially something that's akin to a username is being used as a password. I've wrote about this practice the other day[0]. It's interesting to observe that when Apple announced Touch ID for example it was presented as something with improved security. 0: https://hugotunius.se/2016/04/11/why-i-disabled-touch-id-and...

I think Touch ID does improve security in practice for most people, because it makes it practical to use a proper password for your phone, rather than a four-digit passcode or no passcode at all, as most people did before. You have to consider the limitations it has as well. An attacker could potentially lift your fingerprints and use it to unlock your phone. But they only get five chances to fool the sensor before T…

>it's something different from both, with its own unique properties.

No, it's a username that is physically tied to the user. If I can get that data (fingerprint) then I don't need to go through the usual rigmarole of password hacking.

Fingerprints are literally "one factor auth".

Re: Understanding the ginormous Philippines data breach

#54
post #44

Earlier quoted context omitted.

I think Touch ID does improve security in practice for most people, because it makes it practical to use a proper password for your phone, rather than a four-digit passcode or no passcode at all, as most people did before. You have to consider the limitations it has as well. An attacker could potentially lift your fingerprints and use it to unlock your phone. But they only get five chances to fool the sensor before T…

>it's something different from both, with its own unique properties. No, it's a username that is physically tied to the user. If I can get that data (fingerprint) then I don't need to go through the usual rigmarole of password hacking. Fingerprints are literally "one factor auth".

That doesn't mean that they're usernames. You can say this about passwords too: if you can get that data (password) then you don't need to go through password cracking, and they're literally "one factor auth."

Consider an example. Imagine if HN authenticated based only on the username. Could you get into my account? Now imagine if HN used fingerprint authentication. Would that make it harder?

Re: Understanding the ginormous Philippines data breach

#55

> somehow, last week’s news that 55 million Filipino voters’ data was now out in the wild went largely unnoticed > ... > There’s voting history against names (it appears to just be dates rather than the candidate voted for). So, the data leaked was voter registration info. Actual votes were not in this database. Other headlines would lead a reader to believe actual votes were leaked. For example, "Megabreach: 55 MILL…

Aren't votes supposed to be anonymous?

Re: Understanding the ginormous Philippines data breach

#56
post #40

Increasely wonder why average person trust any party to secure data that literally belongs to them. Are there any startups that are building tech allow end-to-end identity management systems? Seems like a huge market.

What choice do you have?

Re: Understanding the ginormous Philippines data breach

#57

Earlier quoted context omitted.

Touch ID is like a bike lock. It won't stop a sophisticated attacker, but it's enough to stop your coworkers from reading your messages, and it makes the phone worthless for thieves. The biggest advantage of Touch ID is that people who never had a passcode on their phone now use it.

Problem with passcodes on mobile phone is that you need enter them so often that shoulder surfing becomes a problem.

Thank you! Yes, absolutely. People need to learn the difference from "secure, in theory, in a perfect world" and "secure enough, in practice, in the real world". Just about every disagreement in this thread is from two people who are talking about two entirely different concepts of security.

Re: Understanding the ginormous Philippines data breach

#58
post #53

So if I ever traveled to Philippines and scanned fingerprints at the border, anyone in the world can unlock my TouchID?

They don't scan your finger prints at the border in the Philippines. And this is a leak of Filipino citizens' demographic data.

Re: Understanding the ginormous Philippines data breach

#60
post #35
post #33

Earlier quoted context omitted.

Though nothings perfect. Has anyone in practice managed to steal anything at all by hacking Touch ID?

It's not really about hacking Touch ID. Apple has published a really thorough whitepaper[0] on the security of Touch ID and the secure enclave. I don't really think that hacking the Secure Enclave to extract fingerprints is even possible. The problem I see is using fingerprints which are unique to your person, unchangeable, and spread around us in a very liberal fashion as passwords. Imagine for a second that the San…

Touch ID has been hacked in various ways - I think you can use a photo derived from someones hands and it's probably possible from fingerprints on the phone. Then again passwords can be grabbed, locks can be picked and so on. It would seem to me that what is effective in practice is what counts. I mean yeah for San Bernadino they probably would have got a fingerprint but they got the data anyway so does it matter?
Post reply on HN