Live data from Hacker News

Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

ccc.de

161–166 of 166 posts

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#161
post #8

> The Samsung Galaxy S8 is the first flagship smartphone with iris recognition. That's not quite true, Lumia 950, Lumia 950 XL and HP Elite x3 came out a lot earlier than the Galaxy S8 and all of them use iris recognition (still undefeated, by the way)

There could a bit of a bias, Lumias and HP Elite x3 aren't anywhere near as popular as Samsung Galaxy S8, same as most malware targets Windows rather than Linux/macOS.

It's not bias just normal ignorance.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#162

Earlier quoted context omitted.

>It's not like Apple doesn't run into similar problems (not sure if the fingerprint sensor has been defeated–it's a bad idea for 5th amendment reasons in any case). But at least they do the minimum in trying. In 2013 a CCC member broke TouchID access within a few hours after release of the IPhone. All needed was a photograph of the fingerprint on a glass surface. https://www.ccc.de/en/updates/2013/ccc-breaks-apple-to…

AS i have come to understand it, biometrics is a good identifier (telling who you are) but a lousy authenticator (telling that you are allowed). The use of biometrics on mobile devices somewhat mix this, with the assumption that if some user was authenticated within a certain time frame (via a pin or some other knowledge bound check), a simple id is enough to extend that authentication.

> authenticator

Authorization is the counterpart to Authentication: authentication proves who you are (with passwords/tokens/biometrics aka something you know/have/are), authorization controls what you can do (with permissions/ACLs/roles/etc.)

To put it another way, the bouncer at a club checks your photo ID to see that you match it (authentication via something you are), then uses it to see if you can enter (authorization by checking your birthdate against a cut-off/name against a guestlist).

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#163
post #73

Earlier quoted context omitted.

This is remarkable, even though it's obvious to any of their phone users (myself included) that Samsung's software development is shoddy at best, despite its excellent hardware. Which is a huge pity, but may well have something to do with the culture of corporate deference and rigid hierarchy. http://www.asianews.network/content/feature-samsung-debacle-...

why would that only affect their software, but not hardware? While I agree that Samsung is at its core a hardware company and software engineers are still treated like second-class citizens, you can't just expect them to compete with Google or Microsoft overnight, IMO. I'm disinclined to believe that their military-like corporate hierarchy is to blame.

I don't know: perhaps that the company's structures work better for their core expertises, hardware, but software development, perhaps something that came somewhat later and lower down the hierarchy, doesn't work so well in that context?

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#164

Based on the write-up, Samsung has lower quality Iris recognition than could be written by an undergrad in a few hours. I say that, having done so. Most obviously, the system should not tolerate a constant-size pupil, ever. The pupil has micro-dilations around twice per second, and your system is really terrible if you don't verify that changing diameter. Also, multi-spectral is a pretty good test, though I don't kno…

[deleted]

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#165
post #148
post #97

Earlier quoted context omitted.

Not really. Quoting GP: I think a good balance between security and usability would be to allow fingerprint or iris scan when the phone has been constantly in my proximity but require a pin (password) if the phone is taken away. The proximity could be determined for example by pairing the phone with smart watch. When combined with a fingerprint sensor, smart lock keeps the device completely unlocked while "triggered"…

Yeah, the Smart Lock functionality doesn't really support configuring your own primary-vs-fallback behavior. I'd love to have features where the fingerprint is only good enough under certain circumstances, such when the phone hasn't been idle for too long, or when combined with an RFID tag.

You are correct, it's not a perfect system or perfect solution. No security system is perfect.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#166

Biometric data is not a password, it's an identity. Fingerprints and iris scans are equivalent to a username or email. To secure a device you need a password. Basics: something you are (iris scan, fingerprint), something you have (2fa token, usb unlock key), something you know (password). One out of 3 is probably not very secure.

Fingerprints and iris scans are not equivalent to a username or email, since the username and email can be changed easily. Proper biometric data cannot be changed, it is tied to the individual. So when the data is compromised and published in the wild and the devices can be fooled with it (which will always be possible), then the user of biometric recognition devices can become the victim of identity theft for the re…

Fingerprints are not hard to obtain at all. As a matter of fact, fingerprints are easy to obtain.
Post reply on HN