Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

71–80 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#71
post #18

If we've learned anything over the past few months, it is that security is an illusion when it comes to Google, Apple and Facebook. The fingerprint scanner is not intended to protect your personal data from being accessed by nefarious cyber-spooks or crackers. The $5 dollar wrench technique is fairly effective in bypassing such security anyway. The fingerprint scanner is there so that when your phone is nicked by a m…

Giving Apple a break? Just another layer of security? That's not how Apple describes it: http://support.apple.com/kb/HT5949?viewlocale=en_US And selling a stolen iPhone on eBay does not need a password or a fingerprint, a jailbreak is enough …

Jailbreak is enough... When it exists. And for now it doesn't.

Re: Chaos Computer Club breaks Apple TouchID

#72
post #38

Earlier quoted context omitted.

Also worth noting that unlike PINs, the fingerprint can never be changed.

Can't you use different fingers?

Yes, or carry a unique cat around as a security token. http://m.techcrunch.com/2013/09/19/watch-a-cat-unlock-the-ip...

Re: Chaos Computer Club breaks Apple TouchID

#74
post #19

Earlier quoted context omitted.

I think you're missing the biggest security hole with passcodes: whenever someone on the subway unlocks their phone, I need to consciously look away or I'll risk inadvertently committing their code to memory. It makes me seriously uncomfortable. I'll hazard a guess that abuse by acquaintances, intimate or casual, is the most common risk to smartphone users, and that the fingerprint is an incredible improvement over t…

It makes me seriously uncomfortable. Oh I think it's cool to notice, for instance, that a physics major uses 3141.

I agree it'd be cool if it didn't amount to an enormous breach of computer etiquette :)

Re: Chaos Computer Club breaks Apple TouchID

#75
post #55

Earlier quoted context omitted.

The problem is that Apple made a big deal in the announcement about how it was so much more secure than previous implementations, how it used sub-dermal imaging and stuff like that. It appeared from what they were saying, that this would be considerably harder to fake.

It is considerably harder to fake.

Considerably harder? From the article:

"In reality, Apple's sensor has just a higher resolution compared to the sensors so far. So we only needed to ramp up the resolution of our fake",

Re: Chaos Computer Club breaks Apple TouchID

#76

Earlier quoted context omitted.

> Most security experts that I know agree that if an intruder has physical access to a device, it can be considered compromised because it is just a matter of time. Anyone who says this is not a security expert. That hasn't been true since full disk encryption became available. A properly encrypted device is a brick if stolen, which is the only reason to have full disk encryption in the first place.

Most people outside of this community are not using disk encryption. With that said and the caveat that I am not an encryption expert myself: given an infinite amount of computing power and an infinite amount of time, can full disk encryption not be broken? If so, then it is just a question of computing power and time, not of whether it is possible to get to the data.

Yeah, just a matter of time. Bring a flashlight though, because the sun is projected to burn out far sooner than the largest supercomputer will be able to brute force a 256 bit key.

Re: Chaos Computer Club breaks Apple TouchID

#77
post #50

Earlier quoted context omitted.

Even DNA can provide false negatives in the case of human chimeras.

Or just someone skilled enough to place fake dna in his body such that the person taking the sample is fooled into taking it from the fake dna. Yes, this really happened - at least once that we know of: https://en.wikipedia.org/wiki/John_Schneeberger

In Schneeberger's case, it seems that he was simply infusing a part of his body with another man's blood and then making sure that the lab tech drawing the blood sample drew it from the same place. Once they tested his hair and saliva, they had a positive match.

Re: Chaos Computer Club breaks Apple TouchID

#78

At this rate, no method of security is secure.

The most secure computer is the one locked in a room and unplugged.

There has never been a method of security that is secure. The first thing you learn when dealing with security is there are tradeoffs between opportunity, time, money. and usability.

Re: Chaos Computer Club breaks Apple TouchID

#79
post #19

Earlier quoted context omitted.

I think you're missing the biggest security hole with passcodes: whenever someone on the subway unlocks their phone, I need to consciously look away or I'll risk inadvertently committing their code to memory. It makes me seriously uncomfortable. I'll hazard a guess that abuse by acquaintances, intimate or casual, is the most common risk to smartphone users, and that the fingerprint is an incredible improvement over t…

This is true, but this is more down to people not covering their phone. I tend to shield my phone to the point where it would be obvious to me if someone were trying to see my passcode. I think TouchID provides good security against 'casual attacks' - those by people who see you use your phone a lot, people who aren't going to put much effort into an 'attack', just try and post things on your Facebook account while y…

I find the idea that the typical 4-digit password provides any more security against an attacker dedicated enough to make a copy of your finger pretty hard to credit. You're placing a lot of weight on your "covering" ability. (There have been times I've had to try hard not to infer someone's passcode purely from their hand movements.)

Re: Chaos Computer Club breaks Apple TouchID

#80
post #24

I think they're missing the point. The passcode on an iPhone defends against other people in your environment - family members, coworkers, roommates - getting your information opportunistically. It doesn't defend against hackers, the government, or even slightly savvy thieves. Also, if a fingerprint sensor is significantly easier to use, and in practice will deter a class of privacy violations, it could increase over…

The first round of sleephack data exposures will put the failure to that point.
Post reply on HN