Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

101–110 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#101
post #24

I think they're missing the point. The passcode on an iPhone defends against other people in your environment - family members, coworkers, roommates - getting your information opportunistically. It doesn't defend against hackers, the government, or even slightly savvy thieves. Also, if a fingerprint sensor is significantly easier to use, and in practice will deter a class of privacy violations, it could increase over…

> It's one thing to leave fingerprints all around your environment, but there is now the potential to steal your biometrics over the internet. Correct me if I'm wrong, but the biometric data never leaves the device.

It's also not stored on the device. Hashes, not fingerprints, are stored.

You need the fingerprints themselves to fake out the hardware.

Re: Chaos Computer Club breaks Apple TouchID

#102
post #44

Considering that people generally don't wear gloves when they use their phones this is like having a picture of your key on your door. Combine that with what we know you can do with pictures of keys[1] and yes it's obviously not a very good idea. [1]: https://news.ycombinator.com/item?id=6167246

So, if this can be accomplished with keys, have you removed all the locks from your house? Do you rotate your locks every 3-6 months?

Re: Chaos Computer Club breaks Apple TouchID

#103

"Biometrics is fundamentally a technology designed for oppression and control, not for securing everyday device access." Yes

lol, @ "oppression and control" . go back to your conspiracy theory cave. Apple didn't have this in mind, they simply set out to solve a problem.

Re: Chaos Computer Club breaks Apple TouchID

#104
post #24

I think they're missing the point. The passcode on an iPhone defends against other people in your environment - family members, coworkers, roommates - getting your information opportunistically. It doesn't defend against hackers, the government, or even slightly savvy thieves. Also, if a fingerprint sensor is significantly easier to use, and in practice will deter a class of privacy violations, it could increase over…

> I think they're missing the point. The passcode on an iPhone defends against other people in your environment - family members, coworkers, roommates - getting your information opportunistically. It doesn't defend against hackers, the government, or even slightly savvy thieves. The Google Chrome Security team begs to differ [1]. According to them giving someone the illusion of security is bad. [1] https://news.ycomb…

Giving someone the illusion of security is bad because it displaces their understanding of security.

An understanding of security will reveal that security is not a binary state of affairs. It's perfectly reasonable to trust known-imperfect mechanisms like the iPhone fingerprint reader to keep honest people honest and discourage ordinary muggers and thieves. I don't need military-grade access control for my personal iPhone, I don't want the inconvenience that would necessarily accompany it, and I damned sure don't want to pay for it.

And the Google Chrome guy is correct in all respects: it's not reasonable to expect an application to provide security that's redundant with security provided by user accounts on the OS it runs on. It would be better to teach users to create separate accounts on their system, if they want to hide their local passwords from other members of their family.

Re: Chaos Computer Club breaks Apple TouchID

#105

I have accidentally seen basically all of my friends' passcodes as they type it in at bars etc. I could get into their phones easily. TouchID is more secure than that simply because someone needs to take a 2400dpi image of the person's finger to do it. Locks (when physical access to a device is available) are to keep honest people honest. Most security experts that I know agree that if an intruder has physical access…

> Most security experts that I know agree that if an intruder has physical access to a device, it can be considered compromised because it is just a matter of time. Anyone who says this is not a security expert. That hasn't been true since full disk encryption became available. A properly encrypted device is a brick if stolen, which is the only reason to have full disk encryption in the first place.

I take it you're not a security researcher either, because "A properly encrypted device is a brick if stolen, which is the only reason to have full disk encryption in the first place" is insufficient, too.

Cold boot attacks, copying the drive and hacking the bootloader to get the drive password the next time you log in are two trivial methods, both of which have been used already.

Once you lose physical access to your hardware, it's game over. You simply cannot trust your computer after that point if you care AT ALL about maximizing security.

Re: Chaos Computer Club breaks Apple TouchID

#106
Actually, this raises an interesting thought. Couldn't a security-conscious user take advantage of this to turn "something you are" into "something you have"? Since you can train the sensor with anything, is there a market for semi-permanent, cryptographically-random... Thumb rings, or something?

Re: Chaos Computer Club breaks Apple TouchID

#107
post #43

I have accidentally seen basically all of my friends' passcodes as they type it in at bars etc. I could get into their phones easily. TouchID is more secure than that simply because someone needs to take a 2400dpi image of the person's finger to do it. Locks (when physical access to a device is available) are to keep honest people honest. Most security experts that I know agree that if an intruder has physical access…

I have accidentally seen basically all of my friends' passcodes as they type it in at bars etc. I could get into their phones easily. And your friends could change their password 365 times per year every year for the rest of their lives. With fingerprints, they get 10 password changes.

20 if they use their toes.

Re: Chaos Computer Club breaks Apple TouchID

#108

Earlier quoted context omitted.

> It's one thing to leave fingerprints all around your environment, but there is now the potential to steal your biometrics over the internet. Correct me if I'm wrong, but the biometric data never leaves the device.

It's also not stored on the device. Hashes, not fingerprints, are stored. You need the fingerprints themselves to fake out the hardware.

Rare is the phone without the owner's fingerprints stored all over it.

Re: Chaos Computer Club breaks Apple TouchID

#109

Honestly, TouchID is better than what we have today; a 4 digit useless passcode. If somebody has to take a photo of my fingerprint off a glass surface to gain access to my phone, so be it.

4 digit pin? I use a 12+ character alphanumeric password on Android.

Re: Chaos Computer Club breaks Apple TouchID

#110
post #24

I think they're missing the point. The passcode on an iPhone defends against other people in your environment - family members, coworkers, roommates - getting your information opportunistically. It doesn't defend against hackers, the government, or even slightly savvy thieves. Also, if a fingerprint sensor is significantly easier to use, and in practice will deter a class of privacy violations, it could increase over…

> It's one thing to leave fingerprints all around your environment, but there is now the potential to steal your biometrics over the internet. Correct me if I'm wrong, but the biometric data never leaves the device.

I think it's a hot topic in security circles right now that a worm or virus could infect these mobile devices and "phone home" with the data, resulting in a media nightmare.
Post reply on HN