Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

61–70 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#61

Presumably solvable by using a digit that isn't normally in contact with your phone - eg the pinky of your non-dominant hand?

Wonder if using your nose would work... A toe surely would but accessing that piece of hardware is an ugly hack in too many ways.

Re: Chaos Computer Club breaks Apple TouchID

#62
post #4

iOS security is trivial to break if you have physical access to the device. TouchID (and passcodes) should be considered little more than a convenience, not a serious security measure.

Really, how do you trivially break a passcode on an iOS device? There is a way that I know about, and it is very much non-trivial.

Re: Chaos Computer Club breaks Apple TouchID

#63
post #9

Wasn't Gruber getting awfully excited about how amazing and revolutionary Apple's finger print sensor was? Will he be claim chowdering?

From what I've read, Apple's sensor is still more accurate than competing sensors. It works much faster, and is better at recognizing your finger in various positions. It's also faster/easier than a 4 digit passcode.

Let's be fair. Apple said it was easy to use and improved security (compared to the previous iPhone). They didn't say it was designed to the standards needed to protect DOD secrets.

This seems like CCC is just trying to get attention to me; holding the device up to straw-man standards of security.

Re: Chaos Computer Club breaks Apple TouchID

#64
post #24

I think they're missing the point. The passcode on an iPhone defends against other people in your environment - family members, coworkers, roommates - getting your information opportunistically. It doesn't defend against hackers, the government, or even slightly savvy thieves. Also, if a fingerprint sensor is significantly easier to use, and in practice will deter a class of privacy violations, it could increase over…

> I think they're missing the point. The passcode on an iPhone defends against other people in your environment - family members, coworkers, roommates - getting your information opportunistically. It doesn't defend against hackers, the government, or even slightly savvy thieves.

The Google Chrome Security team begs to differ [1]. According to them giving someone the illusion of security is bad.

[1] https://news.ycombinator.com/item?id=6165708

Re: Chaos Computer Club breaks Apple TouchID

#66
post #8

Nice , The mythbusters did this in their fingerprinter scanner episode , although they didn't have the iPhone5s but I am sure the same principle/technique would work.

As I remember, after using a similar technique they started working backwards and found a simple photocopy (no gelatin or other simulated finger) would do it. Apple has at least beat that horrifically low bar.

That was a great episode. Beating the thermal sensor was great too.

Re: Chaos Computer Club breaks Apple TouchID

#67
post #10
post #9

Wasn't Gruber getting awfully excited about how amazing and revolutionary Apple's finger print sensor was? Will he be claim chowdering?

What did he claim?

Well he did approvingly quote some nonsense that the reader would only work on a 'live finger' (presumably it is supposed to be able to detect the presence of a soul?).

http://daringfireball.net/linked/2013/09/12/5s-fingerprint-s...

Re: Chaos Computer Club breaks Apple TouchID

#70
post #55

Earlier quoted context omitted.

The problem is that Apple made a big deal in the announcement about how it was so much more secure than previous implementations, how it used sub-dermal imaging and stuff like that. It appeared from what they were saying, that this would be considerably harder to fake.

It is considerably harder to fake.

It doesn't look it. From the description in the article it appears to be a very similar process to what has been used before, just with a higher resolution printer, but not one that is outside the realm of photo printers.
Post reply on HN