Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

111–120 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#111
post #24

I think they're missing the point. The passcode on an iPhone defends against other people in your environment - family members, coworkers, roommates - getting your information opportunistically. It doesn't defend against hackers, the government, or even slightly savvy thieves. Also, if a fingerprint sensor is significantly easier to use, and in practice will deter a class of privacy violations, it could increase over…

You are overcomplicatimg things. The hypothetical cop could just smash your phone to pieces. Same result, less effort.

Re: Chaos Computer Club breaks Apple TouchID

#112

If we've learned anything over the past few months, it is that security is an illusion when it comes to Google, Apple and Facebook. The fingerprint scanner is not intended to protect your personal data from being accessed by nefarious cyber-spooks or crackers. The $5 dollar wrench technique is fairly effective in bypassing such security anyway. The fingerprint scanner is there so that when your phone is nicked by a m…

> The $5 dollar wrench technique I prefer Schneier's original rubber hose technique . Leaves fewer broken bones and bruises, but just as effective.

Plus, you can't get a decent sized adjustable wrench for less than $15 nowadays. Even the cheap Chinese ones that loosen the parallel alignment on the jaws after a few weeks cost more.

Re: Chaos Computer Club breaks Apple TouchID

#113
Some people seem to be forgetting what this is being used for.

This is an OPTIONAL replacement for the pass code.

However you feel about its level of security it is definitely more secure than a passcode which is the other option.

If someone wanted to target you for whatever reason then how long would they have to follow you with a high zoom camera before they would see you type the passcode in? The passcode/touch ID is to stop opportunistic unlocks not a determined attacker.

Re: Chaos Computer Club breaks Apple TouchID

#114

Earlier quoted context omitted.

Frontline had an excellent piece on the (lack of) reliability behind most of crime forensics. Fingerprints in particular are mentioned as being very unreliable and unscientific. The only scientifically rigorous piece of "CSI" is DNA matching. http://www.pbs.org/wgbh/pages/frontline/real-csi/

Even DNA can provide false negatives in the case of human chimeras.

And false positives in case of stem cell transplantation (a treatment of leukemia). There was a case where they got a false positive because of that. They discovered that it was a false positive because the alleged culprit had an alibi: He was in prison.

Re: Chaos Computer Club breaks Apple TouchID

#115
post #93

Honestly, TouchID is better than what we have today; a 4 digit useless passcode. If somebody has to take a photo of my fingerprint off a glass surface to gain access to my phone, so be it.

It's not as useless as all that. Assuming Apple has properly used their key derivation function, and the phone locks you out after ~10 failed attempts, and there's no way to access a locked phone's data, then a four digit passcode is actually quite secure.

A KDF wouldn't help with a 4 digit PIN

Re: Chaos Computer Club breaks Apple TouchID

#116

Earlier quoted context omitted.

Jailbreak is enough... When it exists. And for now it doesn't.

taking past trends into consideration, it looks like you're betting on the wrong horse, here. it will exist.

What are the actual trends on jailbreaks for iOS on current hardware?

Re: Chaos Computer Club breaks Apple TouchID

#117
post #44

Considering that people generally don't wear gloves when they use their phones this is like having a picture of your key on your door. Combine that with what we know you can do with pictures of keys[1] and yes it's obviously not a very good idea. [1]: https://news.ycombinator.com/item?id=6167246

It is a phone, you can bypass the passcode with a computer anyway - the passcode/touch is designed to prevent opportunistic unlocks not a determined attacker and it is much better than a passcode at doing that.

Re: Chaos Computer Club breaks Apple TouchID

#118

Earlier quoted context omitted.

It's also not stored on the device. Hashes, not fingerprints, are stored. You need the fingerprints themselves to fake out the hardware.

Rare is the phone without the owner's fingerprints stored all over it.

Sure, but his post was about stealing data "over the Internet". That's not possible.

All bets are off with physical access to the hardware, of course.

Re: Chaos Computer Club breaks Apple TouchID

#119

Actually, this raises an interesting thought. Couldn't a security-conscious user take advantage of this to turn "something you are" into "something you have"? Since you can train the sensor with anything, is there a market for semi-permanent, cryptographically-random... Thumb rings, or something?

This is a great idea. Go for it. -Brian :-)

Re: Chaos Computer Club breaks Apple TouchID

#120
post #53

Earlier quoted context omitted.

Theirs is better than the standard old fingerprint scanners and far better than using 'nothing' which is what they are replacing. They have blown nothing out of proportion.

if it causes people to behave recklessly because they have the false impression of security, when they would otherwise have taken better custodianship of their device and their data, then yes ... it can be worse than nothing.

That shouldn't be an issue considering most people don't have a passcode set.
Post reply on HN