Live data from Hacker News

Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

ccc.de

131–140 of 166 posts

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#131

Earlier quoted context omitted.

Edit: 'micro-oscillation' was a term that I lazily invented to describe a phenomenon with which I am only passingly familiar. It is actually called 'hippus' or ' pupillary athetosis'.

Have you read George Orwell's "Politics and the English Language"? If not you should give it a read, it's short. This comment reminded me of his criticism related to Latin usage.

I have now! Hopefully you're accusing me only of saying 'micro-oscillations' when I ought to have said "shrinks and swells slightly at regular intervals."

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#132
post #93

Earlier quoted context omitted.

Well, maybe. Usually flagship phones gets the best (most expensive) chips. Budget phones gets knock-offs. It depends on which fingerprint hw/sw the phone is using. There are about 4 large players in the phone fingerprint chip space that have 90 percent of the market. Fingerprinting is heavily patented so all four vendors have their pros and cons. A few dozen small players competing about 10 percent of the market. The…

Do you know where I could read more about the ways fingerprint scanner detect that it's a human finger? Sounds pretty fascinating.

Just do an internet search for "fingerprint liveness detection". Google Scholar has enough reading for a night or two.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#133
post #129

Earlier quoted context omitted.

Spoofing this eye is significantly easier than spoofing a fingerprint, because modern fingerprint technology detect if a fingerprint is "alive" by looking at sweat pores, pulse, veins under the skin and other features of a living finger.

CCC reported that they managed to bypass Apple's Touch ID in 2013, so it doesn't really seem like one is easier than the other.

AppleID from 2013 may not have included all the features of AppleID in 2017.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#134

Earlier quoted context omitted.

So what's better, then? Tongueprint? I'm down to lick my phone to turn it on.

Tongue prints work fine on typical phone fingerprint readers, so it is an option.

I tried my noose tip and and tonge, neither worked (Huawei). Toes work (obviously).

People reported that pet's pawns work.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#135

Earlier quoted context omitted.

If someone with a glass eye is using a smartphone then one would suspect they are seeing their other, real, eye. This can then be scanned as normal.

You'd think so, but iPhones are incredibly useful to blind people. https://finance.yahoo.com/news/david-pogue-on-iphone-voiceov...

The first time I saw a blind person using an iPhone on the subway (years ago, I think it was an iPhone 4), I was completely blown away at how much he could do with it.

Personally I think apple should allow you to turn the backlight for the screen off entirely for their use. Perfect over the shoulder privacy and better battery life to boot!

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#136

Earlier quoted context omitted.

Samsung always seems to me as if they race to match any iPhone feature–but never more than skin-deep. So when the iPhone gets a fingerprint sensor that saves only a hash of the actual data in a special enclave of a custom chip, Samsung responds with an iris scanner that saves an image of the iris as a world-readable jpeg in your home directory. Thus, their marketing material can claim feature-parity (or even exceed A…

Samsung always seems to me as if they race to match any iPhone feature–but never more than skin-deep Firstly, any biometric technique can be beaten. Against a known, committed foe, it is almost impossible to defend with surety. And for that matter, who can't obtain the pin code of any other user given a short amount of time and focused attention? The notion that "if someone takes an IR high resolution, close photo of…

> ...if someone takes an IR high resolution, close photo of your iris they can defeat your security...

There are commercial security products that regularly perform "IR high resolution" iris scans from several meters away and require no cooperation from the target. Stanley CSS sold one that sat on top of a doorway over five years ago, their product literature says that you need to look at it - but having demoed it myself, I can say that is not true.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#137

Biometric data is not a password, it's an identity. Fingerprints and iris scans are equivalent to a username or email. To secure a device you need a password. Basics: something you are (iris scan, fingerprint), something you have (2fa token, usb unlock key), something you know (password). One out of 3 is probably not very secure.

The password model on Google's version of Android and iOS (as examples) is not biometric based. You need the password every few hours (at least on Android, not sure about iOS) and whenever you restart. The biometric is a keep alive for that "session". For my threat model, that's sufficient. For many, that is sufficient. For some, it absolutely is not and they should disable biometrics entirely. .

iOS requires a password after a reboot, after 24-48 hours of inactivity or after several failed attempts with the fingerprint.

I'm glad it's not every few hours because my iPhone password is quite long.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#138

Earlier quoted context omitted.

Phone must automatically lock quite quickly, otherwise somebody quick just grab it after you have unlocked it. This means the password needs to be typed in constantly if you are frequently picking up the phone. Also you often want to grab the phone with one hand, so you need to be able to type the password with one hand. Combine that with the frequent typing and you probably come to conclusion that you can't have a p…

An encrypted NFC or Bluetooth bracelet, one sold with or separately to a phone would be nice. Pings it every so often. If it can't find it, automatically self locks. If it can't find for for X number of days and a password hasn't been entered in that time then it wipes || locks the phone.

[deleted]

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#139

Earlier quoted context omitted.

Phone must automatically lock quite quickly, otherwise somebody quick just grab it after you have unlocked it. This means the password needs to be typed in constantly if you are frequently picking up the phone. Also you often want to grab the phone with one hand, so you need to be able to type the password with one hand. Combine that with the frequent typing and you probably come to conclusion that you can't have a p…

An encrypted NFC or Bluetooth bracelet, one sold with or separately to a phone would be nice. Pings it every so often. If it can't find it, automatically self locks. If it can't find for for X number of days and a password hasn't been entered in that time then it wipes || locks the phone.

> n encrypted NFC or Bluetooth bracelet

Should be significantly more secure than Mifare though. Ideally something like a contactless OpenGPG card or similar.

Recently I searched for passive NFC ICs that'd be suitable for implementing that, but came up empty. Usecase was exactly that: A NFC device located at about the wrist. My laptop has a NFC reader at just the right place of the handrest to read it. And I'd probably transplant a NFC reader into my desktop computer's keyboard for the same purpose.

But first I'd need that NFC thingy.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#140

Earlier quoted context omitted.

Samsung always seems to me as if they race to match any iPhone feature–but never more than skin-deep. So when the iPhone gets a fingerprint sensor that saves only a hash of the actual data in a special enclave of a custom chip, Samsung responds with an iris scanner that saves an image of the iris as a world-readable jpeg in your home directory. Thus, their marketing material can claim feature-parity (or even exceed A…

>It's not like Apple doesn't run into similar problems (not sure if the fingerprint sensor has been defeated–it's a bad idea for 5th amendment reasons in any case). But at least they do the minimum in trying. In 2013 a CCC member broke TouchID access within a few hours after release of the IPhone. All needed was a photograph of the fingerprint on a glass surface. https://www.ccc.de/en/updates/2013/ccc-breaks-apple-to…

> Biometry is fundamentally broken.

"fingerprints are usernames, not passwords" is the standard advice I've read.

Post reply on HN