Live data from Hacker News

Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

ccc.de

71–80 of 166 posts

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#71

Biometric data is not a password, it's an identity. Fingerprints and iris scans are equivalent to a username or email. To secure a device you need a password. Basics: something you are (iris scan, fingerprint), something you have (2fa token, usb unlock key), something you know (password). One out of 3 is probably not very secure.

Exactly this. We need the big 4 to start pushing this as a standard and with all three passwords can be simpler like 8 alphanumeric characters. There is NO reason that the 2fa can't be built into the mobile OSes and shown on screen/watch with fingerprint verification as the trigger.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#72

Biometric data is not a password, it's an identity. Fingerprints and iris scans are equivalent to a username or email. To secure a device you need a password. Basics: something you are (iris scan, fingerprint), something you have (2fa token, usb unlock key), something you know (password). One out of 3 is probably not very secure.

Phone must automatically lock quite quickly, otherwise somebody quick just grab it after you have unlocked it. This means the password needs to be typed in constantly if you are frequently picking up the phone. Also you often want to grab the phone with one hand, so you need to be able to type the password with one hand. Combine that with the frequent typing and you probably come to conclusion that you can't have a p…

I'd note this is already possible on Android, using 'Smart Lock' - https://support.google.com/nexus/answer/6093922

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#73

Based on the write-up, Samsung has lower quality Iris recognition than could be written by an undergrad in a few hours. I say that, having done so. Most obviously, the system should not tolerate a constant-size pupil, ever. The pupil has micro-dilations around twice per second, and your system is really terrible if you don't verify that changing diameter. Also, multi-spectral is a pretty good test, though I don't kno…

This is remarkable, even though it's obvious to any of their phone users (myself included) that Samsung's software development is shoddy at best, despite its excellent hardware. Which is a huge pity, but may well have something to do with the culture of corporate deference and rigid hierarchy. http://www.asianews.network/content/feature-samsung-debacle-...

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#74
post #8

> The Samsung Galaxy S8 is the first flagship smartphone with iris recognition. That's not quite true, Lumia 950, Lumia 950 XL and HP Elite x3 came out a lot earlier than the Galaxy S8 and all of them use iris recognition (still undefeated, by the way)

There could a bit of a bias, Lumias and HP Elite x3 aren't anywhere near as popular as Samsung Galaxy S8, same as most malware targets Windows rather than Linux/macOS.

I agree the S8 is more widespread than those 3 combined, but those were flagships anyway

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#75

Earlier quoted context omitted.

Samsung always seems to me as if they race to match any iPhone feature–but never more than skin-deep. So when the iPhone gets a fingerprint sensor that saves only a hash of the actual data in a special enclave of a custom chip, Samsung responds with an iris scanner that saves an image of the iris as a world-readable jpeg in your home directory. Thus, their marketing material can claim feature-parity (or even exceed A…

>It's not like Apple doesn't run into similar problems (not sure if the fingerprint sensor has been defeated–it's a bad idea for 5th amendment reasons in any case). But at least they do the minimum in trying. In 2013 a CCC member broke TouchID access within a few hours after release of the IPhone. All needed was a photograph of the fingerprint on a glass surface. https://www.ccc.de/en/updates/2013/ccc-breaks-apple-to…

>All needed was a photograph of the fingerprint on a glass surface.

And wood glue! Looks like that method proved unreliable, so they expanded it:

"To create the mold, the mask is then used to expose the fingerprint structure on photo-senistive PCB material. The PCB material is then developed, etched and cleaned. After this process, the mold is ready. A thin coat of graphite spray is applied to ensure an improved capacitive response. This also makes it easier to remove the fake fingerprint. Finally a thin film of white wood glue is smeared into the mold. After the glue cures the new fake fingerprint is ready for use."

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#76

Earlier quoted context omitted.

Samsung always seems to me as if they race to match any iPhone feature–but never more than skin-deep. So when the iPhone gets a fingerprint sensor that saves only a hash of the actual data in a special enclave of a custom chip, Samsung responds with an iris scanner that saves an image of the iris as a world-readable jpeg in your home directory. Thus, their marketing material can claim feature-parity (or even exceed A…

And this is why it makes it so difficult to choose high end phones. I have been shouting about how my Pixel phone is magnitudes better of a device than any other phone I've ever used, including the S8. On paper it looks awful, but everything this phone does works 100% of the time quickly and without stuttering or failing.

I'm on my second Samsung. First was a very annoying pre-capacitive touch that never worked well. This current one is an old Galaxy S5. It is better, but it likes to restart periodically (fortunately Android handles that well). Battery life is crap and it gets sluggish easily.

Before I had a Motorola. It was much better. I will not buy another Samsung.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#77

Earlier quoted context omitted.

Samsung always seems to me as if they race to match any iPhone feature–but never more than skin-deep. So when the iPhone gets a fingerprint sensor that saves only a hash of the actual data in a special enclave of a custom chip, Samsung responds with an iris scanner that saves an image of the iris as a world-readable jpeg in your home directory. Thus, their marketing material can claim feature-parity (or even exceed A…

>It's not like Apple doesn't run into similar problems (not sure if the fingerprint sensor has been defeated–it's a bad idea for 5th amendment reasons in any case). But at least they do the minimum in trying. In 2013 a CCC member broke TouchID access within a few hours after release of the IPhone. All needed was a photograph of the fingerprint on a glass surface. https://www.ccc.de/en/updates/2013/ccc-breaks-apple-to…

> In 2013 a CCC member broke TouchID access within a few hours after release of the IPhone.

It's actually the same guy as with the S8, aka Starbug.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#78

Biometric data is not a password, it's an identity. Fingerprints and iris scans are equivalent to a username or email. To secure a device you need a password. Basics: something you are (iris scan, fingerprint), something you have (2fa token, usb unlock key), something you know (password). One out of 3 is probably not very secure.

> Basics: something you are (iris scan, fingerprint), something you have (2fa token, usb unlock key), something you know (password). Why complicate things with 2fa tokens. Something you have: the phone! However I agree with something you know being missing.

Sure. But perhaps it should be something you have that isn't the device you're trying to get into.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#79

„But biometric authentication does not fulfill the advertised security promises“ This is completely out of context. For the average smartphone user Iris-Recognition on a phone (just like touch-ID) VS pin-disabled on the phone is a huge step forward.

These are general consumer devices and there are trade offs. The most sophisticated hacker the vast majority of users must defeat is a prying family member or friend.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#80

Biometric data is not a password, it's an identity. Fingerprints and iris scans are equivalent to a username or email. To secure a device you need a password. Basics: something you are (iris scan, fingerprint), something you have (2fa token, usb unlock key), something you know (password). One out of 3 is probably not very secure.

Fingerprints and iris scans are not equivalent to a username or email, since the username and email can be changed easily. Proper biometric data cannot be changed, it is tied to the individual. So when the data is compromised and published in the wild and the devices can be fooled with it (which will always be possible), then the user of biometric recognition devices can become the victim of identity theft for the re…

Good point. It's worse than email or username.
Post reply on HN