Earlier quoted context omitted.
Tongue prints work fine on typical phone fingerprint readers, so it is an option.
And you know this because you tried it? LOL :)
Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
141–150 of 166 posts
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#142Earlier quoted context omitted.
Yes. They explained all the innovative magic of Apple's fingerprint sensor was better image resolution. So all they had to do was improving that on their end too. I imagine the body changes everywhere over time, so this resolution game has a hard limit. A fingerprint is the worst choice of biometric data, as people leave them everywhere...
So what's better, then? Tongueprint? I'm down to lick my phone to turn it on.
How is the iris scanner on Microsoft phones in comparison?
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#143Earlier quoted context omitted.
Samsung always seems to me as if they race to match any iPhone feature–but never more than skin-deep Firstly, any biometric technique can be beaten. Against a known, committed foe, it is almost impossible to defend with surety. And for that matter, who can't obtain the pin code of any other user given a short amount of time and focused attention? The notion that "if someone takes an IR high resolution, close photo of…
> ...if someone takes an IR high resolution, close photo of your iris they can defeat your security... There are commercial security products that regularly perform "IR high resolution" iris scans from several meters away and require no cooperation from the target. Stanley CSS sold one that sat on top of a doorway over five years ago, their product literature says that you need to look at it - but having demoed it my…
Until CCC approves your CSS I will consider it insecure.
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#144Earlier quoted context omitted.
> ...if someone takes an IR high resolution, close photo of your iris they can defeat your security... There are commercial security products that regularly perform "IR high resolution" iris scans from several meters away and require no cooperation from the target. Stanley CSS sold one that sat on top of a doorway over five years ago, their product literature says that you need to look at it - but having demoed it my…
Have any real security researchers have tried to analyze and break this one? Until CCC approves your CSS I will consider it insecure.
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#145Earlier quoted context omitted.
Samsung always seems to me as if they race to match any iPhone feature–but never more than skin-deep. So when the iPhone gets a fingerprint sensor that saves only a hash of the actual data in a special enclave of a custom chip, Samsung responds with an iris scanner that saves an image of the iris as a world-readable jpeg in your home directory. Thus, their marketing material can claim feature-parity (or even exceed A…
Samsung always seems to me as if they race to match any iPhone feature–but never more than skin-deep Firstly, any biometric technique can be beaten. Against a known, committed foe, it is almost impossible to defend with surety. And for that matter, who can't obtain the pin code of any other user given a short amount of time and focused attention? The notion that "if someone takes an IR high resolution, close photo of…
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#146Based on the write-up, Samsung has lower quality Iris recognition than could be written by an undergrad in a few hours. I say that, having done so. Most obviously, the system should not tolerate a constant-size pupil, ever. The pupil has micro-dilations around twice per second, and your system is really terrible if you don't verify that changing diameter. Also, multi-spectral is a pretty good test, though I don't kno…
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#147Earlier quoted context omitted.
You'd think so, but iPhones are incredibly useful to blind people. https://finance.yahoo.com/news/david-pogue-on-iphone-voiceov...
The first time I saw a blind person using an iPhone on the subway (years ago, I think it was an iPhone 4), I was completely blown away at how much he could do with it. Personally I think apple should allow you to turn the backlight for the screen off entirely for their use. Perfect over the shoulder privacy and better battery life to boot!
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#148Earlier quoted context omitted.
I'd note this is already possible on Android, using 'Smart Lock' - https://support.google.com/nexus/answer/6093922
Not really. Quoting GP: I think a good balance between security and usability would be to allow fingerprint or iris scan when the phone has been constantly in my proximity but require a pin (password) if the phone is taken away. The proximity could be determined for example by pairing the phone with smart watch. When combined with a fingerprint sensor, smart lock keeps the device completely unlocked while "triggered"…
I'd love to have features where the fingerprint is only good enough under certain circumstances, such when the phone hasn't been idle for too long, or when combined with an RFID tag.
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#149To those who know german, I recommend watching the german video.
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#150Earlier quoted context omitted.
> ...if someone takes an IR high resolution, close photo of your iris they can defeat your security... There are commercial security products that regularly perform "IR high resolution" iris scans from several meters away and require no cooperation from the target. Stanley CSS sold one that sat on top of a doorway over five years ago, their product literature says that you need to look at it - but having demoed it my…
Have any real security researchers have tried to analyze and break this one? Until CCC approves your CSS I will consider it insecure.