Live data from Hacker News

Fingerprints can be hacked

blog.kraken.com

261–270 of 333 posts

Re: Fingerprints can be hacked

#261
post #91

Earlier quoted context omitted.

> State driver license in USA In which states? The only thing I have been fingerprinted for is in the US is The Global Entry program.

More and more states require fingerprints for driver licenses because of the RealID program. Eventually (soonish) you won't be able to use your driver license to fly without it being RealID compliant. One state I lived in gave me the option of not having a RealID-compliant license if I wanted to. Another didn't, so fingerprints were compulsory.

No, Real ID doesn't require fingerprints, my state issues Real IDs (I have one) and they don't fingerprint anyone.

Re: Fingerprints can be hacked

#262
post #2

My favorite photograph of a fingerprint is when the Chaos Computer Club reproduced the German Foreign ministers fingerprint from a photo. So much for military grade security. https://www.dw.com/en/german-defense-minister-von-der-leyens... - The core problems with biometrics are that: 1) Not revokable (unlike compromised credentials) 2) Not a secret 3) Usually trivial to reproduce and spoof (even "liveliness" tests)

Just a remark: the person whose fingerprints have been reconstructed and that was the defense minister of Germany at time of the stunt (Ursula von der Leyen), is now the president of the European Commission (~= head of the EU government).

Re: Fingerprints can be hacked

#263

Earlier quoted context omitted.

Or err heavily on reducing the release of the guilty, depending on the region.

> Or err heavily on reducing the release of the guilty, depending on the region. This is antithetical to the concept of serving one’s time. Guilty people deserve to go free once their debt to society has been fulfilled.

I'm referring to what people select for with law.

https://en.wikipedia.org/wiki/Blackstone%27s_ratio

Does a law system let some guilty people got free to avoid incarcerating the innocent, or does it incarcerate the innocent to avoid letting some guilty people go free?

My opinion is to lean towards letting the guilty go to avoid incarcerating the innocent, but other people in other places can lean the other direction.

Re: Fingerprints can be hacked

#264
post #213
post #201

Earlier quoted context omitted.

At least on iPhones though they have a way to activate a mode that prevents the use of TouchID and FaceID. If I press the power button on my phone 5 times in a row that turns that off. Yes I still run the risk of my device being unlocked against my will if I'm caught by surprise. But I'm able to disable this functionality in places where I think the risk of that may be higher, e.g. while traveling. I'll still take th…

On modern FaceID phones you need to hold the power and down volume key to bring up the Reset/PowerOff and cancel. Just clicking multiple times will bring up wallet, siri, or do nothing.

Just hit the power button 5 times on my iPhone 13 Pro, and it locked down FaceID as I'd expect (while bringing up the Reset/Power Off screen). You've described an alternative method, not the only.

Re: Fingerprints can be hacked

#265
If we had asked people thirty years ago whether a single company, not a police department or other government agency, could, with consent, collect the most human fingerprints in history, would people have been likely to point out various obstacles and/or doubt it was even possible. Further, would they ever agree that these prints could be collected not for employee access to company resources but for access to people's own personal effects! (Company retains remote access to devices storing personal effects.)

Re: Fingerprints can be hacked

#266

If we had asked people thirty years ago whether a single company, not a police department or other government agency, could, with consent, collect the most human fingerprints in history, would people have been likely to point out various obstacles and/or doubt it was even possible. Further, would they ever agree that these prints could be collected not for employee access to company resources but for access to people…

Any good implementation has fingerprint information stored locally, encrypted, and never transmitted off device.

Re: Fingerprints can be hacked

#267
post #213

Earlier quoted context omitted.

On modern FaceID phones you need to hold the power and down volume key to bring up the Reset/PowerOff and cancel. Just clicking multiple times will bring up wallet, siri, or do nothing.

Just hit the power button 5 times on my iPhone 13 Pro, and it locked down FaceID as I'd expect (while bringing up the Reset/Power Off screen). You've described an alternative method, not the only.

Which OS are you updated to (no please don't post it)? not 15.1.x? Have you disabled wallet, Siri, and SOS? It doesn't work on any of the 5x 12s and 13s (pro and not) I just tried. It did work on an 11, which was not updated to 15.

You also risk the accidental activation of an SOS call.

Re: Fingerprints can be hacked

#268
post #2

My favorite photograph of a fingerprint is when the Chaos Computer Club reproduced the German Foreign ministers fingerprint from a photo. So much for military grade security. https://www.dw.com/en/german-defense-minister-von-der-leyens... - The core problems with biometrics are that: 1) Not revokable (unlike compromised credentials) 2) Not a secret 3) Usually trivial to reproduce and spoof (even "liveliness" tests)

I’ve always thought it’s really silly to use something you leave on everything you touch as a credential.

Re: Fingerprints can be hacked

#269
post #2

My favorite photograph of a fingerprint is when the Chaos Computer Club reproduced the German Foreign ministers fingerprint from a photo. So much for military grade security. https://www.dw.com/en/german-defense-minister-von-der-leyens... - The core problems with biometrics are that: 1) Not revokable (unlike compromised credentials) 2) Not a secret 3) Usually trivial to reproduce and spoof (even "liveliness" tests)

In the case of Apple’s TouchID, the fingerprint is less a password and more of a session extender. You need to login with ID and password to establish a session. Then the fingerprint gives you access to that session. Once the session ends, you need to reestablish your credentials.

This obviously not as secure as a system when you must use your credentials frequently to maintain access, but it seems entirely appropriate for the level of security needed by most individuals on their phones. Especially as the alternative is often a super simple password or even no password at all. TouchID makes a moderate level of security palatable enough for people to actually use.

Re: Fingerprints can be hacked

#270

Earlier quoted context omitted.

Why in the world would you need CRISPR or lab grown meat? Just sequence the DNA and send it off to a DNA assembly service. The price is a couple hundred bucks a pop. You don't have to replicate the entire DNA, just the segments used for forensic PCR. (On a side note, the state of biotechnology and life science knowledge on HN is utterly deplorable, repeating buzz words does not reality make.)

And what is involved in the DNA sequencing? And the DNA assembly service will probably take record of the operation itself (it is not a common service). In the context...

OP was referring to state level actors.
Post reply on HN