The important thing is how much more/less difficult is this than spoofing a fingerprint. If it is significantly harder, I still see it as a win for samsung's security.
Spoofing this eye is significantly easier than spoofing a fingerprint, because modern fingerprint technology detect if a fingerprint is "alive" by looking at sweat pores, pulse, veins under the skin and other features of a living finger.
Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
31–40 of 166 posts
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#32I am curios how much eye damage these system can cause. The S8 gives a warning before you activate it that you should not place the phone too close to your face. How bright is this infrared light and can it cause eye damage although we can't see it?
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#33Whilst it's certainly valuable to make people aware of the limitations of the security systems we use, this shouldn't really come as a surpre. If someone is close enough and motivated enough to take a high-res photo of your face just to access your mobile device, they're also probably close enough to film you typing in your passcode - sure, you might do that less often, but for an average user are either of those thi…
We know that it's certainly less hard than knowing someone's password given a semi sane password policy, but more difficult than scraping fb selfies and printing them.
Thinking out loud, I certainly don't share my phone password with my eye doctor, so there's one example of disclosure.
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#34Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#35I am curios how much eye damage these system can cause. The S8 gives a warning before you activate it that you should not place the phone too close to your face. How bright is this infrared light and can it cause eye damage although we can't see it?
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#36Earlier quoted context omitted.
I suppose Samsung tuned the system to avoid false negatives, which might be difficult in all the lighting conditions that might come up in real world use. It's a device for the mass market and average user after all. Might be that they did a bad job with the Iris recognition, but why not give them the benefit of the doubt and consider that they were aware of the trade-offs involved?
Knowingly and willingly giving users a false sense of security? How is that not worse in every way? If they couldn't manage to get false negatives down to an sensible level without compromising security in such a blatant way, there's two courses of action: Live with it, or don't release it.
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#37>Iris recognition may be barely sufficient to protect a phone against complete strangers unlocking it I suppose that's the attack scenario those systems (at least in phones) are supposed to protect against, to be fair. Suppose the alternative might be that some users use a predictable pin or none at all. Fingerprints or the iris sensor is an improvement for them because they are quick and easy to use. Of course it's…
>Fingerprints or the iris sensor is an improvement for them because they are quick and easy to use. I'm not sure about it being an improvement, human laziness always finds a way to make something less secure. Like buying "fingerprint stickers" because too lazy to pull off a glove when wanting to unlock the phone [0]. The CCC always does interesting stuff like this, a couple of years they reproduced a politicians fing…
Fingerprints are even worse. They are all over your phone. So if someone steals it the key is already included.
Fingerprints are something you leave all over the place right now and with the increased camera placement and tracking done everywhere pictures of your iris wont be much better for long. So both are not something you are or have, they are something everyone you ever passed on the street has access to.
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#38"The by far most expensive part of the iris biometry hack was the purchase of the Galaxy S8 smartphone."
and " Ironically, we got the best results with laser printers made by Samsung" You can tell they really had fun with this!
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#39I am curios how much eye damage these system can cause. The S8 gives a warning before you activate it that you should not place the phone too close to your face. How bright is this infrared light and can it cause eye damage although we can't see it?
Have you ever been outside? It's dimmer than that.
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#40Biometric data is not a password, it's an identity. Fingerprints and iris scans are equivalent to a username or email. To secure a device you need a password. Basics: something you are (iris scan, fingerprint), something you have (2fa token, usb unlock key), something you know (password). One out of 3 is probably not very secure.