If we've learned anything over the past few months, it is that security is an illusion when it comes to Google, Apple and Facebook. The fingerprint scanner is not intended to protect your personal data from being accessed by nefarious cyber-spooks or crackers. The $5 dollar wrench technique is fairly effective in bypassing such security anyway. The fingerprint scanner is there so that when your phone is nicked by a m…
Giving Apple a break? Just another layer of security? That's not how Apple describes it: http://support.apple.com/kb/HT5949?viewlocale=en_US And selling a stolen iPhone on eBay does not need a password or a fingerprint, a jailbreak is enough …
Chaos Computer Club breaks Apple TouchID
71–80 of 458 posts
Re: Chaos Computer Club breaks Apple TouchID
#72Earlier quoted context omitted.
Also worth noting that unlike PINs, the fingerprint can never be changed.
Can't you use different fingers?
Re: Chaos Computer Club breaks Apple TouchID
#73Re: Chaos Computer Club breaks Apple TouchID
#74Earlier quoted context omitted.
I think you're missing the biggest security hole with passcodes: whenever someone on the subway unlocks their phone, I need to consciously look away or I'll risk inadvertently committing their code to memory. It makes me seriously uncomfortable. I'll hazard a guess that abuse by acquaintances, intimate or casual, is the most common risk to smartphone users, and that the fingerprint is an incredible improvement over t…
It makes me seriously uncomfortable. Oh I think it's cool to notice, for instance, that a physics major uses 3141.
Re: Chaos Computer Club breaks Apple TouchID
#75Earlier quoted context omitted.
The problem is that Apple made a big deal in the announcement about how it was so much more secure than previous implementations, how it used sub-dermal imaging and stuff like that. It appeared from what they were saying, that this would be considerably harder to fake.
It is considerably harder to fake.
"In reality, Apple's sensor has just a higher resolution compared to the sensors so far. So we only needed to ramp up the resolution of our fake",
Re: Chaos Computer Club breaks Apple TouchID
#76Earlier quoted context omitted.
> Most security experts that I know agree that if an intruder has physical access to a device, it can be considered compromised because it is just a matter of time. Anyone who says this is not a security expert. That hasn't been true since full disk encryption became available. A properly encrypted device is a brick if stolen, which is the only reason to have full disk encryption in the first place.
Most people outside of this community are not using disk encryption. With that said and the caveat that I am not an encryption expert myself: given an infinite amount of computing power and an infinite amount of time, can full disk encryption not be broken? If so, then it is just a question of computing power and time, not of whether it is possible to get to the data.
Re: Chaos Computer Club breaks Apple TouchID
#77Earlier quoted context omitted.
Even DNA can provide false negatives in the case of human chimeras.
Or just someone skilled enough to place fake dna in his body such that the person taking the sample is fooled into taking it from the fake dna. Yes, this really happened - at least once that we know of: https://en.wikipedia.org/wiki/John_Schneeberger
Re: Chaos Computer Club breaks Apple TouchID
#78At this rate, no method of security is secure.
There has never been a method of security that is secure. The first thing you learn when dealing with security is there are tradeoffs between opportunity, time, money. and usability.
Re: Chaos Computer Club breaks Apple TouchID
#79Earlier quoted context omitted.
I think you're missing the biggest security hole with passcodes: whenever someone on the subway unlocks their phone, I need to consciously look away or I'll risk inadvertently committing their code to memory. It makes me seriously uncomfortable. I'll hazard a guess that abuse by acquaintances, intimate or casual, is the most common risk to smartphone users, and that the fingerprint is an incredible improvement over t…
This is true, but this is more down to people not covering their phone. I tend to shield my phone to the point where it would be obvious to me if someone were trying to see my passcode. I think TouchID provides good security against 'casual attacks' - those by people who see you use your phone a lot, people who aren't going to put much effort into an 'attack', just try and post things on your Facebook account while y…
Re: Chaos Computer Club breaks Apple TouchID
#80I think they're missing the point. The passcode on an iPhone defends against other people in your environment - family members, coworkers, roommates - getting your information opportunistically. It doesn't defend against hackers, the government, or even slightly savvy thieves. Also, if a fingerprint sensor is significantly easier to use, and in practice will deter a class of privacy violations, it could increase over…