Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

81–90 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#81

This isn't new, some other guy broke TouchId by making a fake finger from gelatin and soy sauce. http://blog.fortinet.com/iPhone-5s--Basic-Fingerprint-Replic...

It seems that that guy directly made a 'copy' of his own fingerprint in a mold. I agree that it is breaking TouchId, but the CCC did a more realistic crack: making a fake fingerprint without the person's finger.

Re: Chaos Computer Club breaks Apple TouchID

#82
post #24

I think they're missing the point. The passcode on an iPhone defends against other people in your environment - family members, coworkers, roommates - getting your information opportunistically. It doesn't defend against hackers, the government, or even slightly savvy thieves. Also, if a fingerprint sensor is significantly easier to use, and in practice will deter a class of privacy violations, it could increase over…

> It's one thing to leave fingerprints all around your environment, but there is now the potential to steal your biometrics over the internet.

Correct me if I'm wrong, but the biometric data never leaves the device.

Re: Chaos Computer Club breaks Apple TouchID

#84
post #24

I think they're missing the point. The passcode on an iPhone defends against other people in your environment - family members, coworkers, roommates - getting your information opportunistically. It doesn't defend against hackers, the government, or even slightly savvy thieves. Also, if a fingerprint sensor is significantly easier to use, and in practice will deter a class of privacy violations, it could increase over…

> I think they're missing the point. The passcode on an iPhone defends against other people in your environment - family members, coworkers, roommates - getting your information opportunistically. It doesn't defend against hackers, the government, or even slightly savvy thieves. The Google Chrome Security team begs to differ [1]. According to them giving someone the illusion of security is bad. [1] https://news.ycomb…

Which is an incredibly absurd position, in any context.

Security is not binary.

Re: Chaos Computer Club breaks Apple TouchID

#85

This isn't new, some other guy broke TouchId by making a fake finger from gelatin and soy sauce. http://blog.fortinet.com/iPhone-5s--Basic-Fingerprint-Replic...

Not seeing anywhere in that article where he had success replicating a print. He did get the iPhone 5S to enroll a fake print and unlock with the same fake print. He was unable, however, to replicate an enrolled fingerprint from a real finger and successfully unlock.

Additionally, all of this was done with molds of the target finger - not from lifted fingerprints. Completely different target.

Re: Chaos Computer Club breaks Apple TouchID

#86

They tried to make a fingerprint readers more sophisticated and added a temperature registers to avoid fakes or (more in more gruesome case - a cut off finger), but hackers managed to make so called rubber fingers or peel dead finger and fill with a warm salty water. Anything can be hacked. But I think they are missing the point. If Apple wanted its phones to be a secure gimmick at Pentagon - that was silly. But for…

The exact same arguments could be made for having crappy passwords, which, I might remind you, are defeated hundreds of thousands of times a day, at a massive cost to its victims.

Re: Chaos Computer Club breaks Apple TouchID

#87
post #20

Earlier quoted context omitted.

...2400dpi image of the person's finger... Note: Finger Print, not finger. Here, have a drink out of this freshly washed glass... no, don't worry, I'll wash the glass for you later. :) On the last second point regarding access to a device, I could take a week to make up the fake print during which it won't matter if I have it or not. Since your print isn't changing I just need 5 minutes with your device at any point…

Then create a detailed model using said high resolution fingerprint. If someone cares enough about your phone to do that, they can probably break into it by other means anyway (jail break, brute force passcode, etc)

You leave finger prints on the phone. Just snap a photo with a decent camera - it's probably enough detail. Print it. Stick some latex or glue on it (literally available everywhere).

That's it. This is not rocket science or time consuming like brute forcing. You don't even have to shoulder-surf to catch their password.

Re: Chaos Computer Club breaks Apple TouchID

#88

I have accidentally seen basically all of my friends' passcodes as they type it in at bars etc. I could get into their phones easily. TouchID is more secure than that simply because someone needs to take a 2400dpi image of the person's finger to do it. Locks (when physical access to a device is available) are to keep honest people honest. Most security experts that I know agree that if an intruder has physical access…

> Most security experts that I know agree that if an intruder has physical access to a device, it can be considered compromised because it is just a matter of time. Anyone who says this is not a security expert. That hasn't been true since full disk encryption became available. A properly encrypted device is a brick if stolen, which is the only reason to have full disk encryption in the first place.

No, the physical access statement still holds true, even with FDE. First, if the machine is powered on, they can just extract the keys from RAM. Second, if you continue to use the device after it has been tampered with, you also lose (aka evil maid attack).

Re: Chaos Computer Club breaks Apple TouchID

#90
post #18

If we've learned anything over the past few months, it is that security is an illusion when it comes to Google, Apple and Facebook. The fingerprint scanner is not intended to protect your personal data from being accessed by nefarious cyber-spooks or crackers. The $5 dollar wrench technique is fairly effective in bypassing such security anyway. The fingerprint scanner is there so that when your phone is nicked by a m…

Giving Apple a break? Just another layer of security? That's not how Apple describes it: http://support.apple.com/kb/HT5949?viewlocale=en_US And selling a stolen iPhone on eBay does not need a password or a fingerprint, a jailbreak is enough …

You linked to a support document explaining how the technology works. You may have had a point if this was listed on their product page describing the feature, but instead you have them touting the convenience of using your finger to unlock your phone and make purchases:

You check your iPhone dozens and dozens of times a day, probably more. Entering a passcode each time just slows you down. But you do it because making sure no one else has access to your iPhone is important. With iPhone 5s, getting into your phone is faster, easier, and even a little futuristic. Introducing Touch ID — a new fingerprint identity sensor.

Put your finger on the Home button, and just like that your iPhone unlocks. It’s a convenient and highly secure way to access your phone. Your fingerprint can also approve purchases from iTunes Store, the App Store, and the iBooks Store, so you don’t have to enter your password. And Touch ID is capable of 360-degree readability. Which means no matter what its orientation — portrait, landscape, or anything in between — your iPhone reads your fingerprint and knows who you are. And because Touch ID lets you enroll multiple fingerprints, it knows the people you trust, too.

Post reply on HN