I shouldn't be surprised, but the reporting on this makes it sound way different than the actual research. Specifically, none of the research appears to have been performed on, or tested against ACTUAL SMARTPHONE implementations - for example: "Experiments on a capacitive fingerprint dataset, similar to the one used by Apple TouchID, showed that it is possible to break 6.88% of users’ account in 5 attempts if the FMR…
Smartphones can be fooled by fake, digitally composed fingerprints
51–60 of 114 posts
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#52I shouldn't be surprised, but the reporting on this makes it sound way different than the actual research. Specifically, none of the research appears to have been performed on, or tested against ACTUAL SMARTPHONE implementations - for example: "Experiments on a capacitive fingerprint dataset, similar to the one used by Apple TouchID, showed that it is possible to break 6.88% of users’ account in 5 attempts if the FMR…
That is exactly what the article says. Specifically:
The researchers did not test their approach with real phones, and other security experts said the match rate would be significantly lower in real-life conditions.
and
“To really know what the impact would be on a cellphone, you’d have to try it on the cellphone,” she said.
and
Dr. Ross acknowledged the limitations of the work.
Half of the article is about the limitations of the approach the paper used, so I fail to understand your criticism of the reporting.
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#53I shouldn't be surprised, but the reporting on this makes it sound way different than the actual research. Specifically, none of the research appears to have been performed on, or tested against ACTUAL SMARTPHONE implementations - for example: "Experiments on a capacitive fingerprint dataset, similar to the one used by Apple TouchID, showed that it is possible to break 6.88% of users’ account in 5 attempts if the FMR…
In theory, there's no difference between theory in practice; In practice, there is. ;]
OTOH, Here is a supposed example of an attacker circumventing TouchID iPhone-access controls: "The video shows in detail how CCC member "Starbug" managed to fool the Touch ID sensor of Apple's new iPhone 5s – using only a scanner, tracing paper, a pcb and wood glue." [1]
https://www.heise.de/video/artikel/iPhone-5s-Touch-ID-hack-i...
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#54I shouldn't be surprised, but the reporting on this makes it sound way different than the actual research. Specifically, none of the research appears to have been performed on, or tested against ACTUAL SMARTPHONE implementations - for example: "Experiments on a capacitive fingerprint dataset, similar to the one used by Apple TouchID, showed that it is possible to break 6.88% of users’ account in 5 attempts if the FMR…
I understand it's difficult to test against the actual Touch ID, since it has aggressive hardware-enforced cooldowns and other defensive tech.
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#55I shouldn't be surprised, but the reporting on this makes it sound way different than the actual research. Specifically, none of the research appears to have been performed on, or tested against ACTUAL SMARTPHONE implementations - for example: "Experiments on a capacitive fingerprint dataset, similar to the one used by Apple TouchID, showed that it is possible to break 6.88% of users’ account in 5 attempts if the FMR…
>It seems that using commercial fingerprint software and captive systems 'similar to the one used by Apple TouchID' is very different from actually testing your theories against, you know, Apple TouchID. In theory, there's no difference between theory in practice; In practice, there is. ;] OTOH, Here is a supposed example of an attacker circumventing TouchID iPhone-access controls: "The video shows in detail how CCC…
More real-life conditions (smeared print, non-glass surface) would be interesting to reproduce.
My guess is that it ups the ante significantly for cost of hacking.
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#56Re: Smartphones can be fooled by fake, digitally composed fingerprints
#57The phone is covered with fingerprints from the owner anyway. If you have the phone, you already have the "password". The fingerprint scan is just to make it a little bit annoying for attacker, so they'll factory reset instead of bothering to crack it. It's not intended for any kind of real security. Like many others here I never used to lock my phone at all until the fingerprint scan, and I don't consider the scan a…
This is a ridiculous assertion. On the front, I have an oleophobic screen and constantly wipe the phone (i.e., put in pocket). On the back I have a leather case that would be impossible to get prints from.
Do you know of any demonstration that isn't "lab conditions" where touchID is broken?
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#58Earlier quoted context omitted.
First sentence: > The fact that the fingerprint sensors on smartphones are not quite as secure as the manufacturers want us to believe, has already emerged with the first iPhone with this feature. Ok, a bit awkward > The technique has improved since then, the methods to crack it but also turn. Uh, what? > And not with the means of the analog, but the digital world - via machine learning and an artificial intelligence…
In context, I think it (that specific bit) is fairly easy to follow: The technique has improved since then, the methods to crack it but also turn. The eternal cat and mouse game between team blue and team red. So, apparently the first sentence means that the technique has improved since then, but so have the methods trying to crack it. Though, to be fair, I have no clue what rumgeilt means and that was apparently jus…
Is what it was trying to translate, not sure where you/it got 'rumgeilt' from.
A more natural sounding translation would be:
The technology has improved since then, but, on the other hand, so have the methods to crack it
You could also translate 'wiederum' as 'in turn' which might exlain the 'turn' in Google's translation.
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#59> "Dr. Memon said their findings indicated that if you could somehow create a magic glove with a MasterPrint on each finger, you could get into 40 to 50 percent of iPhones within the five tries allowed before the phone demands the numeric password, known as a personal identification number." I don't understand how this is possible at all. I've always assumed that each fingerprint is essentially turned into a hash, an…
>> "Dr. Memon said their findings indicated that if you could somehow create a magic glove with a MasterPrint on each finger, you could get into 40 to 50 percent of iPhones within the five tries allowed before the phone demands the numeric password, known as a personal identification number." >I don't understand how this is possible at all. You're confusing Sensitivity (also called the true positive rate), Specificit…
Think of it this way: What's the probability that one of the 5 master prints match their specific 1/1000 fingerprint, and not one of the other 999 customers? If you can distinguish between 1000 people, you should be able to distinguish a real from 999 fakes.