Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

91–100 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#91
post #84

Earlier quoted context omitted.

> I think they're missing the point. The passcode on an iPhone defends against other people in your environment - family members, coworkers, roommates - getting your information opportunistically. It doesn't defend against hackers, the government, or even slightly savvy thieves. The Google Chrome Security team begs to differ [1]. According to them giving someone the illusion of security is bad. [1] https://news.ycomb…

Which is an incredibly absurd position, in any context. Security is not binary.

If it were, it would always be 0.

Re: Chaos Computer Club breaks Apple TouchID

#92
post #18

Earlier quoted context omitted.

Giving Apple a break? Just another layer of security? That's not how Apple describes it: http://support.apple.com/kb/HT5949?viewlocale=en_US And selling a stolen iPhone on eBay does not need a password or a fingerprint, a jailbreak is enough …

Jailbreak is enough... When it exists. And for now it doesn't.

taking past trends into consideration, it looks like you're betting on the wrong horse, here. it will exist.

Re: Chaos Computer Club breaks Apple TouchID

#93

Honestly, TouchID is better than what we have today; a 4 digit useless passcode. If somebody has to take a photo of my fingerprint off a glass surface to gain access to my phone, so be it.

It's not as useless as all that. Assuming Apple has properly used their key derivation function, and the phone locks you out after ~10 failed attempts, and there's no way to access a locked phone's data, then a four digit passcode is actually quite secure.

Re: Chaos Computer Club breaks Apple TouchID

#94
post #65

I thought, based on anandtech review, that this scanner is not optical but electrical, hence "sub epidermal scanning", so why does a printed finger work?

It looks like either of the following:

- the capacitance of the ridges and crests of one's fingerprint dominates any differences in subcutaneous capacitance (possibly because they are closer to the scanner, or because there simply is too little variance in capacitance between flesh and hair veins)

- subcutaneous structures resembles fingerprints too much (seems quite possible, as there must be a reason that it is hard to permanently change one's fingerprints by using sand paper)

Aside: a Google found this procedure: http://www.zoklet.net/bbs/archive/index.php/t-202956.html I don't have the faintest idea whether that is real, but regardless, I don't recommend it.

Re: Chaos Computer Club breaks Apple TouchID

#96

Earlier quoted context omitted.

Frontline had an excellent piece on the (lack of) reliability behind most of crime forensics. Fingerprints in particular are mentioned as being very unreliable and unscientific. The only scientifically rigorous piece of "CSI" is DNA matching. http://www.pbs.org/wgbh/pages/frontline/real-csi/

And now even DNA is being called into question. http://mobile.nytimes.com/2013/09/17/science/dna-double-take...

In addition to the chimeric qualities cited in the NYT article (I skimmed), IIRC some DNA sampling has in the past used and may still use a fairly limited profile of markers. The statistically likelihood of matches between distinct parties is in some cases well under the population of the world. Never read into it in detail, but I was left with the impression that "unique identifier" can be an over-statement/qualification also from this perspective.

Re: Chaos Computer Club breaks Apple TouchID

#97
post #53

Earlier quoted context omitted.

Agreed. But they always blow it out of proportion. As if the existing fingerprint systems are extremely insecure and theirs is not. The truth is they are all the same- insecure.

Theirs is better than the standard old fingerprint scanners and far better than using 'nothing' which is what they are replacing. They have blown nothing out of proportion.

if it causes people to behave recklessly because they have the false impression of security, when they would otherwise have taken better custodianship of their device and their data, then yes ... it can be worse than nothing.

Re: Chaos Computer Club breaks Apple TouchID

#98
post #35

If we've learned anything over the past few months, it is that security is an illusion when it comes to Google, Apple and Facebook. The fingerprint scanner is not intended to protect your personal data from being accessed by nefarious cyber-spooks or crackers. The $5 dollar wrench technique is fairly effective in bypassing such security anyway. The fingerprint scanner is there so that when your phone is nicked by a m…

Regardless of whether or not fingerprint scanners are good security wise, it's a bit silly to think that phone robbing thugs are completely dim. The way it works in my first world modern country is that there are shops everywhere that unlock or reset phones as part of their services, and it isn't thugs running them. It's people with an affinity for 'tech' who just happen to deal with a shadier area. If cracking finge…

No, this is not the same as sim unlock. Circumventing touch id technology by making fake fingerprints is exactly the same case as being called to unlock a locked doors. The specialist knows when he is liable to crime and cannot make a legal bussines out of illegal access.

Re: Chaos Computer Club breaks Apple TouchID

#99
post #24

I think they're missing the point. The passcode on an iPhone defends against other people in your environment - family members, coworkers, roommates - getting your information opportunistically. It doesn't defend against hackers, the government, or even slightly savvy thieves. Also, if a fingerprint sensor is significantly easier to use, and in practice will deter a class of privacy violations, it could increase over…

> I think they're missing the point. The passcode on an iPhone defends against other people in your environment - family members, coworkers, roommates - getting your information opportunistically. It doesn't defend against hackers, the government, or even slightly savvy thieves. The Google Chrome Security team begs to differ [1]. According to them giving someone the illusion of security is bad. [1] https://news.ycomb…

Which is ironic coming from a company known to be sharing information directly with the NSA.

Name one security technology that is 100% foolproof. They don't exist. So the point isn't to rely on one thing, but to rely on many things that, used in concert, increase the risk, complexity and cost associated with subverting the entire system--not its individual components.

Re: Chaos Computer Club breaks Apple TouchID

#100
post #50

Earlier quoted context omitted.

Even DNA can provide false negatives in the case of human chimeras.

Or just someone skilled enough to place fake dna in his body such that the person taking the sample is fooled into taking it from the fake dna. Yes, this really happened - at least once that we know of: https://en.wikipedia.org/wiki/John_Schneeberger

Wow!

During his 1999 trial, Schneeberger revealed the method he used to foil the DNA tests. He implanted a 15 cm Penrose drain filled with another man's blood and anticoagulants in his arm. During tests, he tricked the laboratory technician into taking the blood sample from the place the tube was planted.

Post reply on HN