Biometric passports store an actual fingerprint image and not just a hash like the iPhone 5S. So if the resolution was high enough, everyone with access to a biometric passport – for example by scanning people carrying such passports around at an airport – could forge fingerprints …
Chaos Computer Club breaks Apple TouchID
21–30 of 458 posts
Re: Chaos Computer Club breaks Apple TouchID
#22If we've learned anything over the past few months, it is that security is an illusion when it comes to Google, Apple and Facebook. The fingerprint scanner is not intended to protect your personal data from being accessed by nefarious cyber-spooks or crackers. The $5 dollar wrench technique is fairly effective in bypassing such security anyway. The fingerprint scanner is there so that when your phone is nicked by a m…
I prefer Schneier's original rubber hose technique. Leaves fewer broken bones and bruises, but just as effective.
Re: Chaos Computer Club breaks Apple TouchID
#23I have accidentally seen basically all of my friends' passcodes as they type it in at bars etc. I could get into their phones easily. TouchID is more secure than that simply because someone needs to take a 2400dpi image of the person's finger to do it. Locks (when physical access to a device is available) are to keep honest people honest. Most security experts that I know agree that if an intruder has physical access…
Anyone who says this is not a security expert. That hasn't been true since full disk encryption became available. A properly encrypted device is a brick if stolen, which is the only reason to have full disk encryption in the first place.
Re: Chaos Computer Club breaks Apple TouchID
#24Also, if a fingerprint sensor is significantly easier to use, and in practice will deter a class of privacy violations, it could increase overall security. This is a question you can only answer by looking how people behave, not solely with an analysis of the technology.
The fingerprint sensor worries me more that it records biometric information at all. It's one thing to leave fingerprints all around your environment, but there is now the potential to steal your biometrics over the internet. The device supposedly hashes the data derived from your fingerprint, presumably with a hardware-based secret, but I worry someone will find a way around that. (EDIT: maybe this is physically impossible; can someone provide details?)
Also, the issues that CCC discusses about how fingerprint unlocking can be coerced are important. Many law enforcement organizations now have devices that can scan smartphone data, which is bad enough, but at least the use of those devices are controlled. A fingerprint sensor now allows a cop to handcuff someone, jam his or her finger onto the phone, and then to (for instance) delete an incriminating video.
Likewise anyone else willing to use force. Might become the next schoolyard amusement for bullies, if your kid has a smartphone.
Re: Chaos Computer Club breaks Apple TouchID
#25I'd be interested on peoples' opinions, is this more or less secure than a 4-digit passcode? From a real security perspective, users should have alphanumeric password, as far as I know, businesses often enforce this. Obviously a 4-digit code is easy to brute-force on a computer, but it requires far more technical knowledge to do so - booting custom firmware, using some script to brute force, etc, and if the attacker…
Re: Chaos Computer Club breaks Apple TouchID
#26I have accidentally seen basically all of my friends' passcodes as they type it in at bars etc. I could get into their phones easily. TouchID is more secure than that simply because someone needs to take a 2400dpi image of the person's finger to do it. Locks (when physical access to a device is available) are to keep honest people honest. Most security experts that I know agree that if an intruder has physical access…
...2400dpi image of the person's finger... Note: Finger Print, not finger. Here, have a drink out of this freshly washed glass... no, don't worry, I'll wash the glass for you later. :) On the last second point regarding access to a device, I could take a week to make up the fake print during which it won't matter if I have it or not. Since your print isn't changing I just need 5 minutes with your device at any point…
Re: Chaos Computer Club breaks Apple TouchID
#27I'd be interested on peoples' opinions, is this more or less secure than a 4-digit passcode? From a real security perspective, users should have alphanumeric password, as far as I know, businesses often enforce this. Obviously a 4-digit code is easy to brute-force on a computer, but it requires far more technical knowledge to do so - booting custom firmware, using some script to brute force, etc, and if the attacker…
I think you're missing the biggest security hole with passcodes: whenever someone on the subway unlocks their phone, I need to consciously look away or I'll risk inadvertently committing their code to memory. It makes me seriously uncomfortable. I'll hazard a guess that abuse by acquaintances, intimate or casual, is the most common risk to smartphone users, and that the fingerprint is an incredible improvement over t…
I think TouchID provides good security against 'casual attacks' - those by people who see you use your phone a lot, people who aren't going to put much effort into an 'attack', just try and post things on your Facebook account while you're out of the room.
However, in the case of 'real' security, where a person is being targeted for their data, or anything like that, I think it would provide less security.
Re: Chaos Computer Club breaks Apple TouchID
#28Create a random pattern of ridges and, using the technique outlined in the OP, build a latex key. Attach that to your keychain (in some sort of case to improve durability, maybe). Then, enjoy 2-factor auth, between the phone's pass code and the synthetic fingerprint.
Re: Chaos Computer Club breaks Apple TouchID
#29I have accidentally seen basically all of my friends' passcodes as they type it in at bars etc. I could get into their phones easily. TouchID is more secure than that simply because someone needs to take a 2400dpi image of the person's finger to do it. Locks (when physical access to a device is available) are to keep honest people honest. Most security experts that I know agree that if an intruder has physical access…
> Most security experts that I know agree that if an intruder has physical access to a device, it can be considered compromised because it is just a matter of time. Anyone who says this is not a security expert. That hasn't been true since full disk encryption became available. A properly encrypted device is a brick if stolen, which is the only reason to have full disk encryption in the first place.
With that said and the caveat that I am not an encryption expert myself: given an infinite amount of computing power and an infinite amount of time, can full disk encryption not be broken? If so, then it is just a question of computing power and time, not of whether it is possible to get to the data.
Re: Chaos Computer Club breaks Apple TouchID
#30Of course they have broken it, I had no doubt it would be broken like any other fingerprint security system. The issue here is that it's ok, it doesn't really matter. It is all about the amount of security you need. Does a normal user need unbreakable security? No. The security provided with this method is more than ok, it is kinda secure and it's faster (imho) than writing your passcode. After all your "enemies" her…
A password is the only thing that really protects you from this. And now Apple are moving consumers over to a less-secure, more government-friendly intrusion ..