Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

41–50 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#42

Earlier quoted context omitted.

> Most security experts that I know agree that if an intruder has physical access to a device, it can be considered compromised because it is just a matter of time. Anyone who says this is not a security expert. That hasn't been true since full disk encryption became available. A properly encrypted device is a brick if stolen, which is the only reason to have full disk encryption in the first place.

Most people outside of this community are not using disk encryption. With that said and the caveat that I am not an encryption expert myself: given an infinite amount of computing power and an infinite amount of time, can full disk encryption not be broken? If so, then it is just a question of computing power and time, not of whether it is possible to get to the data.

>given an infinite amount of computing power and an infinite amount of time, can full disk encryption not be broken?

Sure. But the difference between "infinite" and "a couple billion years" from a human perspective is minute.

Re: Chaos Computer Club breaks Apple TouchID

#43

I have accidentally seen basically all of my friends' passcodes as they type it in at bars etc. I could get into their phones easily. TouchID is more secure than that simply because someone needs to take a 2400dpi image of the person's finger to do it. Locks (when physical access to a device is available) are to keep honest people honest. Most security experts that I know agree that if an intruder has physical access…

I have accidentally seen basically all of my friends' passcodes as they type it in at bars etc. I could get into their phones easily.

And your friends could change their password 365 times per year every year for the rest of their lives.

With fingerprints, they get 10 password changes.

Re: Chaos Computer Club breaks Apple TouchID

#44
Considering that people generally don't wear gloves when they use their phones this is like having a picture of your key on your door. Combine that with what we know you can do with pictures of keys[1] and yes it's obviously not a very good idea.

[1]: https://news.ycombinator.com/item?id=6167246

Re: Chaos Computer Club breaks Apple TouchID

#45
This is a really silly statement - "This demonstrates – again – that fingerprint biometrics is unsuitable as access control method and should be avoided."

Sure, maybe you can bypass this mechanism, but as an everyday password, this is still a substantially easier tool than typing in a 4-digit password.

In fact, at least you cannot easily spoof my fingerprint at a public location, while you could certainly easily figure out my password by just standing over me when I type it. I wonder how many mall cameras, street cameras and all sorts of public surveillance cameras have all our passwords?

Re: Chaos Computer Club breaks Apple TouchID

#46

I have accidentally seen basically all of my friends' passcodes as they type it in at bars etc. I could get into their phones easily. TouchID is more secure than that simply because someone needs to take a 2400dpi image of the person's finger to do it. Locks (when physical access to a device is available) are to keep honest people honest. Most security experts that I know agree that if an intruder has physical access…

A comment on another article the other day (can't remember which or I'd link) noted that no-one will magically know your passcode when you sleep or nap, but it might not be too hard for them to gently put your thumb on your phone. One would do well to remember that involuntarily "surrendering" login information doesn't necessarily require hoses or wrenches...

Re: Chaos Computer Club breaks Apple TouchID

#47

> The method follows the steps outlined in this how-to with materials that can be found in almost every household I own almost none of the materials they list. They have a very different idea of what materials can be found in almost every household.

By my reading the minimum is: 1) Laser printer 2) transparency sheet 3) white glue.

You might not own a laser printer but surely you have a library or kinkos nearby that makes the distinction academic.

Re: Chaos Computer Club breaks Apple TouchID

#48

If we've learned anything over the past few months, it is that security is an illusion when it comes to Google, Apple and Facebook. The fingerprint scanner is not intended to protect your personal data from being accessed by nefarious cyber-spooks or crackers. The $5 dollar wrench technique is fairly effective in bypassing such security anyway. The fingerprint scanner is there so that when your phone is nicked by a m…

> he still has to know my AppleID password before he can remove the 'Find my Phone' feature.

I don't know if others are experiencing this, but as of iOS 7, that feature turns itself off every time my phone is rebooted.

Re: Chaos Computer Club breaks Apple TouchID

#49
To be fair Apple hasn't said anything about liveness checks or any other safeguards against faked/duplicated fingerprints. All they talked about was how the fingerprint storage itself is secure, hardware level and local. The hack that gets the fingerprints off of the chip by exploiting some implementation related vulnerability would be a big deal.

TouchID is just another fingerprint reader - albeit one that's easier to use.

Re: Chaos Computer Club breaks Apple TouchID

#50

Earlier quoted context omitted.

Frontline had an excellent piece on the (lack of) reliability behind most of crime forensics. Fingerprints in particular are mentioned as being very unreliable and unscientific. The only scientifically rigorous piece of "CSI" is DNA matching. http://www.pbs.org/wgbh/pages/frontline/real-csi/

Even DNA can provide false negatives in the case of human chimeras.

Or just someone skilled enough to place fake dna in his body such that the person taking the sample is fooled into taking it from the fake dna.

Yes, this really happened - at least once that we know of: https://en.wikipedia.org/wiki/John_Schneeberger

Post reply on HN