Live data from Hacker News

Smartphones can be fooled by fake, digitally composed fingerprints

nytimes.com

51–60 of 114 posts

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#51

I shouldn't be surprised, but the reporting on this makes it sound way different than the actual research. Specifically, none of the research appears to have been performed on, or tested against ACTUAL SMARTPHONE implementations - for example: "Experiments on a capacitive fingerprint dataset, similar to the one used by Apple TouchID, showed that it is possible to break 6.88% of users’ account in 5 attempts if the FMR…

I understand it's difficult to test against the actual Touch ID, since it has aggressive hardware-enforced cooldowns and other defensive tech.

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#52

I shouldn't be surprised, but the reporting on this makes it sound way different than the actual research. Specifically, none of the research appears to have been performed on, or tested against ACTUAL SMARTPHONE implementations - for example: "Experiments on a capacitive fingerprint dataset, similar to the one used by Apple TouchID, showed that it is possible to break 6.88% of users’ account in 5 attempts if the FMR…

>I shouldn't be surprised, but the reporting on this makes it sound way different than the actual research. Specifically, none of the research appears to have been performed on, or tested against ACTUAL SMARTPHONE implementations

That is exactly what the article says. Specifically:

The researchers did not test their approach with real phones, and other security experts said the match rate would be significantly lower in real-life conditions.

and

“To really know what the impact would be on a cellphone, you’d have to try it on the cellphone,” she said.

and

Dr. Ross acknowledged the limitations of the work.

Half of the article is about the limitations of the approach the paper used, so I fail to understand your criticism of the reporting.

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#53

I shouldn't be surprised, but the reporting on this makes it sound way different than the actual research. Specifically, none of the research appears to have been performed on, or tested against ACTUAL SMARTPHONE implementations - for example: "Experiments on a capacitive fingerprint dataset, similar to the one used by Apple TouchID, showed that it is possible to break 6.88% of users’ account in 5 attempts if the FMR…

>It seems that using commercial fingerprint software and captive systems 'similar to the one used by Apple TouchID' is very different from actually testing your theories against, you know, Apple TouchID.

In theory, there's no difference between theory in practice; In practice, there is. ;]

OTOH, Here is a supposed example of an attacker circumventing TouchID iPhone-access controls: "The video shows in detail how CCC member "Starbug" managed to fool the Touch ID sensor of Apple's new iPhone 5s – using only a scanner, tracing paper, a pcb and wood glue." [1]

https://www.heise.de/video/artikel/iPhone-5s-Touch-ID-hack-i...

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#54
post #51

I shouldn't be surprised, but the reporting on this makes it sound way different than the actual research. Specifically, none of the research appears to have been performed on, or tested against ACTUAL SMARTPHONE implementations - for example: "Experiments on a capacitive fingerprint dataset, similar to the one used by Apple TouchID, showed that it is possible to break 6.88% of users’ account in 5 attempts if the FMR…

I understand it's difficult to test against the actual Touch ID, since it has aggressive hardware-enforced cooldowns and other defensive tech.

So it's a lock that's too hard to pick to prove how easy it is to pick?

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#55

I shouldn't be surprised, but the reporting on this makes it sound way different than the actual research. Specifically, none of the research appears to have been performed on, or tested against ACTUAL SMARTPHONE implementations - for example: "Experiments on a capacitive fingerprint dataset, similar to the one used by Apple TouchID, showed that it is possible to break 6.88% of users’ account in 5 attempts if the FMR…

>It seems that using commercial fingerprint software and captive systems 'similar to the one used by Apple TouchID' is very different from actually testing your theories against, you know, Apple TouchID. In theory, there's no difference between theory in practice; In practice, there is. ;] OTOH, Here is a supposed example of an attacker circumventing TouchID iPhone-access controls: "The video shows in detail how CCC…

That hack uses lab conditions. They have a clear wine glass with a high resolution scanner.

More real-life conditions (smeared print, non-glass surface) would be interesting to reproduce.

My guess is that it ups the ante significantly for cost of hacking.

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#57
post #29

The phone is covered with fingerprints from the owner anyway. If you have the phone, you already have the "password". The fingerprint scan is just to make it a little bit annoying for attacker, so they'll factory reset instead of bothering to crack it. It's not intended for any kind of real security. Like many others here I never used to lock my phone at all until the fingerprint scan, and I don't consider the scan a…

> The phone is covered with fingerprints from the owner anyway. If you have the phone, you already have the "password".

This is a ridiculous assertion. On the front, I have an oleophobic screen and constantly wipe the phone (i.e., put in pocket). On the back I have a leather case that would be impossible to get prints from.

Do you know of any demonstration that isn't "lab conditions" where touchID is broken?

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#58
post #15

Earlier quoted context omitted.

First sentence: > The fact that the fingerprint sensors on smartphones are not quite as secure as the manufacturers want us to believe, has already emerged with the first iPhone with this feature. Ok, a bit awkward > The technique has improved since then, the methods to crack it but also turn. Uh, what? > And not with the means of the analog, but the digital world - via machine learning and an artificial intelligence…

In context, I think it (that specific bit) is fairly easy to follow: The technique has improved since then, the methods to crack it but also turn. The eternal cat and mouse game between team blue and team red. So, apparently the first sentence means that the technique has improved since then, but so have the methods trying to crack it. Though, to be fair, I have no clue what rumgeilt means and that was apparently jus…

>Die Technik hat sich seitdem zwar verbessert, die Methoden sie zu knacken aber wiederum auch.

Is what it was trying to translate, not sure where you/it got 'rumgeilt' from.

A more natural sounding translation would be:

The technology has improved since then, but, on the other hand, so have the methods to crack it

You could also translate 'wiederum' as 'in turn' which might exlain the 'turn' in Google's translation.

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#59

> "Dr. Memon said their findings indicated that if you could somehow create a magic glove with a MasterPrint on each finger, you could get into 40 to 50 percent of iPhones within the five tries allowed before the phone demands the numeric password, known as a personal identification number." I don't understand how this is possible at all. I've always assumed that each fingerprint is essentially turned into a hash, an…

>> "Dr. Memon said their findings indicated that if you could somehow create a magic glove with a MasterPrint on each finger, you could get into 40 to 50 percent of iPhones within the five tries allowed before the phone demands the numeric password, known as a personal identification number." >I don't understand how this is possible at all. You're confusing Sensitivity (also called the true positive rate), Specificit…

I think the point is that it recognizes their fingerprint, and doesn't mistake it for any of the 999 other users. If it can tell the differences between a thousand fingerprints, why can't it be sensitive enough to reject at least 999/1000 false fingerprints?

Think of it this way: What's the probability that one of the 5 master prints match their specific 1/1000 fingerprint, and not one of the other 999 customers? If you can distinguish between 1000 people, you should be able to distinguish a real from 999 fakes.

Post reply on HN