Live data from Hacker News

Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

ccc.de

41–50 of 166 posts

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#41

Based on the write-up, Samsung has lower quality Iris recognition than could be written by an undergrad in a few hours. I say that, having done so. Most obviously, the system should not tolerate a constant-size pupil, ever. The pupil has micro-dilations around twice per second, and your system is really terrible if you don't verify that changing diameter. Also, multi-spectral is a pretty good test, though I don't kno…

Samsung always seems to me as if they race to match any iPhone feature–but never more than skin-deep.

So when the iPhone gets a fingerprint sensor that saves only a hash of the actual data in a special enclave of a custom chip, Samsung responds with an iris scanner that saves an image of the iris as a world-readable jpeg in your home directory.

Thus, their marketing material can claim feature-parity (or even exceed Apple). But it never seems like they actually care.

It's not like Apple doesn't run into similar problems (not sure if the fingerprint sensor has been defeated–it's a bad idea for 5th amendment reasons in any case). But at least they do the minimum in trying.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#42
post #16

Based on the write-up, Samsung has lower quality Iris recognition than could be written by an undergrad in a few hours. I say that, having done so. Most obviously, the system should not tolerate a constant-size pupil, ever. The pupil has micro-dilations around twice per second, and your system is really terrible if you don't verify that changing diameter. Also, multi-spectral is a pretty good test, though I don't kno…

I suppose Samsung tuned the system to avoid false negatives, which might be difficult in all the lighting conditions that might come up in real world use. It's a device for the mass market and average user after all. Might be that they did a bad job with the Iris recognition, but why not give them the benefit of the doubt and consider that they were aware of the trade-offs involved?

That could be the case, after all it's not a Diebold ATM.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#43
post #17

Based on the write-up, Samsung has lower quality Iris recognition than could be written by an undergrad in a few hours. I say that, having done so. Most obviously, the system should not tolerate a constant-size pupil, ever. The pupil has micro-dilations around twice per second, and your system is really terrible if you don't verify that changing diameter. Also, multi-spectral is a pretty good test, though I don't kno…

Do you have a source about these micro-dilations? I googled a little bit but couldn't find enlightening results in my superficial search.

A similar concept that I remember from university are saccades (minimal, involuntary eye movements).

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#44

Based on the write-up, Samsung has lower quality Iris recognition than could be written by an undergrad in a few hours. I say that, having done so. Most obviously, the system should not tolerate a constant-size pupil, ever. The pupil has micro-dilations around twice per second, and your system is really terrible if you don't verify that changing diameter. Also, multi-spectral is a pretty good test, though I don't kno…

Well, a few hours is quite the euphemism if you're talking about starting from scratch.

Also, the cellphone image resolution is far too low to recognize dilations. Looking at the video, I'm surprised that it works as well as it does, to be honest.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#45

Biometric data is not a password, it's an identity. Fingerprints and iris scans are equivalent to a username or email. To secure a device you need a password. Basics: something you are (iris scan, fingerprint), something you have (2fa token, usb unlock key), something you know (password). One out of 3 is probably not very secure.

Phone must automatically lock quite quickly, otherwise somebody quick just grab it after you have unlocked it. This means the password needs to be typed in constantly if you are frequently picking up the phone. Also you often want to grab the phone with one hand, so you need to be able to type the password with one hand. Combine that with the frequent typing and you probably come to conclusion that you can't have a proper, secure passphrase. Instead you resort to pin code of some length. Now remember that you need to be typing the pin code constantly to unlock the phone. With one hand operation there's little you can do to protect yourself against shoulder surfing. This means you pin code is not that private.

Iris scanning or fingerprints are easy for determined attacker, but I would say they are hard for somebody who just grabs your phone. Vice versa for the pin code.

I think a good balance between security and usability would be to allow fingerprint or iris scan when the phone has been constantly in my proximity but require a pin (password) if the phone is taken away. The proximity could be determined for example by pairing the phone with smart watch.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#46

I am curios how much eye damage these system can cause. The S8 gives a warning before you activate it that you should not place the phone too close to your face. How bright is this infrared light and can it cause eye damage although we can't see it?

Anecdotally I do not notice any eye discomfort while using this n times per day. It's also not "bright" from my perspective but someone with this system would better answer the eye damage question.

It's unlikely to be dangerous (see other answers), but "eye discomfort" is a bad yardstick: the retina doesn't have nociceptors and any discomfort would only be secondary, appearing long after the damage is done. See (without being seen) the few people who manage to observe each solar eclipse with binoculars.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#47
post #29
post #21

Earlier quoted context omitted.

> CCC were able to do this for about the cost of a S8. I think you misunderstood this. The cost was buying the S8. You only need a laser printer, a decent camera and a contact lens.

That is what he meant. Doing it better is that easy, that the cost of the S8 is more expensive then the hours of programming labor.

What programming labor? They just printed a photo and put a lens on it.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#48
post #6

Whilst it's certainly valuable to make people aware of the limitations of the security systems we use, this shouldn't really come as a surpre. If someone is close enough and motivated enough to take a high-res photo of your face just to access your mobile device, they're also probably close enough to film you typing in your passcode - sure, you might do that less often, but for an average user are either of those thi…

> If someone is close enough and motivated enough to take a high-res photo of your face just to access your mobile device, they're also probably close enough to film you typing in your passcode

Not sure about that. All of my friends, family and work colleagues are 'close enough' to me to take a high res photo of my face (and I'd gladly let them do it), but none of them can see my passwords when I'm typing or unlock my phone without my permission. For me this revelation is of a big concern.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#49
post #11

„But biometric authentication does not fulfill the advertised security promises“ This is completely out of context. For the average smartphone user Iris-Recognition on a phone (just like touch-ID) VS pin-disabled on the phone is a huge step forward.

I can obtain an image of you online, while I need to be on-site to spot you typing your pin. So if I have your phone, I can do research at home to break in. Additionally, you cannot change your iris once it's compromised. This is an absolute no-no for secure systems! Changing your pin is easy. This is definitely not a huge step forward. And, as already mentioned, the average user gets misguided by exaggerated marketi…

A random photo on the net probably doesn't have the resolution needed for Iris recognition

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#50
post #36
post #22

Earlier quoted context omitted.

Knowingly and willingly giving users a false sense of security? How is that not worse in every way? If they couldn't manage to get false negatives down to an sensible level without compromising security in such a blatant way, there's two courses of action: Live with it, or don't release it.

Or release it and make money with your cool feature that competitors don't have.

Spot on.

This is a marketing gimmick, not a security feature.

Just as with fingerprint readers[1] the target audience is people who otherwise wouldn't lock their phone at all.

[1] https://arstechnica.com/apple/2013/09/chaos-computer-club-ha...

Post reply on HN