Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

11–20 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#12
I'd be interested on peoples' opinions, is this more or less secure than a 4-digit passcode?

From a real security perspective, users should have alphanumeric password, as far as I know, businesses often enforce this.

Obviously a 4-digit code is easy to brute-force on a computer, but it requires far more technical knowledge to do so - booting custom firmware, using some script to brute force, etc, and if the attacker doesn't have the skills, they are limited to 10 tries, maybe more after waiting a few minutes or an hour.

It seems to me that, excluding users leaving smudges on their screen and seeing the passcode that way, a fingerprint is even easier to break than a 4-digit passcode.

Re: Chaos Computer Club breaks Apple TouchID

#13

The "How to fake fingerprints" link [1], is one of the scariest things I have seen, given how simple it is, and how much we reply on fingerprints for linking people to crimes. BTW, for anyone who does not know about Chaos Computer Club (CCC) [2], they run a massive conference in EU. You can look at some of their talks @ http://media.ccc.de/ [1] http://dasalte.ccc.de/biometrie/fingerabdruck_kopieren?langu... [2] http:…

Frontline had an excellent piece on the (lack of) reliability behind most of crime forensics. Fingerprints in particular are mentioned as being very unreliable and unscientific. The only scientifically rigorous piece of "CSI" is DNA matching.

http://www.pbs.org/wgbh/pages/frontline/real-csi/

Re: Chaos Computer Club breaks Apple TouchID

#14
I have accidentally seen basically all of my friends' passcodes as they type it in at bars etc. I could get into their phones easily. TouchID is more secure than that simply because someone needs to take a 2400dpi image of the person's finger to do it.

Locks (when physical access to a device is available) are to keep honest people honest. Most security experts that I know agree that if an intruder has physical access to a device, it can be considered compromised because it is just a matter of time.

Re: Chaos Computer Club breaks Apple TouchID

#15
If we've learned anything over the past few months, it is that security is an illusion when it comes to Google, Apple and Facebook.

The fingerprint scanner is not intended to protect your personal data from being accessed by nefarious cyber-spooks or crackers. The $5 dollar wrench technique is fairly effective in bypassing such security anyway.

The fingerprint scanner is there so that when your phone is nicked by a mugger, they can't reset to factory defaults and sell it on eBay. If some knife wielding thug that robs me of my phone has the intellectual capability of lifting my fingerprints off the case and then using them to bypass the security, he still has to know my AppleID password before he can remove the 'Find my Phone' feature.

Give Apple a break. This is just another layer of security. It's _not_ the panacea to all our security woes, and they have never claimed it was.

Re: Chaos Computer Club breaks Apple TouchID

#16
Of course they have broken it, I had no doubt it would be broken like any other fingerprint security system.

The issue here is that it's ok, it doesn't really matter. It is all about the amount of security you need. Does a normal user need unbreakable security? No. The security provided with this method is more than ok, it is kinda secure and it's faster (imho) than writing your passcode. After all your "enemies" here are nosy friends or similar...

If you need "unbreakable" security then you shouldn't use iphone or android, or you should use an specific secure storage application (cyphered content, hard to guess pass or whatever). If you need "unbreakable" security you better consider hiring a security consultant.

So, the question here is, are the security systems in mobile devices more than fine for most normal users? I guess so...

Re: Chaos Computer Club breaks Apple TouchID

#17
post #2

Kind of a "well duh" post. All of the image scan finger print readers are easy to game. Even the ones that use capacitance can be beaten with a rubber glove and a copy of the finger print, printed on the latex. (the best is actually an Vinyl condom that doesn't come pre-lubed, the ink sticks better and the vinyl is less of an insulator)

The problem is that Apple made a big deal in the announcement about how it was so much more secure than previous implementations, how it used sub-dermal imaging and stuff like that. It appeared from what they were saying, that this would be considerably harder to fake.

Re: Chaos Computer Club breaks Apple TouchID

#18

If we've learned anything over the past few months, it is that security is an illusion when it comes to Google, Apple and Facebook. The fingerprint scanner is not intended to protect your personal data from being accessed by nefarious cyber-spooks or crackers. The $5 dollar wrench technique is fairly effective in bypassing such security anyway. The fingerprint scanner is there so that when your phone is nicked by a m…

Giving Apple a break? Just another layer of security? That's not how Apple describes it:

http://support.apple.com/kb/HT5949?viewlocale=en_US

And selling a stolen iPhone on eBay does not need a password or a fingerprint, a jailbreak is enough …

Re: Chaos Computer Club breaks Apple TouchID

#19

I'd be interested on peoples' opinions, is this more or less secure than a 4-digit passcode? From a real security perspective, users should have alphanumeric password, as far as I know, businesses often enforce this. Obviously a 4-digit code is easy to brute-force on a computer, but it requires far more technical knowledge to do so - booting custom firmware, using some script to brute force, etc, and if the attacker…

I think you're missing the biggest security hole with passcodes: whenever someone on the subway unlocks their phone, I need to consciously look away or I'll risk inadvertently committing their code to memory. It makes me seriously uncomfortable.

I'll hazard a guess that abuse by acquaintances, intimate or casual, is the most common risk to smartphone users, and that the fingerprint is an incredible improvement over the status quo.

Re: Chaos Computer Club breaks Apple TouchID

#20

I have accidentally seen basically all of my friends' passcodes as they type it in at bars etc. I could get into their phones easily. TouchID is more secure than that simply because someone needs to take a 2400dpi image of the person's finger to do it. Locks (when physical access to a device is available) are to keep honest people honest. Most security experts that I know agree that if an intruder has physical access…

...2400dpi image of the person's finger...

Note: Finger Print, not finger.

Here, have a drink out of this freshly washed glass... no, don't worry, I'll wash the glass for you later. :)

On the last second point regarding access to a device, I could take a week to make up the fake print during which it won't matter if I have it or not. Since your print isn't changing I just need 5 minutes with your device at any point in the future.

Post reply on HN