Live data from Hacker News

Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

ccc.de

31–40 of 166 posts

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#31

The important thing is how much more/less difficult is this than spoofing a fingerprint. If it is significantly harder, I still see it as a win for samsung's security.

Spoofing this eye is significantly easier than spoofing a fingerprint, because modern fingerprint technology detect if a fingerprint is "alive" by looking at sweat pores, pulse, veins under the skin and other features of a living finger.

But do phones check for all those markers?

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#32

I am curios how much eye damage these system can cause. The S8 gives a warning before you activate it that you should not place the phone too close to your face. How bright is this infrared light and can it cause eye damage although we can't see it?

No, it can't. The warning is for optimal detection rates, it doesn't harm your eye.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#33
post #6

Whilst it's certainly valuable to make people aware of the limitations of the security systems we use, this shouldn't really come as a surpre. If someone is close enough and motivated enough to take a high-res photo of your face just to access your mobile device, they're also probably close enough to film you typing in your passcode - sure, you might do that less often, but for an average user are either of those thi…

We should understand the attack model better and the likelihood of a successful eye capture.

We know that it's certainly less hard than knowing someone's password given a semi sane password policy, but more difficult than scraping fb selfies and printing them.

Thinking out loud, I certainly don't share my phone password with my eye doctor, so there's one example of disclosure.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#35

I am curios how much eye damage these system can cause. The S8 gives a warning before you activate it that you should not place the phone too close to your face. How bright is this infrared light and can it cause eye damage although we can't see it?

Have you ever been outside? It's dimmer than that.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#36
post #22
post #16

Earlier quoted context omitted.

I suppose Samsung tuned the system to avoid false negatives, which might be difficult in all the lighting conditions that might come up in real world use. It's a device for the mass market and average user after all. Might be that they did a bad job with the Iris recognition, but why not give them the benefit of the doubt and consider that they were aware of the trade-offs involved?

Knowingly and willingly giving users a false sense of security? How is that not worse in every way? If they couldn't manage to get false negatives down to an sensible level without compromising security in such a blatant way, there's two courses of action: Live with it, or don't release it.

Or release it and make money with your cool feature that competitors don't have.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#37
post #14

>Iris recognition may be barely sufficient to protect a phone against complete strangers unlocking it I suppose that's the attack scenario those systems (at least in phones) are supposed to protect against, to be fair. Suppose the alternative might be that some users use a predictable pin or none at all. Fingerprints or the iris sensor is an improvement for them because they are quick and easy to use. Of course it's…

>Fingerprints or the iris sensor is an improvement for them because they are quick and easy to use. I'm not sure about it being an improvement, human laziness always finds a way to make something less secure. Like buying "fingerprint stickers" because too lazy to pull off a glove when wanting to unlock the phone [0]. The CCC always does interesting stuff like this, a couple of years they reproduced a politicians fing…

> a fingerprint on a glove

Fingerprints are even worse. They are all over your phone. So if someone steals it the key is already included.

Fingerprints are something you leave all over the place right now and with the increased camera placement and tracking done everywhere pictures of your iris wont be much better for long. So both are not something you are or have, they are something everyone you ever passed on the street has access to.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#38
post #4
post #2

"The by far most expensive part of the iris biometry hack was the purchase of the Galaxy S8 smartphone."

and " Ironically, we got the best results with laser printers made by Samsung" You can tell they really had fun with this!

Well, it is the CCC. These guys do this for fun, so having more fun while doing it is just added bonus.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#39
post #35

I am curios how much eye damage these system can cause. The S8 gives a warning before you activate it that you should not place the phone too close to your face. How bright is this infrared light and can it cause eye damage although we can't see it?

Have you ever been outside? It's dimmer than that.

A nice campfire that noticeably warms your face when you look at it probably gives off a couple orders of magnitude more IR than the phone. IR can damage eyes [1], but the phone probably won't contribute significantly

[1] https://www.ncbi.nlm.nih.gov/pmc/articles/PMC3116568/

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#40

Biometric data is not a password, it's an identity. Fingerprints and iris scans are equivalent to a username or email. To secure a device you need a password. Basics: something you are (iris scan, fingerprint), something you have (2fa token, usb unlock key), something you know (password). One out of 3 is probably not very secure.

Fingerprints and iris scans are not equivalent to a username or email, since the username and email can be changed easily. Proper biometric data cannot be changed, it is tied to the individual. So when the data is compromised and published in the wild and the devices can be fooled with it (which will always be possible), then the user of biometric recognition devices can become the victim of identity theft for the rest of their life.
Post reply on HN