I think they're missing the point. The passcode on an iPhone defends against other people in your environment - family members, coworkers, roommates - getting your information opportunistically. It doesn't defend against hackers, the government, or even slightly savvy thieves. Also, if a fingerprint sensor is significantly easier to use, and in practice will deter a class of privacy violations, it could increase over…
Chaos Computer Club breaks Apple TouchID
111–120 of 458 posts
Re: Chaos Computer Club breaks Apple TouchID
#112If we've learned anything over the past few months, it is that security is an illusion when it comes to Google, Apple and Facebook. The fingerprint scanner is not intended to protect your personal data from being accessed by nefarious cyber-spooks or crackers. The $5 dollar wrench technique is fairly effective in bypassing such security anyway. The fingerprint scanner is there so that when your phone is nicked by a m…
> The $5 dollar wrench technique I prefer Schneier's original rubber hose technique . Leaves fewer broken bones and bruises, but just as effective.
Re: Chaos Computer Club breaks Apple TouchID
#113This is an OPTIONAL replacement for the pass code.
However you feel about its level of security it is definitely more secure than a passcode which is the other option.
If someone wanted to target you for whatever reason then how long would they have to follow you with a high zoom camera before they would see you type the passcode in? The passcode/touch ID is to stop opportunistic unlocks not a determined attacker.
Re: Chaos Computer Club breaks Apple TouchID
#114Earlier quoted context omitted.
Frontline had an excellent piece on the (lack of) reliability behind most of crime forensics. Fingerprints in particular are mentioned as being very unreliable and unscientific. The only scientifically rigorous piece of "CSI" is DNA matching. http://www.pbs.org/wgbh/pages/frontline/real-csi/
Even DNA can provide false negatives in the case of human chimeras.
Re: Chaos Computer Club breaks Apple TouchID
#115Honestly, TouchID is better than what we have today; a 4 digit useless passcode. If somebody has to take a photo of my fingerprint off a glass surface to gain access to my phone, so be it.
It's not as useless as all that. Assuming Apple has properly used their key derivation function, and the phone locks you out after ~10 failed attempts, and there's no way to access a locked phone's data, then a four digit passcode is actually quite secure.
Re: Chaos Computer Club breaks Apple TouchID
#116Re: Chaos Computer Club breaks Apple TouchID
#117Considering that people generally don't wear gloves when they use their phones this is like having a picture of your key on your door. Combine that with what we know you can do with pictures of keys[1] and yes it's obviously not a very good idea. [1]: https://news.ycombinator.com/item?id=6167246
Re: Chaos Computer Club breaks Apple TouchID
#118Earlier quoted context omitted.
It's also not stored on the device. Hashes, not fingerprints, are stored. You need the fingerprints themselves to fake out the hardware.
Rare is the phone without the owner's fingerprints stored all over it.
All bets are off with physical access to the hardware, of course.
Re: Chaos Computer Club breaks Apple TouchID
#119Actually, this raises an interesting thought. Couldn't a security-conscious user take advantage of this to turn "something you are" into "something you have"? Since you can train the sensor with anything, is there a market for semi-permanent, cryptographically-random... Thumb rings, or something?
Re: Chaos Computer Club breaks Apple TouchID
#120Earlier quoted context omitted.
Theirs is better than the standard old fingerprint scanners and far better than using 'nothing' which is what they are replacing. They have blown nothing out of proportion.
if it causes people to behave recklessly because they have the false impression of security, when they would otherwise have taken better custodianship of their device and their data, then yes ... it can be worse than nothing.