Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

131–140 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#131
post #121

Earlier quoted context omitted.

Frontline had an excellent piece on the (lack of) reliability behind most of crime forensics. Fingerprints in particular are mentioned as being very unreliable and unscientific. The only scientifically rigorous piece of "CSI" is DNA matching. http://www.pbs.org/wgbh/pages/frontline/real-csi/

Maybe we should lick the iPhone to provide accurate DNA biometric lol

Don't give them any ideas!

Re: Chaos Computer Club breaks Apple TouchID

#132
post #107
post #43

Earlier quoted context omitted.

I have accidentally seen basically all of my friends' passcodes as they type it in at bars etc. I could get into their phones easily. And your friends could change their password 365 times per year every year for the rest of their lives. With fingerprints, they get 10 password changes.

20 if they use their toes.

22 if they also use their nipples.

Re: Chaos Computer Club breaks Apple TouchID

#133
post #122

Were people saying that this was secure? I thought it was just another fancy unlocking method like Google's "use your face to unlock"

Yes, they were - for example http://tech.fortune.cnn.com/2013/09/19/iphone-5s-fingerprint...:

"As for the tech itself, Rogers explains fingerprint scanning as a whole is more secure than the four-digit passcode. Copying someone's fingerprints remains a cumbersome process, not to mention pricey -- as much as $200,000, by some estimates."

Edit - and http://daringfireball.net/linked/2013/09/12/5s-fingerprint-s... which someone linked elsewhere in this discussion:

" And like the sensor in the iPhone 5S, the sensors ... can detect the ridge and valley pattern of your fingerprint not from the layer of dead skin on the outside of your finger (which a fake finger can easily replicate), but from the living layer of skin under the surface of your finger, using an RF signal. This will protect you from thieves trying to chop off your finger when they mug you for your phone (assuming they’re tech-literate thieves, of course), as well as from people with fake fingers using the fingerprint they lifted from your phone screen."

Re: Chaos Computer Club breaks Apple TouchID

#134
post #55

Earlier quoted context omitted.

It is considerably harder to fake.

Considerably harder? From the article: "In reality, Apple's sensor has just a higher resolution compared to the sensors so far. So we only needed to ramp up the resolution of our fake",

Difficulty of lifting a good print is probably proportional to the resolution needed. Ie, you need a higher quality print to get a higher resolution image to contain additional information.

Re: Chaos Computer Club breaks Apple TouchID

#135
post #127
post #7

Expected. Still much, much better security than no code at all. I will use it (with full knowledge of its downsides and tradeoffs) and it would behoove the CCC to not portray security as a binary state. (Just as much as it would behoove Apple to be truthful in their marketing.) Don't use it if thieves would consider going through all the effort of faking out the scanner. That's what I take from this no doubt valuable…

Not that expected. I know a lot of people were BSing about how much more secure Apple's fingerprint sensor was and how the usual techniques for faking a finger wouldn't work on it, including some security researchers.

Yes. I anxiously await Gruber's lengthy post-mortem about the fingerprint reader being just as bad as all previous fingerprint readers, equal in number, length and enthusiasm to his previous posts about how wonderful and advanced it is.

Re: Chaos Computer Club breaks Apple TouchID

#136

If we've learned anything over the past few months, it is that security is an illusion when it comes to Google, Apple and Facebook. The fingerprint scanner is not intended to protect your personal data from being accessed by nefarious cyber-spooks or crackers. The $5 dollar wrench technique is fairly effective in bypassing such security anyway. The fingerprint scanner is there so that when your phone is nicked by a m…

> The $5 dollar wrench technique I prefer Schneier's original rubber hose technique . Leaves fewer broken bones and bruises, but just as effective.

"Thermorectal cryptanalysis" it is called in Russian, and involves a soldering iron.

Re: Chaos Computer Club breaks Apple TouchID

#137
post #127
post #7

Expected. Still much, much better security than no code at all. I will use it (with full knowledge of its downsides and tradeoffs) and it would behoove the CCC to not portray security as a binary state. (Just as much as it would behoove Apple to be truthful in their marketing.) Don't use it if thieves would consider going through all the effort of faking out the scanner. That's what I take from this no doubt valuable…

Not that expected. I know a lot of people were BSing about how much more secure Apple's fingerprint sensor was and how the usual techniques for faking a finger wouldn't work on it, including some security researchers.

Well, they were wrong. Quite obviously. I'm just saying that I was very much expecting an attack like that to work.

Re: Chaos Computer Club breaks Apple TouchID

#138
post #115
post #93

Earlier quoted context omitted.

It's not as useless as all that. Assuming Apple has properly used their key derivation function, and the phone locks you out after ~10 failed attempts, and there's no way to access a locked phone's data, then a four digit passcode is actually quite secure.

A KDF wouldn't help with a 4 digit PIN

Wouldn't it? E.g., what if you did the derivation from the PIN in combination with a securely stored random salt (that could, as an added bonus, change every time you changed your key code)? That was, incidentally, what I meant by "properly used their KDF".

Re: Chaos Computer Club breaks Apple TouchID

#139
Can the fingerprint reader work with other parts of your hand ? For example if you can use the back of your finger or part of your palm then it could be a little more secure because you don't leave the prints of these everywhere.

Re: Chaos Computer Club breaks Apple TouchID

#140
post #7

Expected. Still much, much better security than no code at all. I will use it (with full knowledge of its downsides and tradeoffs) and it would behoove the CCC to not portray security as a binary state. (Just as much as it would behoove Apple to be truthful in their marketing.) Don't use it if thieves would consider going through all the effort of faking out the scanner. That's what I take from this no doubt valuable…

Yes, we often say security and think it means total protection. It doesn't. Its rare to see any security feature that cannot be bypassed or broken by some means. This is why we implement security in layers. If it were a binary state then a single layer would be sufficient. The idea is to make it so difficult to break through every layer of security that it becomes impractical but there will always be someone who does…

> Fingerprint scanning is absolutely better than a pass code

How often can you change your fingerprint? I can change my pass code virtually an infinite number of times. How often do you inadvertently leave your pass code in random places just by touching things?

A good pass code is absolutely better than fingerprint scanning.

Post reply on HN