Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

31–40 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#31

The "How to fake fingerprints" link [1], is one of the scariest things I have seen, given how simple it is, and how much we reply on fingerprints for linking people to crimes. BTW, for anyone who does not know about Chaos Computer Club (CCC) [2], they run a massive conference in EU. You can look at some of their talks @ http://media.ccc.de/ [1] http://dasalte.ccc.de/biometrie/fingerabdruck_kopieren?langu... [2] http:…

Frontline had an excellent piece on the (lack of) reliability behind most of crime forensics. Fingerprints in particular are mentioned as being very unreliable and unscientific. The only scientifically rigorous piece of "CSI" is DNA matching. http://www.pbs.org/wgbh/pages/frontline/real-csi/

And now even DNA is being called into question.

http://mobile.nytimes.com/2013/09/17/science/dna-double-take...

Re: Chaos Computer Club breaks Apple TouchID

#33

If we've learned anything over the past few months, it is that security is an illusion when it comes to Google, Apple and Facebook. The fingerprint scanner is not intended to protect your personal data from being accessed by nefarious cyber-spooks or crackers. The $5 dollar wrench technique is fairly effective in bypassing such security anyway. The fingerprint scanner is there so that when your phone is nicked by a m…

Agreed. But they always blow it out of proportion. As if the existing fingerprint systems are extremely insecure and theirs is not. The truth is they are all the same- insecure.

Re: Chaos Computer Club breaks Apple TouchID

#34

The "How to fake fingerprints" link [1], is one of the scariest things I have seen, given how simple it is, and how much we reply on fingerprints for linking people to crimes. BTW, for anyone who does not know about Chaos Computer Club (CCC) [2], they run a massive conference in EU. You can look at some of their talks @ http://media.ccc.de/ [1] http://dasalte.ccc.de/biometrie/fingerabdruck_kopieren?langu... [2] http:…

Frontline had an excellent piece on the (lack of) reliability behind most of crime forensics. Fingerprints in particular are mentioned as being very unreliable and unscientific. The only scientifically rigorous piece of "CSI" is DNA matching. http://www.pbs.org/wgbh/pages/frontline/real-csi/

Even DNA can provide false negatives in the case of human chimeras.

Re: Chaos Computer Club breaks Apple TouchID

#35

If we've learned anything over the past few months, it is that security is an illusion when it comes to Google, Apple and Facebook. The fingerprint scanner is not intended to protect your personal data from being accessed by nefarious cyber-spooks or crackers. The $5 dollar wrench technique is fairly effective in bypassing such security anyway. The fingerprint scanner is there so that when your phone is nicked by a m…

Regardless of whether or not fingerprint scanners are good security wise, it's a bit silly to think that phone robbing thugs are completely dim. The way it works in my first world modern country is that there are shops everywhere that unlock or reset phones as part of their services, and it isn't thugs running them. It's people with an affinity for 'tech' who just happen to deal with a shadier area.

If cracking fingerprint authentication is as easy as this article suggests then there's no doubt that these types of shops will do this readily. Steal a phone -> bring it to a place that does it.

The AppleID password is another thing though.

Re: Chaos Computer Club breaks Apple TouchID

#36
post #7

Expected. Still much, much better security than no code at all. I will use it (with full knowledge of its downsides and tradeoffs) and it would behoove the CCC to not portray security as a binary state. (Just as much as it would behoove Apple to be truthful in their marketing.) Don't use it if thieves would consider going through all the effort of faking out the scanner. That's what I take from this no doubt valuable…

Yes, we often say security and think it means total protection. It doesn't. Its rare to see any security feature that cannot be bypassed or broken by some means. This is why we implement security in layers. If it were a binary state then a single layer would be sufficient. The idea is to make it so difficult to break through every layer of security that it becomes impractical but there will always be someone who does it.

I also don't think Apple is dishonest in their marketing. Fingerprint scanning is absolutely better than a pass code and the marketing around it all gives the impression that using it ensures no one can unlock your phone without your fingerprint. Nothing dishonest in that. Plus the layperson really has no interest in learning the specifics anyway so I'm not sure it matters what they say about it so long as it sounds cool and futuristic.

Re: Chaos Computer Club breaks Apple TouchID

#38

I'd be interested on peoples' opinions, is this more or less secure than a 4-digit passcode? From a real security perspective, users should have alphanumeric password, as far as I know, businesses often enforce this. Obviously a 4-digit code is easy to brute-force on a computer, but it requires far more technical knowledge to do so - booting custom firmware, using some script to brute force, etc, and if the attacker…

Also worth noting that unlike PINs, the fingerprint can never be changed.

Can't you use different fingers?

Re: Chaos Computer Club breaks Apple TouchID

#40
post #19

I'd be interested on peoples' opinions, is this more or less secure than a 4-digit passcode? From a real security perspective, users should have alphanumeric password, as far as I know, businesses often enforce this. Obviously a 4-digit code is easy to brute-force on a computer, but it requires far more technical knowledge to do so - booting custom firmware, using some script to brute force, etc, and if the attacker…

I think you're missing the biggest security hole with passcodes: whenever someone on the subway unlocks their phone, I need to consciously look away or I'll risk inadvertently committing their code to memory. It makes me seriously uncomfortable. I'll hazard a guess that abuse by acquaintances, intimate or casual, is the most common risk to smartphone users, and that the fingerprint is an incredible improvement over t…

It makes me seriously uncomfortable.

Oh I think it's cool to notice, for instance, that a physics major uses 3141.

Post reply on HN