Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

141–150 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#142

At this rate, no method of security is secure.

The most secure computer is the one locked in a room and unplugged. There has never been a method of security that is secure. The first thing you learn when dealing with security is there are tradeoffs between opportunity, time, money. and usability.

While I agree with the spirit of your post, there is in fact a method of security that is definitively unbreakable (if used correctly/precluding side-channelling): the one-time-pad.

But as you imply, the reason we don't use it is because the opportunity cost and hassle of using it are too high for many uses.

Re: Chaos Computer Club breaks Apple TouchID

#143

Earlier quoted context omitted.

And now even DNA is being called into question. http://mobile.nytimes.com/2013/09/17/science/dna-double-take...

In addition to the chimeric qualities cited in the NYT article (I skimmed), IIRC some DNA sampling has in the past used and may still use a fairly limited profile of markers. The statistically likelihood of matches between distinct parties is in some cases well under the population of the world. Never read into it in detail, but I was left with the impression that "unique identifier" can be an over-statement/qualific…

>The statistically likelihood of matches between distinct parties is in some cases well under the population of the world.

In addition to that, there are problems with bias and statistical independence. A given marker is unlikely to be present in exactly 50% of the population, and to the extent that it isn't it can reduce the probability by that amount that a test match is a true match. Meanwhile the suspect pool for a given crime is likely to encompass several (perhaps many) members of the same extended family, who for the obvious reason are significantly more likely than random members of the world population to have the tested markers match one another. Even within a city you will generally see concentrations of specific ethnicities who may have a higher statistical incidence of specific genetic markers than other populations, which can screw up the numbers by an amount that historically hasn't even knowable because we don't have good numbers on the statistical incidence of specific markers within geographical populations.

The place where this is most pernicious is when they get a sample from a crime scene and run it against some "DNA database" to find a hit. Then everybody is talking about the probability that X suspect would match the DNA at the crime scene rather than the probability that someone in the database would match even if the actual perpetrator wasn't in the database.

Re: Chaos Computer Club breaks Apple TouchID

#144

Much more convienient than a passcode with a little less security. I'd still use it unless I was a CIA agent.

How is it less security though? You don't have to follow someone for very long with a high zoom camera before you can get their passcode and that is a lot easier than duplicating their fingerprint. And yeh it is much much more convenient.

Do you inadvertently leave your pass code lying around in random placed all day long? How often can you change your fingerprint?

Re: Chaos Computer Club breaks Apple TouchID

#145

Earlier quoted context omitted.

> I think they're missing the point. The passcode on an iPhone defends against other people in your environment - family members, coworkers, roommates - getting your information opportunistically. It doesn't defend against hackers, the government, or even slightly savvy thieves. The Google Chrome Security team begs to differ [1]. According to them giving someone the illusion of security is bad. [1] https://news.ycomb…

Which is ironic coming from a company known to be sharing information directly with the NSA. Name one security technology that is 100% foolproof. They don't exist. So the point isn't to rely on one thing, but to rely on many things that, used in concert, increase the risk, complexity and cost associated with subverting the entire system--not its individual components.

I don't think I've seen anyone parry an appeal to authority with an ad hominem lately. Good one.

Re: Chaos Computer Club breaks Apple TouchID

#146
post #4

iOS security is trivial to break if you have physical access to the device. TouchID (and passcodes) should be considered little more than a convenience, not a serious security measure.

Really, how do you trivially break a passcode on an iOS device? There is a way that I know about, and it is very much non-trivial.

Just use brute force or dictionary attack over the wire. Given that most users use 4-digit pass codes, this can be done usually in minutes, almost always in less than an hour.

Or, if your target is paranoid and uses a very long passcode, target the charger rather than the device itself. iOS assumes any physical device to which it is connected when unlocked is secure. Replace the usb brick with a small computer (e.g. Raspberry Pi) in a convincing looking Apple-esque case. Then wait until your target plugs in his iDevice and unlocks it. You can then dump the drive, or side load malicious code.

Re: Chaos Computer Club breaks Apple TouchID

#147

Earlier quoted context omitted.

So, if this can be accomplished with keys, have you removed all the locks from your house? Do you rotate your locks every 3-6 months?

My front door does not have a picture of my key on it. My phone has tons of fingerprints though. It's a touch screen phone. One of those words is "touch" which clearly implies your finger coming in contact with it. Even if you wanted to use gloves you need special ones for it to work properly with the capacitive screen. Unless you are continuously wiping it (the screen, not the data) it will have you prints on it.

If you slightly smear your finger every time you remove it from the sensor you shouldn't have this problem. Additionally, if you are keeping your phone in your pocket, as I do, pull it out and take a look (like I just did) and you'll be hard pressed to see much of anything resembling a useful print. I use my phone pretty much all day long and it is devoid of useful prints.

Does that mean you couldn't find my prints in other places? Sure. But I can probably find your keys in other places, too.

We know that SSL is generally not implemented properly, that the CAs are probably all hacked or subverted by the NSA, that the NSA may have developed backdoors to a number of the more popular encryption suites, but I don't hear anyone running around demanding Google or Facebook disable SSL.

If you are doing something that requires sufficient security that you don't want someone to access it via your fingerprint alone, add additional layers of security.

If you are doing something potentially incriminating ... don't do it on your freaking phone because it's probably been exploited in a dozen other ways by various authorities who can use it to find out most of what they need without being in physical possession of the phone anyway.

Most people aren't worried about the mafia or the CIA or the NSA. Most people don't even bother using a passcode, let alone a passphrase on their phones. If you can add something as easy to use as this, then it adds an additional layer of security against the casual abuse most people will find themselves subjected to (random people making calls from your phone, spouses spying on their email, etc.).

If you are worried about the CIA and the NSA, using a phone at all for anything is probably not in your best interest at this point.

Re: Chaos Computer Club breaks Apple TouchID

#148
post #124
post #111

Earlier quoted context omitted.

You are overcomplicatimg things. The hypothetical cop could just smash your phone to pieces. Same result, less effort.

Not the same result at all. You now have lost your phone and the cop has to argue that you smashed it yourself out of spite. There may be more witnesses or evidence after smashing a phone. Presumably there are even phone company records showing when and where a device went dead. I am not a lawyer but it seems to me, 9 times out 10, the cop would prefer a cleaner result - they confiscate your device, and oops, when yo…

Why wouldn't they just confiscate it, and "oops, it fell in a bucket of water"?

Re: Chaos Computer Club breaks Apple TouchID

#149
So the big question is, how hard is it to get at 2400 DPI finger print?

They don't show if they can scan the finger print off the phone. I would imagine that it could be quite tricky to get that level of resolution.

I would like to see a complete hack purely based on a finger print on the phone.

Re: Chaos Computer Club breaks Apple TouchID

#150

The "How to fake fingerprints" link [1], is one of the scariest things I have seen, given how simple it is, and how much we reply on fingerprints for linking people to crimes. BTW, for anyone who does not know about Chaos Computer Club (CCC) [2], they run a massive conference in EU. You can look at some of their talks @ http://media.ccc.de/ [1] http://dasalte.ccc.de/biometrie/fingerabdruck_kopieren?langu... [2] http:…

This is my favourite piece of "biometrics don't work" material - http://www.cs.auckland.ac.nz/~pgut001/pubs/biometrics.pdf

It's a bit old now but it's still as valid.

Post reply on HN