Live data from Hacker News

Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

ccc.de

81–90 of 166 posts

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#81

Earlier quoted context omitted.

What programming labor? They just printed a photo and put a lens on it.

I think that tbihl and bebna are trying to say that it would cost Samsung less to defeat the attack by programming one of the listed countermeasures than it cost the CCC folks to buy one of these phones. (I don't agree.)

That is exactly what I meant. Like you're probably thinking, my estimate IS an amateurish one, taking into account no business admin/healthcare/etc. But I remember implementing this (as a small part of a project) at a time when I couldn't be bothered to put more than a few hours into any project. At any rate, I can't explain their failure to implement these checks, because they're SO trivial.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#83

Based on the write-up, Samsung has lower quality Iris recognition than could be written by an undergrad in a few hours. I say that, having done so. Most obviously, the system should not tolerate a constant-size pupil, ever. The pupil has micro-dilations around twice per second, and your system is really terrible if you don't verify that changing diameter. Also, multi-spectral is a pretty good test, though I don't kno…

Samsung always seems to me as if they race to match any iPhone feature–but never more than skin-deep. So when the iPhone gets a fingerprint sensor that saves only a hash of the actual data in a special enclave of a custom chip, Samsung responds with an iris scanner that saves an image of the iris as a world-readable jpeg in your home directory. Thus, their marketing material can claim feature-parity (or even exceed A…

Samsung always seems to me as if they race to match any iPhone feature–but never more than skin-deep

Firstly, any biometric technique can be beaten. Against a known, committed foe, it is almost impossible to defend with surety. And for that matter, who can't obtain the pin code of any other user given a short amount of time and focused attention? The notion that "if someone takes an IR high resolution, close photo of your iris they can defeat your security" is asinine given that the same people could obtain your pin in a million and one ways.

These mechanisms are to induce users to use some security, and the primary defense is against lost or stolen phones, making it convenient enough that it isn't disabled.

Secondly, how did this somehow turn into yet another Royal Apple spiel? Aside from the easy beatability of the Apple fingerprint sensor, why wouldn't you compare the fingerprint sensor on a Samsung?

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#84

Earlier quoted context omitted.

>It's not like Apple doesn't run into similar problems (not sure if the fingerprint sensor has been defeated–it's a bad idea for 5th amendment reasons in any case). But at least they do the minimum in trying. In 2013 a CCC member broke TouchID access within a few hours after release of the IPhone. All needed was a photograph of the fingerprint on a glass surface. https://www.ccc.de/en/updates/2013/ccc-breaks-apple-to…

>All needed was a photograph of the fingerprint on a glass surface. And wood glue! Looks like that method proved unreliable, so they expanded it: "To create the mold, the mask is then used to expose the fingerprint structure on photo-senistive PCB material. The PCB material is then developed, etched and cleaned. After this process, the mold is ready. A thin coat of graphite spray is applied to ensure an improved capa…

Yes. They explained all the innovative magic of Apple's fingerprint sensor was better image resolution. So all they had to do was improving that on their end too. I imagine the body changes everywhere over time, so this resolution game has a hard limit. A fingerprint is the worst choice of biometric data, as people leave them everywhere...

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#86

Earlier quoted context omitted.

>It's not like Apple doesn't run into similar problems (not sure if the fingerprint sensor has been defeated–it's a bad idea for 5th amendment reasons in any case). But at least they do the minimum in trying. In 2013 a CCC member broke TouchID access within a few hours after release of the IPhone. All needed was a photograph of the fingerprint on a glass surface. https://www.ccc.de/en/updates/2013/ccc-breaks-apple-to…

> In 2013 a CCC member broke TouchID access within a few hours after release of the IPhone. It's actually the same guy as with the S8, aka Starbug.

> It's actually the same guy as with the S8, aka Starbug.

Yes, hopefully he will give another talk at 34C3. Very entertaining guy too!

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#87

Earlier quoted context omitted.

>It's not like Apple doesn't run into similar problems (not sure if the fingerprint sensor has been defeated–it's a bad idea for 5th amendment reasons in any case). But at least they do the minimum in trying. In 2013 a CCC member broke TouchID access within a few hours after release of the IPhone. All needed was a photograph of the fingerprint on a glass surface. https://www.ccc.de/en/updates/2013/ccc-breaks-apple-to…

> In 2013 a CCC member broke TouchID access within a few hours after release of the IPhone. It's actually the same guy as with the S8, aka Starbug.

https://media.ccc.de/v/31c3_-_6450_-_de_-_saal_1_-_201412272...

They also managed to get the fingerprint of a politician via a high resolution picture taken at a speech. (Also a phone PIN via eye reflection captured by the front camera.)

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#88

Earlier quoted context omitted.

Spoofing this eye is significantly easier than spoofing a fingerprint, because modern fingerprint technology detect if a fingerprint is "alive" by looking at sweat pores, pulse, veins under the skin and other features of a living finger.

But do phones check for all those markers?

Well, maybe. Usually flagship phones gets the best (most expensive) chips. Budget phones gets knock-offs.

It depends on which fingerprint hw/sw the phone is using. There are about 4 large players in the phone fingerprint chip space that have 90 percent of the market. Fingerprinting is heavily patented so all four vendors have their pros and cons. A few dozen small players competing about 10 percent of the market. They probably don't do much of it.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#89

Based on the write-up, Samsung has lower quality Iris recognition than could be written by an undergrad in a few hours. I say that, having done so. Most obviously, the system should not tolerate a constant-size pupil, ever. The pupil has micro-dilations around twice per second, and your system is really terrible if you don't verify that changing diameter. Also, multi-spectral is a pretty good test, though I don't kno…

Edit: 'micro-oscillation' was a term that I lazily invented to describe a phenomenon with which I am only passingly familiar. It is actually called 'hippus' or ' pupillary athetosis'.
Post reply on HN