Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

51–60 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#51

Earlier quoted context omitted.

Frontline had an excellent piece on the (lack of) reliability behind most of crime forensics. Fingerprints in particular are mentioned as being very unreliable and unscientific. The only scientifically rigorous piece of "CSI" is DNA matching. http://www.pbs.org/wgbh/pages/frontline/real-csi/

Even DNA can provide false negatives in the case of human chimeras.

The case of Lydia Fairchild is particularly harrowing, she nearly lost her own kids because most of her DNA didn't match. http://en.wikipedia.org/wiki/Lydia_Fairchild

Re: Chaos Computer Club breaks Apple TouchID

#53

If we've learned anything over the past few months, it is that security is an illusion when it comes to Google, Apple and Facebook. The fingerprint scanner is not intended to protect your personal data from being accessed by nefarious cyber-spooks or crackers. The $5 dollar wrench technique is fairly effective in bypassing such security anyway. The fingerprint scanner is there so that when your phone is nicked by a m…

Agreed. But they always blow it out of proportion. As if the existing fingerprint systems are extremely insecure and theirs is not. The truth is they are all the same- insecure.

Theirs is better than the standard old fingerprint scanners and far better than using 'nothing' which is what they are replacing. They have blown nothing out of proportion.

Re: Chaos Computer Club breaks Apple TouchID

#54

These findings would have been more surprising if the fingerprints were taken from the phone itself!

Actually, touchscreens are more or less the ideal surface to get the fingerprints from - a smooth glass object frequently touched. I just took my phone out of my pocket and found three very clear prints... Just look at 00:37 in the video they posted (1) - lots of clear prints. If the video was higher resolution, you might even be able to use frames of their video as a print source.

1. http://www.youtube.com/watch?v=HM8b8d8kSNQ&t=37

Re: Chaos Computer Club breaks Apple TouchID

#55
post #2

Kind of a "well duh" post. All of the image scan finger print readers are easy to game. Even the ones that use capacitance can be beaten with a rubber glove and a copy of the finger print, printed on the latex. (the best is actually an Vinyl condom that doesn't come pre-lubed, the ink sticks better and the vinyl is less of an insulator)

The problem is that Apple made a big deal in the announcement about how it was so much more secure than previous implementations, how it used sub-dermal imaging and stuff like that. It appeared from what they were saying, that this would be considerably harder to fake.

It is considerably harder to fake.

Re: Chaos Computer Club breaks Apple TouchID

#56

Earlier quoted context omitted.

Frontline had an excellent piece on the (lack of) reliability behind most of crime forensics. Fingerprints in particular are mentioned as being very unreliable and unscientific. The only scientifically rigorous piece of "CSI" is DNA matching. http://www.pbs.org/wgbh/pages/frontline/real-csi/

Even DNA can provide false negatives in the case of human chimeras.

Or even mosaic individuals (which is slightly different): http://en.wikipedia.org/wiki/Mosaicism

Re: Chaos Computer Club breaks Apple TouchID

#57

This is a really silly statement - "This demonstrates – again – that fingerprint biometrics is unsuitable as access control method and should be avoided." Sure, maybe you can bypass this mechanism, but as an everyday password, this is still a substantially easier tool than typing in a 4-digit password. In fact, at least you cannot easily spoof my fingerprint at a public location, while you could certainly easily figu…

> this is still a substantially easier tool than typing in a 4-digit password.

I know tons of people, including myself, who don't use any passcode on their phone because the 4 digit stuff is a hassle.

CCC is arguing this isn't pick-proof anti-tampering deadbolt, when right now a huge number of users don't even have a door. It's still a MASSIVE improvement.

Re: Chaos Computer Club breaks Apple TouchID

#58

If we've learned anything over the past few months, it is that security is an illusion when it comes to Google, Apple and Facebook. The fingerprint scanner is not intended to protect your personal data from being accessed by nefarious cyber-spooks or crackers. The $5 dollar wrench technique is fairly effective in bypassing such security anyway. The fingerprint scanner is there so that when your phone is nicked by a m…

Stop moving the goalpost.

Re: Chaos Computer Club breaks Apple TouchID

#59

If we've learned anything over the past few months, it is that security is an illusion when it comes to Google, Apple and Facebook. The fingerprint scanner is not intended to protect your personal data from being accessed by nefarious cyber-spooks or crackers. The $5 dollar wrench technique is fairly effective in bypassing such security anyway. The fingerprint scanner is there so that when your phone is nicked by a m…

Apple claims that "The technology within Touch ID is some of the most advanced hardware and software we've put in any device." [1]. This attack showed that increasing sensor resolution only requires increasing the resolution on the fake print to match.

This attack is an interesting data point in the debate over using biometrics in access control systems. Apple was hyped to have introduced something new and exciting in this space, but it's quickly been shown to not be a significant advance in fingerprint sensor technology.

Touch ID, however, is still an adequately secure access control check to be useful to consumers.

[1]http://support.apple.com/kb/HT5949?viewlocale=en_US

Re: Chaos Computer Club breaks Apple TouchID

#60
They tried to make a fingerprint readers more sophisticated and added a temperature registers to avoid fakes or (more in more gruesome case - a cut off finger), but hackers managed to make so called rubber fingers or peel dead finger and fill with a warm salty water. Anything can be hacked.

But I think they are missing the point. If Apple wanted its phones to be a secure gimmick at Pentagon - that was silly. But for average user - nobody is going to steal your prints. It's just a usability. For average Joe it is so much easier to tap with finger than type PIN all the time. But if you get specifically targeted nothing will save you.

Post reply on HN