Live data from Hacker News

Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

ccc.de

21–30 of 166 posts

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#21

Based on the write-up, Samsung has lower quality Iris recognition than could be written by an undergrad in a few hours. I say that, having done so. Most obviously, the system should not tolerate a constant-size pupil, ever. The pupil has micro-dilations around twice per second, and your system is really terrible if you don't verify that changing diameter. Also, multi-spectral is a pretty good test, though I don't kno…

> CCC were able to do this for about the cost of a S8.

I think you misunderstood this. The cost was buying the S8.

You only need a laser printer, a decent camera and a contact lens.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#22
post #16

Based on the write-up, Samsung has lower quality Iris recognition than could be written by an undergrad in a few hours. I say that, having done so. Most obviously, the system should not tolerate a constant-size pupil, ever. The pupil has micro-dilations around twice per second, and your system is really terrible if you don't verify that changing diameter. Also, multi-spectral is a pretty good test, though I don't kno…

I suppose Samsung tuned the system to avoid false negatives, which might be difficult in all the lighting conditions that might come up in real world use. It's a device for the mass market and average user after all. Might be that they did a bad job with the Iris recognition, but why not give them the benefit of the doubt and consider that they were aware of the trade-offs involved?

Knowingly and willingly giving users a false sense of security? How is that not worse in every way?

If they couldn't manage to get false negatives down to an sensible level without compromising security in such a blatant way, there's two courses of action: Live with it, or don't release it.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#23

„But biometric authentication does not fulfill the advertised security promises“ This is completely out of context. For the average smartphone user Iris-Recognition on a phone (just like touch-ID) VS pin-disabled on the phone is a huge step forward.

The trouble with statements like 'for the average xyz user' is:

1. 50% of your users won't have their needs met - that's a large proportion assuming a uniform distribution

2. We can't be sure a uniform distribution in the first place is appropriate

3. If we're going to assume an average user then why don't we assume an average phone too: If the average user gets by without something today then why bother building it as a new feature?

In the end a product should not be designed for an average user. It should be designed for a well defined audience who's needs will met well by the product. If you're going to bother with fancy biometric tech as a feature and selling point then you're clearly NOT aiming at the average user who couldn't care less...

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#25
post #14

>Iris recognition may be barely sufficient to protect a phone against complete strangers unlocking it I suppose that's the attack scenario those systems (at least in phones) are supposed to protect against, to be fair. Suppose the alternative might be that some users use a predictable pin or none at all. Fingerprints or the iris sensor is an improvement for them because they are quick and easy to use. Of course it's…

>Fingerprints or the iris sensor is an improvement for them because they are quick and easy to use.

I'm not sure about it being an improvement, human laziness always finds a way to make something less secure. Like buying "fingerprint stickers" because too lazy to pull off a glove when wanting to unlock the phone [0].

The CCC always does interesting stuff like this, a couple of years they reproduced a politicians fingerprint just using photos of her hands [1].

This kind of stuff turns biometrics from something "you are" (your fingerprint, your iris) to something "you have" (a fingerprint on a glove, a picture of an iris) making biometrics often very trivial to bypass.

[0] http://gizmodo.com/these-fake-fingerprint-stickers-let-you-a...

[1] https://arstechnica.com/security/2014/12/politicians-fingerp...

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#26

Biometric data is not a password, it's an identity. Fingerprints and iris scans are equivalent to a username or email. To secure a device you need a password. Basics: something you are (iris scan, fingerprint), something you have (2fa token, usb unlock key), something you know (password). One out of 3 is probably not very secure.

> Basics: something you are (iris scan, fingerprint), something you have (2fa token, usb unlock key), something you know (password).

Why complicate things with 2fa tokens. Something you have: the phone! However I agree with something you know being missing.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#27

Biometric data is not a password, it's an identity. Fingerprints and iris scans are equivalent to a username or email. To secure a device you need a password. Basics: something you are (iris scan, fingerprint), something you have (2fa token, usb unlock key), something you know (password). One out of 3 is probably not very secure.

One out of three is still somewhat more secure than zero out of three.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#28

Based on the write-up, Samsung has lower quality Iris recognition than could be written by an undergrad in a few hours. I say that, having done so. Most obviously, the system should not tolerate a constant-size pupil, ever. The pupil has micro-dilations around twice per second, and your system is really terrible if you don't verify that changing diameter. Also, multi-spectral is a pretty good test, though I don't kno…

You could also add eye-tracking to have the user follow a pattern and add complexity to faking it.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#29
post #21

Based on the write-up, Samsung has lower quality Iris recognition than could be written by an undergrad in a few hours. I say that, having done so. Most obviously, the system should not tolerate a constant-size pupil, ever. The pupil has micro-dilations around twice per second, and your system is really terrible if you don't verify that changing diameter. Also, multi-spectral is a pretty good test, though I don't kno…

> CCC were able to do this for about the cost of a S8. I think you misunderstood this. The cost was buying the S8. You only need a laser printer, a decent camera and a contact lens.

That is what he meant. Doing it better is that easy, that the cost of the S8 is more expensive then the hours of programming labor.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#30

I am curios how much eye damage these system can cause. The S8 gives a warning before you activate it that you should not place the phone too close to your face. How bright is this infrared light and can it cause eye damage although we can't see it?

Anecdotally I do not notice any eye discomfort while using this n times per day. It's also not "bright" from my perspective but someone with this system would better answer the eye damage question.
Post reply on HN