I shouldn't be surprised, but the reporting on this makes it sound way different than the actual research. Specifically, none of the research appears to have been performed on, or tested against ACTUAL SMARTPHONE implementations - for example: "Experiments on a capacitive fingerprint dataset, similar to the one used by Apple TouchID, showed that it is possible to break 6.88% of users’ account in 5 attempts if the FMR…
>It seems that using commercial fingerprint software and captive systems 'similar to the one used by Apple TouchID' is very different from actually testing your theories against, you know, Apple TouchID. In theory, there's no difference between theory in practice; In practice, there is. ;] OTOH, Here is a supposed example of an attacker circumventing TouchID iPhone-access controls: "The video shows in detail how CCC…
Smartphones can be fooled by fake, digitally composed fingerprints
81–90 of 114 posts
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#82Earlier quoted context omitted.
I imagine that sort of "committed adversary" is also quite capable of hitting you with a $5 wrench until you tell them the passcode...
I was presuming the sort of high-profile target where kidnapping them would quickly get some snipers emplaced and/or a MOAB dropped on you. If you want to, say, steal a nuclear submarine, you can't just kidnap an admiral and force them to hand over the keys. :P
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#83Earlier quoted context omitted.
I was presuming the sort of high-profile target where kidnapping them would quickly get some snipers emplaced and/or a MOAB dropped on you. If you want to, say, steal a nuclear submarine, you can't just kidnap an admiral and force them to hand over the keys. :P
No, that's the inelegant solution. Blackmail works far better with far less blowback.
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#84Earlier quoted context omitted.
>It seems that using commercial fingerprint software and captive systems 'similar to the one used by Apple TouchID' is very different from actually testing your theories against, you know, Apple TouchID. In theory, there's no difference between theory in practice; In practice, there is. ;] OTOH, Here is a supposed example of an attacker circumventing TouchID iPhone-access controls: "The video shows in detail how CCC…
That hack uses lab conditions. They have a clear wine glass with a high resolution scanner. More real-life conditions (smeared print, non-glass surface) would be interesting to reproduce. My guess is that it ups the ante significantly for cost of hacking.
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#85Earlier quoted context omitted.
>I shouldn't be surprised, but the reporting on this makes it sound way different than the actual research. Specifically, none of the research appears to have been performed on, or tested against ACTUAL SMARTPHONE implementations That is exactly what the article says. Specifically: The researchers did not test their approach with real phones, and other security experts said the match rate would be significantly lower…
The article currently linked here is not the same one originally linked. It was changed after I made my post. That said, the headline still explicitly calls out smartphones.
Grr, hate it when they do that, it's clearly too hard to add a second link "previously the linked article was: ..."?
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#86I shouldn't be surprised, but the reporting on this makes it sound way different than the actual research. Specifically, none of the research appears to have been performed on, or tested against ACTUAL SMARTPHONE implementations - for example: "Experiments on a capacitive fingerprint dataset, similar to the one used by Apple TouchID, showed that it is possible to break 6.88% of users’ account in 5 attempts if the FMR…
I understand it's difficult to test against the actual Touch ID, since it has aggressive hardware-enforced cooldowns and other defensive tech.
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#87Earlier quoted context omitted.
That hack uses lab conditions. They have a clear wine glass with a high resolution scanner. More real-life conditions (smeared print, non-glass surface) would be interesting to reproduce. My guess is that it ups the ante significantly for cost of hacking.
In "real life"—unless there was some absolute urgency to the problem—you wouldn't try to reconstruct a smudged partial print; you'd just use social engineering/espionage tactics to get a good print. (Remember that iOS locks and/or wipes devices after 10 failed attempts. You want to go to however much effort is required to be perfect the first time.) I can think of a number of situations one could create where a perso…
You only get 5 attempts at TouchID - 10 attempts is for the passcode.
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#88Nearly all biometrics, except for physically invasive ones, are easily stolen . All are forgeable. Biometrics can never be revoked once compromised. They're like the social security number of logins. Completely useless. Using biometrics for security or identity violates practically every rule for secure credentials. They exchange convenience for extremely minimal security. Perhaps the oft-cited username, not a passwo…
Because we don't have any other practical alternatives? With how often people unlock their phones in public, PIN codes are absolutely useless.
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#89The phone is covered with fingerprints from the owner anyway. If you have the phone, you already have the "password". The fingerprint scan is just to make it a little bit annoying for attacker, so they'll factory reset instead of bothering to crack it. It's not intended for any kind of real security. Like many others here I never used to lock my phone at all until the fingerprint scan, and I don't consider the scan a…
How do you know that the finger data the scanner uses is present in oil prints? If this true, someone would have created a working demonstration in the past 5 years.
Re: Smartphones can be fooled by fake, digitally composed fingerprints
#90Earlier quoted context omitted.
It's pretty good at European languages, but still terrible at Arabic and Japanese. The system still has a very shallow understanding of the content. One of my primarily Arabic-speaking colleagues was actually offended by Google Translate butchering their language so badly; their culture places a relatively high value on poetry, calligraphy, etc. As an exercise, try translating your search queries into Arabic before s…
I wonder how much Arabic translation suffers from a lack of available data to feed the ML. [1] > Nor are foreign books much translated: in the 1,000 years since the reign of the Caliph Mamoun, say the authors, the Arabs have translated as many books as Spain translates in one year. [1] http://www.economist.com/node/1213392