Live data from Hacker News

Smartphones can be fooled by fake, digitally composed fingerprints

nytimes.com

71–80 of 114 posts

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#71
post #55

Earlier quoted context omitted.

>It seems that using commercial fingerprint software and captive systems 'similar to the one used by Apple TouchID' is very different from actually testing your theories against, you know, Apple TouchID. In theory, there's no difference between theory in practice; In practice, there is. ;] OTOH, Here is a supposed example of an attacker circumventing TouchID iPhone-access controls: "The video shows in detail how CCC…

That hack uses lab conditions. They have a clear wine glass with a high resolution scanner. More real-life conditions (smeared print, non-glass surface) would be interesting to reproduce. My guess is that it ups the ante significantly for cost of hacking.

This is absolutely not a lab condition. You can very easily extract a fingerprint from a glass or so, as was done e.g. with Wolfgang Schaeuble, a German politician

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#72

Earlier quoted context omitted.

>I shouldn't be surprised, but the reporting on this makes it sound way different than the actual research. Specifically, none of the research appears to have been performed on, or tested against ACTUAL SMARTPHONE implementations That is exactly what the article says. Specifically: The researchers did not test their approach with real phones, and other security experts said the match rate would be significantly lower…

The article currently linked here is not the same one originally linked. It was changed after I made my post. That said, the headline still explicitly calls out smartphones.

[deleted]

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#74
post #70
post #55

Earlier quoted context omitted.

That hack uses lab conditions. They have a clear wine glass with a high resolution scanner. More real-life conditions (smeared print, non-glass surface) would be interesting to reproduce. My guess is that it ups the ante significantly for cost of hacking.

In "real life"—unless there was some absolute urgency to the problem—you wouldn't try to reconstruct a smudged partial print; you'd just use social engineering/espionage tactics to get a good print. (Remember that iOS locks and/or wipes devices after 10 failed attempts. You want to go to however much effort is required to be perfect the first time.) I can think of a number of situations one could create where a perso…

I imagine that sort of "committed adversary" is also quite capable of hitting you with a $5 wrench until you tell them the passcode...

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#75
post #70
post #55

Earlier quoted context omitted.

That hack uses lab conditions. They have a clear wine glass with a high resolution scanner. More real-life conditions (smeared print, non-glass surface) would be interesting to reproduce. My guess is that it ups the ante significantly for cost of hacking.

In "real life"—unless there was some absolute urgency to the problem—you wouldn't try to reconstruct a smudged partial print; you'd just use social engineering/espionage tactics to get a good print. (Remember that iOS locks and/or wipes devices after 10 failed attempts. You want to go to however much effort is required to be perfect the first time.) I can think of a number of situations one could create where a perso…

Well, 10 failed attempts doesn't necessarily hold water anymore.

Wasn't that whole "Can the FBI convince Apple to unlock this iPhone" case solved by backing up the NAND memory and constantly reflashing it after the 10 attempts were used up?

I imagine the same process can be applied in this case too

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#76
post #70
post #55

Earlier quoted context omitted.

That hack uses lab conditions. They have a clear wine glass with a high resolution scanner. More real-life conditions (smeared print, non-glass surface) would be interesting to reproduce. My guess is that it ups the ante significantly for cost of hacking.

In "real life"—unless there was some absolute urgency to the problem—you wouldn't try to reconstruct a smudged partial print; you'd just use social engineering/espionage tactics to get a good print. (Remember that iOS locks and/or wipes devices after 10 failed attempts. You want to go to however much effort is required to be perfect the first time.) I can think of a number of situations one could create where a perso…

Well, 10 failed attempts doesn't necessarily hold water anymore.

Wasn't that whole "Can the FBI convince Apple to unlock this iPhone" case solved by backing up the NAND memory and constantly reflashing it after the 10 attempts were used up?

I imagine the same process can be applied in this case too

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#77
post #55

Earlier quoted context omitted.

That hack uses lab conditions. They have a clear wine glass with a high resolution scanner. More real-life conditions (smeared print, non-glass surface) would be interesting to reproduce. My guess is that it ups the ante significantly for cost of hacking.

This is absolutely not a lab condition. You can very easily extract a fingerprint from a glass or so, as was done e.g. with Wolfgang Schaeuble, a German politician

Or just take a photo:

https://www.youtube.com/watch?v=VVxL9ymiyAU

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#78
Do you think your partner is cheating om you and you need to spy on their phone or hack their whatsapp, texts, facebook, Viber etc or you want to prevent your phone from being hacked. I strongly recommend SpyhackGod@gmail.com for all hacking problems you might have. He's reliable and efficient. You're welcome

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#79
post #74
post #70

Earlier quoted context omitted.

In "real life"—unless there was some absolute urgency to the problem—you wouldn't try to reconstruct a smudged partial print; you'd just use social engineering/espionage tactics to get a good print. (Remember that iOS locks and/or wipes devices after 10 failed attempts. You want to go to however much effort is required to be perfect the first time.) I can think of a number of situations one could create where a perso…

I imagine that sort of "committed adversary" is also quite capable of hitting you with a $5 wrench until you tell them the passcode...

I was presuming the sort of high-profile target where kidnapping them would quickly get some snipers emplaced and/or a MOAB dropped on you. If you want to, say, steal a nuclear submarine, you can't just kidnap an admiral and force them to hand over the keys. :P

Re: Smartphones can be fooled by fake, digitally composed fingerprints

#80
post #75
post #70

Earlier quoted context omitted.

In "real life"—unless there was some absolute urgency to the problem—you wouldn't try to reconstruct a smudged partial print; you'd just use social engineering/espionage tactics to get a good print. (Remember that iOS locks and/or wipes devices after 10 failed attempts. You want to go to however much effort is required to be perfect the first time.) I can think of a number of situations one could create where a perso…

Well, 10 failed attempts doesn't necessarily hold water anymore. Wasn't that whole "Can the FBI convince Apple to unlock this iPhone" case solved by backing up the NAND memory and constantly reflashing it after the 10 attempts were used up? I imagine the same process can be applied in this case too

Things have changed in the iPhone 5s, you can't bypass the unlock limit by desoldering a NAND chip anymore.
Post reply on HN