Live data from Hacker News

Understanding the ginormous Philippines data breach

troyhunt.com

81–90 of 93 posts

Re: Understanding the ginormous Philippines data breach

#81
post #13

Although this is a lot of data on each person. Each individual field doesn't seem too sensitive on its own. Electoral enrollment status and place you live is usually public information. It should be to prevent vote fraud. Without other ID, you give your passport details to every company that uses it for ID, every airline, even the bouncer at a bar. When you're travelling and don't have the local ID, you use it to get…

The Mormon church is really called the Church of Jesus Christ of Latter-day Saints (of which I'm a member). It sounds like you might be thinking of the affiliated, free genealogy site, http://www.familysearch.org. It doesn't disclose data on living persons. But you might really enjoy using it to look up your deceased ancestors. My wife loves it.

--

A free, fast emacs org-mode replacement which is easier to learn and lets you put the same thing in more than one place at the same time: "Atomic knowledge": http://onemodel.org .

Re: Understanding the ginormous Philippines data breach

#82
post #60
post #35

Earlier quoted context omitted.

It's not really about hacking Touch ID. Apple has published a really thorough whitepaper[0] on the security of Touch ID and the secure enclave. I don't really think that hacking the Secure Enclave to extract fingerprints is even possible. The problem I see is using fingerprints which are unique to your person, unchangeable, and spread around us in a very liberal fashion as passwords. Imagine for a second that the San…

Touch ID has been hacked in various ways - I think you can use a photo derived from someones hands and it's probably possible from fingerprints on the phone. Then again passwords can be grabbed, locks can be picked and so on. It would seem to me that what is effective in practice is what counts. I mean yeah for San Bernadino they probably would have got a fingerprint but they got the data anyway so does it matter?

Pretty sure the only time TouchID was hacked involved a lot of equipment and painstaking work to create a fake finger. A photo of someone's hands is almost certainly insufficient.

In other words, citation needed.

Re: Understanding the ginormous Philippines data breach

#83
post #13

Although this is a lot of data on each person. Each individual field doesn't seem too sensitive on its own. Electoral enrollment status and place you live is usually public information. It should be to prevent vote fraud. Without other ID, you give your passport details to every company that uses it for ID, every airline, even the bouncer at a bar. When you're travelling and don't have the local ID, you use it to get…

The LDS church "hoards" it for a reason. Genealogy and baptisms for the dead.

Re: Understanding the ginormous Philippines data breach

#84
post #55

> somehow, last week’s news that 55 million Filipino voters’ data was now out in the wild went largely unnoticed > ... > There’s voting history against names (it appears to just be dates rather than the candidate voted for). So, the data leaked was voter registration info. Actual votes were not in this database. Other headlines would lead a reader to believe actual votes were leaked. For example, "Megabreach: 55 MILL…

Aren't votes supposed to be anonymous?

Absolutely. My point was some headlines and articles made it sound like votes were disclosed, and you need to dig into the details to discover that's not the case.

Re: Understanding the ginormous Philippines data breach

#85
post #4

A friend of mine in the Philippines, a security researcher himself, said to me that "the breach itself isn't really serious -- it's the candidate the breach favors thats the bigger controversy"

I'm am sorry but what kind of security researcher can claim that this breach isn't serious? The electoral implications may be a bigger controversy but to suggest that the breach isn't serious it's insane. What is described in the post is nothing short of a nightmare scenario for anyone, no only security-conscious people.

Unfortunately, the government undervalues security and the work of its IT and CS departments. Lots of legacy code/databases and workers are underpaid(compared to the private sector).

Re: Understanding the ginormous Philippines data breach

#86
post #4

A friend of mine in the Philippines, a security researcher himself, said to me that "the breach itself isn't really serious -- it's the candidate the breach favors thats the bigger controversy"

I'm am sorry but what kind of security researcher can claim that this breach isn't serious? The electoral implications may be a bigger controversy but to suggest that the breach isn't serious it's insane. What is described in the post is nothing short of a nightmare scenario for anyone, no only security-conscious people.

I think the person was trying to imply that, in the Philippines, identify theft is less of a big deal than fraud voting.

Re: Understanding the ginormous Philippines data breach

#87
post #60

Earlier quoted context omitted.

Touch ID has been hacked in various ways - I think you can use a photo derived from someones hands and it's probably possible from fingerprints on the phone. Then again passwords can be grabbed, locks can be picked and so on. It would seem to me that what is effective in practice is what counts. I mean yeah for San Bernadino they probably would have got a fingerprint but they got the data anyway so does it matter?

Pretty sure the only time TouchID was hacked involved a lot of equipment and painstaking work to create a fake finger. A photo of someone's hands is almost certainly insufficient. In other words, citation needed.

TouchID isn't that great at identifying a real finger vs a fake. Someone was able to bypass it using only items that you could buy at a local radioshack and a laser printer within 48 hours after it was released.

http://www.heise.de/video/artikel/iPhone-5s-Touch-ID-hack-in...

I can't find it now but not long after that another group found an even simpler method of printing out a fake print, I did find a much more recent attack based on just using a special conductive ink cartridge in a regular inkjet to directly print something on paper that would work. Bottom line is that it doesn't take a lot of fancy equipment, supplies, or skills to print a fake fingerprint that will fool TouchID.

https://www.youtube.com/watch?v=fZJI_BrMZXU

As for "a photo derived from someones hands", I'm not sure what they meant but if you had a photo that could make out the ridges of someone's fingerprint then yeah absolutely.

Re: Understanding the ginormous Philippines data breach

#88
post #27

> As serious as the info above is, it’s only scratching the surface. Per the reports linked to earlier, there’s also biometric data relating to fingerprints in the system. This contains columns names such as these: > PRINT_FLAG, FINGER_INFO, FINGER_TOPO_COORD, QUALITY, MATCHING_FINGER > The values within there can be quite detailed and I’ve no reason to think that this isn’t indeed legitimate print data uniquely and…

The whole notion of using fingerprints for authentication is weird. Essentially something that's akin to a username is being used as a password. I've wrote about this practice the other day[0]. It's interesting to observe that when Apple announced Touch ID for example it was presented as something with improved security. 0: https://hugotunius.se/2016/04/11/why-i-disabled-touch-id-and...

Definitions can blur since biometric data can play more than one role.

A username can identify (but not authenticate) an individual, biometric data can do both, whereas a password is nothing by itself. It’s only meaningful in conjunction with an identifier as a shared secret in order to authenticate.

Re: Understanding the ginormous Philippines data breach

#89
post #80
post #34

Earlier quoted context omitted.

> Considering you need to provide fingerprints to request all sorts of documents, what would the government be able to do that they aren't already able now? If they already have fingerprints, and now fingerprints are suddenly required for voting, that makes election fraud easier for the government.

How does it make it easier than doing everything the same except not requiring fingerprints?

If you've convinced people that fingerprints prove a person was there and voted, then you have additional weight for your fraud.

Re: Understanding the ginormous Philippines data breach

#90

> As serious as the info above is, it’s only scratching the surface. Per the reports linked to earlier, there’s also biometric data relating to fingerprints in the system. This contains columns names such as these: > PRINT_FLAG, FINGER_INFO, FINGER_TOPO_COORD, QUALITY, MATCHING_FINGER > The values within there can be quite detailed and I’ve no reason to think that this isn’t indeed legitimate print data uniquely and…

They should keep a hash of the finger print info, not the info itself. I don't know how it would work, but keeping biometric data for authentification is indeed potentially worse than keeping plain text passwords.

Like, the output range of a convnet, or something.

Post reply on HN