Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

121–130 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#121

The "How to fake fingerprints" link [1], is one of the scariest things I have seen, given how simple it is, and how much we reply on fingerprints for linking people to crimes. BTW, for anyone who does not know about Chaos Computer Club (CCC) [2], they run a massive conference in EU. You can look at some of their talks @ http://media.ccc.de/ [1] http://dasalte.ccc.de/biometrie/fingerabdruck_kopieren?langu... [2] http:…

Frontline had an excellent piece on the (lack of) reliability behind most of crime forensics. Fingerprints in particular are mentioned as being very unreliable and unscientific. The only scientifically rigorous piece of "CSI" is DNA matching. http://www.pbs.org/wgbh/pages/frontline/real-csi/

Maybe we should lick the iPhone to provide accurate DNA biometric lol

Re: Chaos Computer Club breaks Apple TouchID

#123
post #94
post #65

I thought, based on anandtech review, that this scanner is not optical but electrical, hence "sub epidermal scanning", so why does a printed finger work?

It looks like either of the following: - the capacitance of the ridges and crests of one's fingerprint dominates any differences in subcutaneous capacitance (possibly because they are closer to the scanner, or because there simply is too little variance in capacitance between flesh and hair veins) - subcutaneous structures resembles fingerprints too much (seems quite possible, as there must be a reason that it is har…

The subcutaneous structures are, from what I've read, basically the same as the surface ridges and crests.

Re: Chaos Computer Club breaks Apple TouchID

#124
post #111
post #24

I think they're missing the point. The passcode on an iPhone defends against other people in your environment - family members, coworkers, roommates - getting your information opportunistically. It doesn't defend against hackers, the government, or even slightly savvy thieves. Also, if a fingerprint sensor is significantly easier to use, and in practice will deter a class of privacy violations, it could increase over…

You are overcomplicatimg things. The hypothetical cop could just smash your phone to pieces. Same result, less effort.

Not the same result at all. You now have lost your phone and the cop has to argue that you smashed it yourself out of spite. There may be more witnesses or evidence after smashing a phone. Presumably there are even phone company records showing when and where a device went dead.

I am not a lawyer but it seems to me, 9 times out 10, the cop would prefer a cleaner result - they confiscate your device, and oops, when you get it back, the video is gone.

Re: Chaos Computer Club breaks Apple TouchID

#125

Much more convienient than a passcode with a little less security. I'd still use it unless I was a CIA agent.

How is it less security though? You don't have to follow someone for very long with a high zoom camera before you can get their passcode and that is a lot easier than duplicating their fingerprint. And yeh it is much much more convenient.

Re: Chaos Computer Club breaks Apple TouchID

#126

The "How to fake fingerprints" link [1], is one of the scariest things I have seen, given how simple it is, and how much we reply on fingerprints for linking people to crimes. BTW, for anyone who does not know about Chaos Computer Club (CCC) [2], they run a massive conference in EU. You can look at some of their talks @ http://media.ccc.de/ [1] http://dasalte.ccc.de/biometrie/fingerabdruck_kopieren?langu... [2] http:…

Frontline had an excellent piece on the (lack of) reliability behind most of crime forensics. Fingerprints in particular are mentioned as being very unreliable and unscientific. The only scientifically rigorous piece of "CSI" is DNA matching. http://www.pbs.org/wgbh/pages/frontline/real-csi/

Isn't it rather easy to obtain somebody's DNA, and also clone it? Seems even easier than obtaining somebody's fingerprints.

Re: Chaos Computer Club breaks Apple TouchID

#127
post #7

Expected. Still much, much better security than no code at all. I will use it (with full knowledge of its downsides and tradeoffs) and it would behoove the CCC to not portray security as a binary state. (Just as much as it would behoove Apple to be truthful in their marketing.) Don't use it if thieves would consider going through all the effort of faking out the scanner. That's what I take from this no doubt valuable…

Not that expected. I know a lot of people were BSing about how much more secure Apple's fingerprint sensor was and how the usual techniques for faking a finger wouldn't work on it, including some security researchers.

Re: Chaos Computer Club breaks Apple TouchID

#128
post #44

Considering that people generally don't wear gloves when they use their phones this is like having a picture of your key on your door. Combine that with what we know you can do with pictures of keys[1] and yes it's obviously not a very good idea. [1]: https://news.ycombinator.com/item?id=6167246

So, if this can be accomplished with keys, have you removed all the locks from your house? Do you rotate your locks every 3-6 months?

My front door does not have a picture of my key on it. My phone has tons of fingerprints though. It's a touch screen phone. One of those words is "touch" which clearly implies your finger coming in contact with it. Even if you wanted to use gloves you need special ones for it to work properly with the capacitive screen. Unless you are continuously wiping it (the screen, not the data) it will have you prints on it.

Re: Chaos Computer Club breaks Apple TouchID

#129
post #87

Earlier quoted context omitted.

Then create a detailed model using said high resolution fingerprint. If someone cares enough about your phone to do that, they can probably break into it by other means anyway (jail break, brute force passcode, etc)

You leave finger prints on the phone. Just snap a photo with a decent camera - it's probably enough detail. Print it. Stick some latex or glue on it (literally available everywhere). That's it . This is not rocket science or time consuming like brute forcing. You don't even have to shoulder-surf to catch their password.

Importantly, this has been demonstrated. The CCC has been doing it for years and published a howto with material costs in the low one-digit Euro range.

http://translate.google.com/translate?sl=de&tl=en&js=n&prev=...

Re: Chaos Computer Club breaks Apple TouchID

#130
post #109

Honestly, TouchID is better than what we have today; a 4 digit useless passcode. If somebody has to take a photo of my fingerprint off a glass surface to gain access to my phone, so be it.

4 digit pin? I use a 12+ character alphanumeric password on Android.

To unlock your phone? Each time you need to use / check it?
Post reply on HN