Earlier quoted context omitted.
>It seems that using commercial fingerprint software and captive systems 'similar to the one used by Apple TouchID' is very different from actually testing your theories against, you know, Apple TouchID. In theory, there's no difference between theory in practice; In practice, there is. ;] OTOH, Here is a supposed example of an attacker circumventing TouchID iPhone-access controls: "The video shows in detail how CCC…
That hack uses lab conditions. They have a clear wine glass with a high resolution scanner. More real-life conditions (smeared print, non-glass surface) would be interesting to reproduce. My guess is that it ups the ante significantly for cost of hacking.
Smartphones can be fooled by fake, digitally composed fingerprints
71–80 of 114 posts
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#72Earlier quoted context omitted.
>I shouldn't be surprised, but the reporting on this makes it sound way different than the actual research. Specifically, none of the research appears to have been performed on, or tested against ACTUAL SMARTPHONE implementations That is exactly what the article says. Specifically: The researchers did not test their approach with real phones, and other security experts said the match rate would be significantly lower…
The article currently linked here is not the same one originally linked. It was changed after I made my post. That said, the headline still explicitly calls out smartphones.
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#73Re: Smartphones can be fooled by fake, digitally composed fingerprints
#74Earlier quoted context omitted.
That hack uses lab conditions. They have a clear wine glass with a high resolution scanner. More real-life conditions (smeared print, non-glass surface) would be interesting to reproduce. My guess is that it ups the ante significantly for cost of hacking.
In "real life"—unless there was some absolute urgency to the problem—you wouldn't try to reconstruct a smudged partial print; you'd just use social engineering/espionage tactics to get a good print. (Remember that iOS locks and/or wipes devices after 10 failed attempts. You want to go to however much effort is required to be perfect the first time.) I can think of a number of situations one could create where a perso…
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#75Earlier quoted context omitted.
That hack uses lab conditions. They have a clear wine glass with a high resolution scanner. More real-life conditions (smeared print, non-glass surface) would be interesting to reproduce. My guess is that it ups the ante significantly for cost of hacking.
In "real life"—unless there was some absolute urgency to the problem—you wouldn't try to reconstruct a smudged partial print; you'd just use social engineering/espionage tactics to get a good print. (Remember that iOS locks and/or wipes devices after 10 failed attempts. You want to go to however much effort is required to be perfect the first time.) I can think of a number of situations one could create where a perso…
Wasn't that whole "Can the FBI convince Apple to unlock this iPhone" case solved by backing up the NAND memory and constantly reflashing it after the 10 attempts were used up?
I imagine the same process can be applied in this case too
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#76Earlier quoted context omitted.
That hack uses lab conditions. They have a clear wine glass with a high resolution scanner. More real-life conditions (smeared print, non-glass surface) would be interesting to reproduce. My guess is that it ups the ante significantly for cost of hacking.
In "real life"—unless there was some absolute urgency to the problem—you wouldn't try to reconstruct a smudged partial print; you'd just use social engineering/espionage tactics to get a good print. (Remember that iOS locks and/or wipes devices after 10 failed attempts. You want to go to however much effort is required to be perfect the first time.) I can think of a number of situations one could create where a perso…
Wasn't that whole "Can the FBI convince Apple to unlock this iPhone" case solved by backing up the NAND memory and constantly reflashing it after the 10 attempts were used up?
I imagine the same process can be applied in this case too
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#77Earlier quoted context omitted.
That hack uses lab conditions. They have a clear wine glass with a high resolution scanner. More real-life conditions (smeared print, non-glass surface) would be interesting to reproduce. My guess is that it ups the ante significantly for cost of hacking.
This is absolutely not a lab condition. You can very easily extract a fingerprint from a glass or so, as was done e.g. with Wolfgang Schaeuble, a German politician
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#78Re: Smartphones can be fooled by fake, digitally composed fingerprints
#79Earlier quoted context omitted.
In "real life"—unless there was some absolute urgency to the problem—you wouldn't try to reconstruct a smudged partial print; you'd just use social engineering/espionage tactics to get a good print. (Remember that iOS locks and/or wipes devices after 10 failed attempts. You want to go to however much effort is required to be perfect the first time.) I can think of a number of situations one could create where a perso…
I imagine that sort of "committed adversary" is also quite capable of hitting you with a $5 wrench until you tell them the passcode...
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#80Earlier quoted context omitted.
In "real life"—unless there was some absolute urgency to the problem—you wouldn't try to reconstruct a smudged partial print; you'd just use social engineering/espionage tactics to get a good print. (Remember that iOS locks and/or wipes devices after 10 failed attempts. You want to go to however much effort is required to be perfect the first time.) I can think of a number of situations one could create where a perso…
Well, 10 failed attempts doesn't necessarily hold water anymore. Wasn't that whole "Can the FBI convince Apple to unlock this iPhone" case solved by backing up the NAND memory and constantly reflashing it after the 10 attempts were used up? I imagine the same process can be applied in this case too