Live data from Hacker News

Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

ccc.de

61–70 of 166 posts

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#61
post #17

Earlier quoted context omitted.

Do you have a source about these micro-dilations? I googled a little bit but couldn't find enlightening results in my superficial search.

A similar concept that I remember from university are saccades (minimal, involuntary eye movements).

Yes but those are well-known and visible to the naked eye. I've never heard of these 'micro-dilations' and Google didn't show anything.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#62
post #17

Based on the write-up, Samsung has lower quality Iris recognition than could be written by an undergrad in a few hours. I say that, having done so. Most obviously, the system should not tolerate a constant-size pupil, ever. The pupil has micro-dilations around twice per second, and your system is really terrible if you don't verify that changing diameter. Also, multi-spectral is a pretty good test, though I don't kno…

Do you have a source about these micro-dilations? I googled a little bit but couldn't find enlightening results in my superficial search.

The closest I could find was this:

https://graphics.stanford.edu/papers/remote-pupillometry/

It seems that there are reasonably large changes due to thinking about something, but not due to just looking unless your camera can detect 0.01 mm changes in diameter, which maybe tbihl's could be that seems unreasonable for a smartphone camera.

I would guess tbihl has never tried to get iris recognition working on a cost-constrained consumer device at a huge scale. They might not think it is so trivial then.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#64

Based on the write-up, Samsung has lower quality Iris recognition than could be written by an undergrad in a few hours. I say that, having done so. Most obviously, the system should not tolerate a constant-size pupil, ever. The pupil has micro-dilations around twice per second, and your system is really terrible if you don't verify that changing diameter. Also, multi-spectral is a pretty good test, though I don't kno…

Samsung always seems to me as if they race to match any iPhone feature–but never more than skin-deep. So when the iPhone gets a fingerprint sensor that saves only a hash of the actual data in a special enclave of a custom chip, Samsung responds with an iris scanner that saves an image of the iris as a world-readable jpeg in your home directory. Thus, their marketing material can claim feature-parity (or even exceed A…

[deleted]

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#65
post #54

Earlier quoted context omitted.

A random photo on the net probably doesn't have the resolution needed for Iris recognition

The CCC used an old digicam at medium distance. It is quite likely that such a photo is on FB, Instagram etc. Side note: The CCC even recovered the fingerprint of the Germany's defense minister from a photo: https://www.theguardian.com/technology/2014/dec/30/hacker-fa...

Yeah then Samsung's "iris recognition" is more like "iris blur matching"

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#66
post #59
post #34

Wait. S8 has iris recognition system and people are dumb enough to scan their eyes and give another biometric data point to god knows whom?

Given how easily they broke the iris recognition, that particular cat is likely already out of the bag.

As it would to varying degrees with any system, knowing humans.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#67

Biometric data is not a password, it's an identity. Fingerprints and iris scans are equivalent to a username or email. To secure a device you need a password. Basics: something you are (iris scan, fingerprint), something you have (2fa token, usb unlock key), something you know (password). One out of 3 is probably not very secure.

The password model on Google's version of Android and iOS (as examples) is not biometric based. You need the password every few hours (at least on Android, not sure about iOS) and whenever you restart. The biometric is a keep alive for that "session". For my threat model, that's sufficient. For many, that is sufficient. For some, it absolutely is not and they should disable biometrics entirely. .

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#68

Based on the write-up, Samsung has lower quality Iris recognition than could be written by an undergrad in a few hours. I say that, having done so. Most obviously, the system should not tolerate a constant-size pupil, ever. The pupil has micro-dilations around twice per second, and your system is really terrible if you don't verify that changing diameter. Also, multi-spectral is a pretty good test, though I don't kno…

Samsung always seems to me as if they race to match any iPhone feature–but never more than skin-deep. So when the iPhone gets a fingerprint sensor that saves only a hash of the actual data in a special enclave of a custom chip, Samsung responds with an iris scanner that saves an image of the iris as a world-readable jpeg in your home directory. Thus, their marketing material can claim feature-parity (or even exceed A…

And this is why it makes it so difficult to choose high end phones. I have been shouting about how my Pixel phone is magnitudes better of a device than any other phone I've ever used, including the S8.

On paper it looks awful, but everything this phone does works 100% of the time quickly and without stuttering or failing.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#70
post #39
post #35

Earlier quoted context omitted.

Have you ever been outside? It's dimmer than that.

A nice campfire that noticeably warms your face when you look at it probably gives off a couple orders of magnitude more IR than the phone. IR can damage eyes [1], but the phone probably won't contribute significantly [1] https://www.ncbi.nlm.nih.gov/pmc/articles/PMC3116568/

To be fair a campfire also puts out visible light which can cause you to blink or squint which a "pure IR" light won't.

But the IR from the S8 is still extremely small and safe.

Post reply on HN