Live data from Hacker News

Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

ccc.de

11–20 of 166 posts

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#11

„But biometric authentication does not fulfill the advertised security promises“ This is completely out of context. For the average smartphone user Iris-Recognition on a phone (just like touch-ID) VS pin-disabled on the phone is a huge step forward.

I can obtain an image of you online, while I need to be on-site to spot you typing your pin. So if I have your phone, I can do research at home to break in.

Additionally, you cannot change your iris once it's compromised. This is an absolute no-no for secure systems! Changing your pin is easy.

This is definitely not a huge step forward. And, as already mentioned, the average user gets misguided by exaggerated marketing promises.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#12
post #8

> The Samsung Galaxy S8 is the first flagship smartphone with iris recognition. That's not quite true, Lumia 950, Lumia 950 XL and HP Elite x3 came out a lot earlier than the Galaxy S8 and all of them use iris recognition (still undefeated, by the way)

There could a bit of a bias, Lumias and HP Elite x3 aren't anywhere near as popular as Samsung Galaxy S8, same as most malware targets Windows rather than Linux/macOS.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#14
>Iris recognition may be barely sufficient to protect a phone against complete strangers unlocking it

I suppose that's the attack scenario those systems (at least in phones) are supposed to protect against, to be fair. Suppose the alternative might be that some users use a predictable pin or none at all. Fingerprints or the iris sensor is an improvement for them because they are quick and easy to use.

Of course it's still good to deflate the hype around Iris scanners a bit and demonstrate that it is currently a very limited technology after all. Especially considering their remark that iris scanners spread to other devices too.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#15

„But biometric authentication does not fulfill the advertised security promises“ This is completely out of context. For the average smartphone user Iris-Recognition on a phone (just like touch-ID) VS pin-disabled on the phone is a huge step forward.

Here's some context:

    The patterns in your irises are unique to you and are
    virtually impossible to replicate, meaning iris
    authentication is one of the safest ways to keep your
    phone locked and the contents private.
Source: http://www.samsung.com/global/galaxy/galaxy-s8/security/

I think the quote is fair.

Also your pin disabled argument doesn't make a lot of sense. That's like saying 123456 is a good password because many people disable the password prompt at login.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#16

Based on the write-up, Samsung has lower quality Iris recognition than could be written by an undergrad in a few hours. I say that, having done so. Most obviously, the system should not tolerate a constant-size pupil, ever. The pupil has micro-dilations around twice per second, and your system is really terrible if you don't verify that changing diameter. Also, multi-spectral is a pretty good test, though I don't kno…

I suppose Samsung tuned the system to avoid false negatives, which might be difficult in all the lighting conditions that might come up in real world use. It's a device for the mass market and average user after all.

Might be that they did a bad job with the Iris recognition, but why not give them the benefit of the doubt and consider that they were aware of the trade-offs involved?

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#17

Based on the write-up, Samsung has lower quality Iris recognition than could be written by an undergrad in a few hours. I say that, having done so. Most obviously, the system should not tolerate a constant-size pupil, ever. The pupil has micro-dilations around twice per second, and your system is really terrible if you don't verify that changing diameter. Also, multi-spectral is a pretty good test, though I don't kno…

Do you have a source about these micro-dilations? I googled a little bit but couldn't find enlightening results in my superficial search.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#18

The important thing is how much more/less difficult is this than spoofing a fingerprint. If it is significantly harder, I still see it as a win for samsung's security.

Spoofing this eye is significantly easier than spoofing a fingerprint, because modern fingerprint technology detect if a fingerprint is "alive" by looking at sweat pores, pulse, veins under the skin and other features of a living finger.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#19
I am curios how much eye damage these system can cause. The S8 gives a warning before you activate it that you should not place the phone too close to your face.

How bright is this infrared light and can it cause eye damage although we can't see it?

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#20
Biometric data is not a password, it's an identity. Fingerprints and iris scans are equivalent to a username or email.

To secure a device you need a password.

Basics: something you are (iris scan, fingerprint), something you have (2fa token, usb unlock key), something you know (password).

One out of 3 is probably not very secure.

Post reply on HN