Earlier quoted context omitted.
Edit: 'micro-oscillation' was a term that I lazily invented to describe a phenomenon with which I am only passingly familiar. It is actually called 'hippus' or ' pupillary athetosis'.
Have you read George Orwell's "Politics and the English Language"? If not you should give it a read, it's short. This comment reminded me of his criticism related to Latin usage.
Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
131–140 of 166 posts
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#132Earlier quoted context omitted.
Well, maybe. Usually flagship phones gets the best (most expensive) chips. Budget phones gets knock-offs. It depends on which fingerprint hw/sw the phone is using. There are about 4 large players in the phone fingerprint chip space that have 90 percent of the market. Fingerprinting is heavily patented so all four vendors have their pros and cons. A few dozen small players competing about 10 percent of the market. The…
Do you know where I could read more about the ways fingerprint scanner detect that it's a human finger? Sounds pretty fascinating.
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#133Earlier quoted context omitted.
Spoofing this eye is significantly easier than spoofing a fingerprint, because modern fingerprint technology detect if a fingerprint is "alive" by looking at sweat pores, pulse, veins under the skin and other features of a living finger.
CCC reported that they managed to bypass Apple's Touch ID in 2013, so it doesn't really seem like one is easier than the other.
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#134Earlier quoted context omitted.
So what's better, then? Tongueprint? I'm down to lick my phone to turn it on.
Tongue prints work fine on typical phone fingerprint readers, so it is an option.
People reported that pet's pawns work.
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#135Earlier quoted context omitted.
If someone with a glass eye is using a smartphone then one would suspect they are seeing their other, real, eye. This can then be scanned as normal.
You'd think so, but iPhones are incredibly useful to blind people. https://finance.yahoo.com/news/david-pogue-on-iphone-voiceov...
Personally I think apple should allow you to turn the backlight for the screen off entirely for their use. Perfect over the shoulder privacy and better battery life to boot!
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#136Earlier quoted context omitted.
Samsung always seems to me as if they race to match any iPhone feature–but never more than skin-deep. So when the iPhone gets a fingerprint sensor that saves only a hash of the actual data in a special enclave of a custom chip, Samsung responds with an iris scanner that saves an image of the iris as a world-readable jpeg in your home directory. Thus, their marketing material can claim feature-parity (or even exceed A…
Samsung always seems to me as if they race to match any iPhone feature–but never more than skin-deep Firstly, any biometric technique can be beaten. Against a known, committed foe, it is almost impossible to defend with surety. And for that matter, who can't obtain the pin code of any other user given a short amount of time and focused attention? The notion that "if someone takes an IR high resolution, close photo of…
There are commercial security products that regularly perform "IR high resolution" iris scans from several meters away and require no cooperation from the target. Stanley CSS sold one that sat on top of a doorway over five years ago, their product literature says that you need to look at it - but having demoed it myself, I can say that is not true.
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#137Biometric data is not a password, it's an identity. Fingerprints and iris scans are equivalent to a username or email. To secure a device you need a password. Basics: something you are (iris scan, fingerprint), something you have (2fa token, usb unlock key), something you know (password). One out of 3 is probably not very secure.
The password model on Google's version of Android and iOS (as examples) is not biometric based. You need the password every few hours (at least on Android, not sure about iOS) and whenever you restart. The biometric is a keep alive for that "session". For my threat model, that's sufficient. For many, that is sufficient. For some, it absolutely is not and they should disable biometrics entirely. .
I'm glad it's not every few hours because my iPhone password is quite long.
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#138Earlier quoted context omitted.
Phone must automatically lock quite quickly, otherwise somebody quick just grab it after you have unlocked it. This means the password needs to be typed in constantly if you are frequently picking up the phone. Also you often want to grab the phone with one hand, so you need to be able to type the password with one hand. Combine that with the frequent typing and you probably come to conclusion that you can't have a p…
An encrypted NFC or Bluetooth bracelet, one sold with or separately to a phone would be nice. Pings it every so often. If it can't find it, automatically self locks. If it can't find for for X number of days and a password hasn't been entered in that time then it wipes || locks the phone.
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#139Earlier quoted context omitted.
Phone must automatically lock quite quickly, otherwise somebody quick just grab it after you have unlocked it. This means the password needs to be typed in constantly if you are frequently picking up the phone. Also you often want to grab the phone with one hand, so you need to be able to type the password with one hand. Combine that with the frequent typing and you probably come to conclusion that you can't have a p…
An encrypted NFC or Bluetooth bracelet, one sold with or separately to a phone would be nice. Pings it every so often. If it can't find it, automatically self locks. If it can't find for for X number of days and a password hasn't been entered in that time then it wipes || locks the phone.
Should be significantly more secure than Mifare though. Ideally something like a contactless OpenGPG card or similar.
Recently I searched for passive NFC ICs that'd be suitable for implementing that, but came up empty. Usecase was exactly that: A NFC device located at about the wrist. My laptop has a NFC reader at just the right place of the handrest to read it. And I'd probably transplant a NFC reader into my desktop computer's keyboard for the same purpose.
But first I'd need that NFC thingy.
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#140Earlier quoted context omitted.
Samsung always seems to me as if they race to match any iPhone feature–but never more than skin-deep. So when the iPhone gets a fingerprint sensor that saves only a hash of the actual data in a special enclave of a custom chip, Samsung responds with an iris scanner that saves an image of the iris as a world-readable jpeg in your home directory. Thus, their marketing material can claim feature-parity (or even exceed A…
>It's not like Apple doesn't run into similar problems (not sure if the fingerprint sensor has been defeated–it's a bad idea for 5th amendment reasons in any case). But at least they do the minimum in trying. In 2013 a CCC member broke TouchID access within a few hours after release of the IPhone. All needed was a photograph of the fingerprint on a glass surface. https://www.ccc.de/en/updates/2013/ccc-breaks-apple-to…
"fingerprints are usernames, not passwords" is the standard advice I've read.