Live data from Hacker News

Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

ccc.de

121–130 of 166 posts

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#121

Earlier quoted context omitted.

Yes. They explained all the innovative magic of Apple's fingerprint sensor was better image resolution. So all they had to do was improving that on their end too. I imagine the body changes everywhere over time, so this resolution game has a hard limit. A fingerprint is the worst choice of biometric data, as people leave them everywhere...

People don't leave perfect moldae prints everywhere. AFAIK CCC never had a proof of concept of a real world usage of this. They needed access the original finger. That isn't to say it's not possible but it is a pretty major asterisk.

They did it also with a simple press photo of a politician.

There's no need to get a perfect copy.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#122
post #54

Earlier quoted context omitted.

A random photo on the net probably doesn't have the resolution needed for Iris recognition

The CCC used an old digicam at medium distance. It is quite likely that such a photo is on FB, Instagram etc. Side note: The CCC even recovered the fingerprint of the Germany's defense minister from a photo: https://www.theguardian.com/technology/2014/dec/30/hacker-fa...

They also used the IR mode of a digicam. That hack is not possible from existing photos only, I think.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#123
post #14

>Iris recognition may be barely sufficient to protect a phone against complete strangers unlocking it I suppose that's the attack scenario those systems (at least in phones) are supposed to protect against, to be fair. Suppose the alternative might be that some users use a predictable pin or none at all. Fingerprints or the iris sensor is an improvement for them because they are quick and easy to use. Of course it's…

>Fingerprints or the iris sensor is an improvement for them because they are quick and easy to use. I'm not sure about it being an improvement, human laziness always finds a way to make something less secure. Like buying "fingerprint stickers" because too lazy to pull off a glove when wanting to unlock the phone [0]. The CCC always does interesting stuff like this, a couple of years they reproduced a politicians fing…

> The CCC always does interesting stuff like this, a couple of years they reproduced a politicians fingerprint just using photos of her hands.

That was actually the same guy.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#124

Earlier quoted context omitted.

Yes. They explained all the innovative magic of Apple's fingerprint sensor was better image resolution. So all they had to do was improving that on their end too. I imagine the body changes everywhere over time, so this resolution game has a hard limit. A fingerprint is the worst choice of biometric data, as people leave them everywhere...

People don't leave perfect moldae prints everywhere. AFAIK CCC never had a proof of concept of a real world usage of this. They needed access the original finger. That isn't to say it's not possible but it is a pretty major asterisk.

Didn't some group pull a politician's finger print off his dinner glass and then include it as an insert with all the issues of some magazine?

Can't find the reference right now, but somebody's gotta remember this, it was when the UK was considering using biometric data as IDs.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#125

Earlier quoted context omitted.

Samsung always seems to me as if they race to match any iPhone feature–but never more than skin-deep. So when the iPhone gets a fingerprint sensor that saves only a hash of the actual data in a special enclave of a custom chip, Samsung responds with an iris scanner that saves an image of the iris as a world-readable jpeg in your home directory. Thus, their marketing material can claim feature-parity (or even exceed A…

>It's not like Apple doesn't run into similar problems (not sure if the fingerprint sensor has been defeated–it's a bad idea for 5th amendment reasons in any case). But at least they do the minimum in trying. In 2013 a CCC member broke TouchID access within a few hours after release of the IPhone. All needed was a photograph of the fingerprint on a glass surface. https://www.ccc.de/en/updates/2013/ccc-breaks-apple-to…

AS i have come to understand it, biometrics is a good identifier (telling who you are) but a lousy authenticator (telling that you are allowed).

The use of biometrics on mobile devices somewhat mix this, with the assumption that if some user was authenticated within a certain time frame (via a pin or some other knowledge bound check), a simple id is enough to extend that authentication.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#126

Earlier quoted context omitted.

So what's better, then? Tongueprint? I'm down to lick my phone to turn it on.

Tongue prints work fine on typical phone fingerprint readers, so it is an option.

And you know this because you tried it? LOL :)

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#127

Earlier quoted context omitted.

People don't leave perfect moldae prints everywhere. AFAIK CCC never had a proof of concept of a real world usage of this. They needed access the original finger. That isn't to say it's not possible but it is a pretty major asterisk.

Didn't some group pull a politician's finger print off his dinner glass and then include it as an insert with all the issues of some magazine? Can't find the reference right now, but somebody's gotta remember this, it was when the UK was considering using biometric data as IDs.

That was CCC in 2008. To underscore the inherent problems of biometric authentication, they pulled Wolfgang Schäuble's fingerprints of a dinner glass and published it in their magazine. That issue also included a ready-to-use replica. Schäuble was Germany's interior minister at the time and a strong proponent of biometric data in passports and increased surveillance.

https://www.ccc.de/updates/2008/schaubles-finger (in German)

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#128
post #86

Earlier quoted context omitted.

> In 2013 a CCC member broke TouchID access within a few hours after release of the IPhone. It's actually the same guy as with the S8, aka Starbug.

> It's actually the same guy as with the S8, aka Starbug. Yes, hopefully he will give another talk at 34C3. Very entertaining guy too!

No need to wait for 34c3, he's giving a 30 minute talk at Gulaschprogrammiernacht in Karlsruhe on Thursday: https://entropia.de/GPN17:hacking_galaxy_S8_iris_recognition

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#129

The important thing is how much more/less difficult is this than spoofing a fingerprint. If it is significantly harder, I still see it as a win for samsung's security.

Spoofing this eye is significantly easier than spoofing a fingerprint, because modern fingerprint technology detect if a fingerprint is "alive" by looking at sweat pores, pulse, veins under the skin and other features of a living finger.

CCC reported that they managed to bypass Apple's Touch ID in 2013, so it doesn't really seem like one is easier than the other.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#130
post #23

„But biometric authentication does not fulfill the advertised security promises“ This is completely out of context. For the average smartphone user Iris-Recognition on a phone (just like touch-ID) VS pin-disabled on the phone is a huge step forward.

The trouble with statements like 'for the average xyz user' is: 1. 50% of your users won't have their needs met - that's a large proportion assuming a uniform distribution 2. We can't be sure a uniform distribution in the first place is appropriate 3. If we're going to assume an average user then why don't we assume an average phone too: If the average user gets by without something today then why bother building it…

> The trouble with statements like 'for the average xyz user' is: 1. 50% of your users won't have their needs met

Oh come on. You know what's meant: no nerds. That's 99% of users who'll have their needs met, not 50%.

Post reply on HN