Live data from Hacker News

Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

ccc.de

51–60 of 166 posts

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#51

„But biometric authentication does not fulfill the advertised security promises“ This is completely out of context. For the average smartphone user Iris-Recognition on a phone (just like touch-ID) VS pin-disabled on the phone is a huge step forward.

Here's some context: The patterns in your irises are unique to you and are virtually impossible to replicate, meaning iris authentication is one of the safest ways to keep your phone locked and the contents private. Source: http://www.samsung.com/global/galaxy/galaxy-s8/security/ I think the quote is fair. Also your pin disabled argument doesn't make a lot of sense. That's like saying 123456 is a good password becaus…

A pin of 123456 is more secure than no pin at all.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#52
post #29

Earlier quoted context omitted.

That is what he meant. Doing it better is that easy, that the cost of the S8 is more expensive then the hours of programming labor.

What programming labor? They just printed a photo and put a lens on it.

You're agreeing.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#53

I am curios how much eye damage these system can cause. The S8 gives a warning before you activate it that you should not place the phone too close to your face. How bright is this infrared light and can it cause eye damage although we can't see it?

In general yes, invisible things can burn your eyes but it's probably of no concern here. The more common thing you'll run into is things like cheap DPSS green lasers that output a large amount of IR, you don't have a blink reflex for things outside of your visible range and these will cause damage on the higher end.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#54
post #11

Earlier quoted context omitted.

I can obtain an image of you online, while I need to be on-site to spot you typing your pin. So if I have your phone, I can do research at home to break in. Additionally, you cannot change your iris once it's compromised. This is an absolute no-no for secure systems! Changing your pin is easy. This is definitely not a huge step forward. And, as already mentioned, the average user gets misguided by exaggerated marketi…

A random photo on the net probably doesn't have the resolution needed for Iris recognition

The CCC used an old digicam at medium distance. It is quite likely that such a photo is on FB, Instagram etc.

Side note: The CCC even recovered the fingerprint of the Germany's defense minister from a photo: https://www.theguardian.com/technology/2014/dec/30/hacker-fa...

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#55

Earlier quoted context omitted.

What programming labor? They just printed a photo and put a lens on it.

You're agreeing.

Yeah, well, in that sense, the cost of the S8 was also higher than the hours the researchers spent scrubbing toilets to develop this exploit.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#56

Biometric data is not a password, it's an identity. Fingerprints and iris scans are equivalent to a username or email. To secure a device you need a password. Basics: something you are (iris scan, fingerprint), something you have (2fa token, usb unlock key), something you know (password). One out of 3 is probably not very secure.

Just to make your point explicit, you can't change your identity/biometrics/fingerprint if it is compromised. You can change your keys.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#57
post #29

Earlier quoted context omitted.

That is what he meant. Doing it better is that easy, that the cost of the S8 is more expensive then the hours of programming labor.

What programming labor? They just printed a photo and put a lens on it.

I think that tbihl and bebna are trying to say that it would cost Samsung less to defeat the attack by programming one of the listed countermeasures than it cost the CCC folks to buy one of these phones. (I don't agree.)

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#58

Earlier quoted context omitted.

Here's some context: The patterns in your irises are unique to you and are virtually impossible to replicate, meaning iris authentication is one of the safest ways to keep your phone locked and the contents private. Source: http://www.samsung.com/global/galaxy/galaxy-s8/security/ I think the quote is fair. Also your pin disabled argument doesn't make a lot of sense. That's like saying 123456 is a good password becaus…

A pin of 123456 is more secure than no pin at all.

Yes, but that doesn't say anything about the security of passwords in general. (The same way that bad iris recognition being better than no auth at all doesn't say anything about the security of iris recognition in general.)

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#59
post #34

Wait. S8 has iris recognition system and people are dumb enough to scan their eyes and give another biometric data point to god knows whom?

Given how easily they broke the iris recognition, that particular cat is likely already out of the bag.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#60

Based on the write-up, Samsung has lower quality Iris recognition than could be written by an undergrad in a few hours. I say that, having done so. Most obviously, the system should not tolerate a constant-size pupil, ever. The pupil has micro-dilations around twice per second, and your system is really terrible if you don't verify that changing diameter. Also, multi-spectral is a pretty good test, though I don't kno…

Samsung always seems to me as if they race to match any iPhone feature–but never more than skin-deep. So when the iPhone gets a fingerprint sensor that saves only a hash of the actual data in a special enclave of a custom chip, Samsung responds with an iris scanner that saves an image of the iris as a world-readable jpeg in your home directory. Thus, their marketing material can claim feature-parity (or even exceed A…

>It's not like Apple doesn't run into similar problems (not sure if the fingerprint sensor has been defeated–it's a bad idea for 5th amendment reasons in any case). But at least they do the minimum in trying.

In 2013 a CCC member broke TouchID access within a few hours after release of the IPhone. All needed was a photograph of the fingerprint on a glass surface. https://www.ccc.de/en/updates/2013/ccc-breaks-apple-touchid

Same method worked on the Iphone 6, as Apple hasn't changed a thing. Biometry is fundamentally broken.

Post reply on HN