Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

21–30 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#21
What is the resolution of the fingerprint image stored in biometric passport, i.e., the kind of passport you need to enter the US?

Biometric passports store an actual fingerprint image and not just a hash like the iPhone 5S. So if the resolution was high enough, everyone with access to a biometric passport – for example by scanning people carrying such passports around at an airport – could forge fingerprints …

Re: Chaos Computer Club breaks Apple TouchID

#22

If we've learned anything over the past few months, it is that security is an illusion when it comes to Google, Apple and Facebook. The fingerprint scanner is not intended to protect your personal data from being accessed by nefarious cyber-spooks or crackers. The $5 dollar wrench technique is fairly effective in bypassing such security anyway. The fingerprint scanner is there so that when your phone is nicked by a m…

> The $5 dollar wrench technique

I prefer Schneier's original rubber hose technique. Leaves fewer broken bones and bruises, but just as effective.

Re: Chaos Computer Club breaks Apple TouchID

#23

I have accidentally seen basically all of my friends' passcodes as they type it in at bars etc. I could get into their phones easily. TouchID is more secure than that simply because someone needs to take a 2400dpi image of the person's finger to do it. Locks (when physical access to a device is available) are to keep honest people honest. Most security experts that I know agree that if an intruder has physical access…

> Most security experts that I know agree that if an intruder has physical access to a device, it can be considered compromised because it is just a matter of time.

Anyone who says this is not a security expert. That hasn't been true since full disk encryption became available. A properly encrypted device is a brick if stolen, which is the only reason to have full disk encryption in the first place.

Re: Chaos Computer Club breaks Apple TouchID

#24
I think they're missing the point. The passcode on an iPhone defends against other people in your environment - family members, coworkers, roommates - getting your information opportunistically. It doesn't defend against hackers, the government, or even slightly savvy thieves.

Also, if a fingerprint sensor is significantly easier to use, and in practice will deter a class of privacy violations, it could increase overall security. This is a question you can only answer by looking how people behave, not solely with an analysis of the technology.

The fingerprint sensor worries me more that it records biometric information at all. It's one thing to leave fingerprints all around your environment, but there is now the potential to steal your biometrics over the internet. The device supposedly hashes the data derived from your fingerprint, presumably with a hardware-based secret, but I worry someone will find a way around that. (EDIT: maybe this is physically impossible; can someone provide details?)

Also, the issues that CCC discusses about how fingerprint unlocking can be coerced are important. Many law enforcement organizations now have devices that can scan smartphone data, which is bad enough, but at least the use of those devices are controlled. A fingerprint sensor now allows a cop to handcuff someone, jam his or her finger onto the phone, and then to (for instance) delete an incriminating video.

Likewise anyone else willing to use force. Might become the next schoolyard amusement for bullies, if your kid has a smartphone.

Re: Chaos Computer Club breaks Apple TouchID

#25

I'd be interested on peoples' opinions, is this more or less secure than a 4-digit passcode? From a real security perspective, users should have alphanumeric password, as far as I know, businesses often enforce this. Obviously a 4-digit code is easy to brute-force on a computer, but it requires far more technical knowledge to do so - booting custom firmware, using some script to brute force, etc, and if the attacker…

Also worth noting that unlike PINs, the fingerprint can never be changed.

Re: Chaos Computer Club breaks Apple TouchID

#26
post #20

I have accidentally seen basically all of my friends' passcodes as they type it in at bars etc. I could get into their phones easily. TouchID is more secure than that simply because someone needs to take a 2400dpi image of the person's finger to do it. Locks (when physical access to a device is available) are to keep honest people honest. Most security experts that I know agree that if an intruder has physical access…

...2400dpi image of the person's finger... Note: Finger Print, not finger. Here, have a drink out of this freshly washed glass... no, don't worry, I'll wash the glass for you later. :) On the last second point regarding access to a device, I could take a week to make up the fake print during which it won't matter if I have it or not. Since your print isn't changing I just need 5 minutes with your device at any point…

Then create a detailed model using said high resolution fingerprint. If someone cares enough about your phone to do that, they can probably break into it by other means anyway (jail break, brute force passcode, etc)

Re: Chaos Computer Club breaks Apple TouchID

#27
post #19

I'd be interested on peoples' opinions, is this more or less secure than a 4-digit passcode? From a real security perspective, users should have alphanumeric password, as far as I know, businesses often enforce this. Obviously a 4-digit code is easy to brute-force on a computer, but it requires far more technical knowledge to do so - booting custom firmware, using some script to brute force, etc, and if the attacker…

I think you're missing the biggest security hole with passcodes: whenever someone on the subway unlocks their phone, I need to consciously look away or I'll risk inadvertently committing their code to memory. It makes me seriously uncomfortable. I'll hazard a guess that abuse by acquaintances, intimate or casual, is the most common risk to smartphone users, and that the fingerprint is an incredible improvement over t…

This is true, but this is more down to people not covering their phone. I tend to shield my phone to the point where it would be obvious to me if someone were trying to see my passcode.

I think TouchID provides good security against 'casual attacks' - those by people who see you use your phone a lot, people who aren't going to put much effort into an 'attack', just try and post things on your Facebook account while you're out of the room.

However, in the case of 'real' security, where a person is being targeted for their data, or anything like that, I think it would provide less security.

Re: Chaos Computer Club breaks Apple TouchID

#28
Here's an idea that would improve security in conjunction with the new sensor:

Create a random pattern of ridges and, using the technique outlined in the OP, build a latex key. Attach that to your keychain (in some sort of case to improve durability, maybe). Then, enjoy 2-factor auth, between the phone's pass code and the synthetic fingerprint.

Re: Chaos Computer Club breaks Apple TouchID

#29

I have accidentally seen basically all of my friends' passcodes as they type it in at bars etc. I could get into their phones easily. TouchID is more secure than that simply because someone needs to take a 2400dpi image of the person's finger to do it. Locks (when physical access to a device is available) are to keep honest people honest. Most security experts that I know agree that if an intruder has physical access…

> Most security experts that I know agree that if an intruder has physical access to a device, it can be considered compromised because it is just a matter of time. Anyone who says this is not a security expert. That hasn't been true since full disk encryption became available. A properly encrypted device is a brick if stolen, which is the only reason to have full disk encryption in the first place.

Most people outside of this community are not using disk encryption.

With that said and the caveat that I am not an encryption expert myself: given an infinite amount of computing power and an infinite amount of time, can full disk encryption not be broken? If so, then it is just a question of computing power and time, not of whether it is possible to get to the data.

Re: Chaos Computer Club breaks Apple TouchID

#30

Of course they have broken it, I had no doubt it would be broken like any other fingerprint security system. The issue here is that it's ok, it doesn't really matter. It is all about the amount of security you need. Does a normal user need unbreakable security? No. The security provided with this method is more than ok, it is kinda secure and it's faster (imho) than writing your passcode. After all your "enemies" her…

Actually, its not okay. The reason is: fingerprints are not a valid protection against government intrusion.

A password is the only thing that really protects you from this. And now Apple are moving consumers over to a less-secure, more government-friendly intrusion ..

Post reply on HN