Chaos Computer Club breaks Apple TouchID
41–50 of 458 posts
Re: Chaos Computer Club breaks Apple TouchID
#42Earlier quoted context omitted.
> Most security experts that I know agree that if an intruder has physical access to a device, it can be considered compromised because it is just a matter of time. Anyone who says this is not a security expert. That hasn't been true since full disk encryption became available. A properly encrypted device is a brick if stolen, which is the only reason to have full disk encryption in the first place.
Most people outside of this community are not using disk encryption. With that said and the caveat that I am not an encryption expert myself: given an infinite amount of computing power and an infinite amount of time, can full disk encryption not be broken? If so, then it is just a question of computing power and time, not of whether it is possible to get to the data.
Sure. But the difference between "infinite" and "a couple billion years" from a human perspective is minute.
Re: Chaos Computer Club breaks Apple TouchID
#43I have accidentally seen basically all of my friends' passcodes as they type it in at bars etc. I could get into their phones easily. TouchID is more secure than that simply because someone needs to take a 2400dpi image of the person's finger to do it. Locks (when physical access to a device is available) are to keep honest people honest. Most security experts that I know agree that if an intruder has physical access…
And your friends could change their password 365 times per year every year for the rest of their lives.
With fingerprints, they get 10 password changes.
Re: Chaos Computer Club breaks Apple TouchID
#44Re: Chaos Computer Club breaks Apple TouchID
#45Sure, maybe you can bypass this mechanism, but as an everyday password, this is still a substantially easier tool than typing in a 4-digit password.
In fact, at least you cannot easily spoof my fingerprint at a public location, while you could certainly easily figure out my password by just standing over me when I type it. I wonder how many mall cameras, street cameras and all sorts of public surveillance cameras have all our passwords?
Re: Chaos Computer Club breaks Apple TouchID
#46I have accidentally seen basically all of my friends' passcodes as they type it in at bars etc. I could get into their phones easily. TouchID is more secure than that simply because someone needs to take a 2400dpi image of the person's finger to do it. Locks (when physical access to a device is available) are to keep honest people honest. Most security experts that I know agree that if an intruder has physical access…
Re: Chaos Computer Club breaks Apple TouchID
#47> The method follows the steps outlined in this how-to with materials that can be found in almost every household I own almost none of the materials they list. They have a very different idea of what materials can be found in almost every household.
You might not own a laser printer but surely you have a library or kinkos nearby that makes the distinction academic.
Re: Chaos Computer Club breaks Apple TouchID
#48If we've learned anything over the past few months, it is that security is an illusion when it comes to Google, Apple and Facebook. The fingerprint scanner is not intended to protect your personal data from being accessed by nefarious cyber-spooks or crackers. The $5 dollar wrench technique is fairly effective in bypassing such security anyway. The fingerprint scanner is there so that when your phone is nicked by a m…
I don't know if others are experiencing this, but as of iOS 7, that feature turns itself off every time my phone is rebooted.
Re: Chaos Computer Club breaks Apple TouchID
#49TouchID is just another fingerprint reader - albeit one that's easier to use.
Re: Chaos Computer Club breaks Apple TouchID
#50Earlier quoted context omitted.
Frontline had an excellent piece on the (lack of) reliability behind most of crime forensics. Fingerprints in particular are mentioned as being very unreliable and unscientific. The only scientifically rigorous piece of "CSI" is DNA matching. http://www.pbs.org/wgbh/pages/frontline/real-csi/
Even DNA can provide false negatives in the case of human chimeras.
Yes, this really happened - at least once that we know of: https://en.wikipedia.org/wiki/John_Schneeberger