Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

151–160 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#151

The "How to fake fingerprints" link [1], is one of the scariest things I have seen, given how simple it is, and how much we reply on fingerprints for linking people to crimes. BTW, for anyone who does not know about Chaos Computer Club (CCC) [2], they run a massive conference in EU. You can look at some of their talks @ http://media.ccc.de/ [1] http://dasalte.ccc.de/biometrie/fingerabdruck_kopieren?langu... [2] http:…

>The "How to fake fingerprints" link [1], is one of the scariest things I have seen, given how simple it is, and how much we reply on fingerprints for linking people to crimes.

I think DNA evidence is even worse. Given how simple it's for anyone (from an oppresive government to a criminal to take DNA from someone they want to frame and place in on a crime scene. Heck, it's even easier than fingerprints, and it's also thought of as "irefutable".

Re: Chaos Computer Club breaks Apple TouchID

#152
post #124
post #111

Earlier quoted context omitted.

You are overcomplicatimg things. The hypothetical cop could just smash your phone to pieces. Same result, less effort.

Not the same result at all. You now have lost your phone and the cop has to argue that you smashed it yourself out of spite. There may be more witnesses or evidence after smashing a phone. Presumably there are even phone company records showing when and where a device went dead. I am not a lawyer but it seems to me, 9 times out 10, the cop would prefer a cleaner result - they confiscate your device, and oops, when yo…

If cops wanted clean results, they wouldn't do anything that looks bad on your smartphone camera to begin with.

Re: Chaos Computer Club breaks Apple TouchID

#153
post #50

Earlier quoted context omitted.

Even DNA can provide false negatives in the case of human chimeras.

Or just someone skilled enough to place fake dna in his body such that the person taking the sample is fooled into taking it from the fake dna. Yes, this really happened - at least once that we know of: https://en.wikipedia.org/wiki/John_Schneeberger

Or someone just being careful with his DNA at the crime he commits, that then places someone else's DNA that he wants to frame?

Re: Chaos Computer Club breaks Apple TouchID

#154
post #67
post #10

Earlier quoted context omitted.

What did he claim?

Well he did approvingly quote some nonsense that the reader would only work on a 'live finger' (presumably it is supposed to be able to detect the presence of a soul?). http://daringfireball.net/linked/2013/09/12/5s-fingerprint-s...

Well, to be fair, in this case it was a live finger.

Re: Chaos Computer Club breaks Apple TouchID

#155
Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security.

A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs.

Touch ID is going to massively reduce the number of totally unsecured iPhones that require zero effort to access. That's the goal.

I think some people see "fingerprint scanner" and think "military-grade security" because that's where we've seen scanners before in movies and such. But this is really very much a solution for the consumer market, where convenience and usability are critical features of a security system. Sometimes infosec folks forget that. If you make it too hard to use (passcodes), people just bypass it. So you can blame the user, or you can try to design something easier to use. If in the end you've improved the overall security landscape, you've succeeded. I think that's what Apple is doing here.

Re: Chaos Computer Club breaks Apple TouchID

#156

Earlier quoted context omitted.

In addition to the chimeric qualities cited in the NYT article (I skimmed), IIRC some DNA sampling has in the past used and may still use a fairly limited profile of markers. The statistically likelihood of matches between distinct parties is in some cases well under the population of the world. Never read into it in detail, but I was left with the impression that "unique identifier" can be an over-statement/qualific…

>The statistically likelihood of matches between distinct parties is in some cases well under the population of the world. In addition to that, there are problems with bias and statistical independence. A given marker is unlikely to be present in exactly 50% of the population, and to the extent that it isn't it can reduce the probability by that amount that a test match is a true match. Meanwhile the suspect pool for…

>The place where this is most pernicious is when they get a sample from a crime scene and run it against some "DNA database" to find a hit. Then everybody is talking about the probability that X suspect would match the DNA at the crime scene rather than the probability that someone in the database would match even if the actual perpetrator wasn't in the database.

Or the probability that, match or not, the DNA from the crime scene belongs to the criminal.

And not, say, someone the victim came in contact with earlier, someone that happened to be in the crime scene before the crime took place, or even some third guy the actual criminal took a DNA from in order to frame him.

Re: Chaos Computer Club breaks Apple TouchID

#158

Earlier quoted context omitted.

And now even DNA is being called into question. http://mobile.nytimes.com/2013/09/17/science/dna-double-take...

In addition to the chimeric qualities cited in the NYT article (I skimmed), IIRC some DNA sampling has in the past used and may still use a fairly limited profile of markers. The statistically likelihood of matches between distinct parties is in some cases well under the population of the world. Never read into it in detail, but I was left with the impression that "unique identifier" can be an over-statement/qualific…

> The statistically likelihood of matches between distinct parties is in some cases well under the population of the world.

I thought that was pretty much always the case. Which is why DNA evidence is never used alone - you don't take DNA traces found at a scene of crime, run it against a huge database, find a match, close the case and try and sentence the matching person.

Instead you either investigate whether that matching person had means and motive and no alibi, or (more often) you check the DNA only against people you already suspect for whatever reasons.

Both variants reduce the likelihood of false positives by quite a few orders of magnitude.

Re: Chaos Computer Club breaks Apple TouchID

#159

Earlier quoted context omitted.

Which is ironic coming from a company known to be sharing information directly with the NSA. Name one security technology that is 100% foolproof. They don't exist. So the point isn't to rely on one thing, but to rely on many things that, used in concert, increase the risk, complexity and cost associated with subverting the entire system--not its individual components.

I don't think I've seen anyone parry an appeal to authority with an ad hominem lately. Good one.

Umm... I think the point was to subvert the appeal to authority by pointing out that Google has been compromised.

The main argument is in the second paragraph.

Anyhow, thanks for noticing :)

Re: Chaos Computer Club breaks Apple TouchID

#160
post #140

Earlier quoted context omitted.

Yes, we often say security and think it means total protection. It doesn't. Its rare to see any security feature that cannot be bypassed or broken by some means. This is why we implement security in layers. If it were a binary state then a single layer would be sufficient. The idea is to make it so difficult to break through every layer of security that it becomes impractical but there will always be someone who does…

> Fingerprint scanning is absolutely better than a pass code How often can you change your fingerprint? I can change my pass code virtually an infinite number of times. How often do you inadvertently leave your pass code in random places just by touching things? A good pass code is absolutely better than fingerprint scanning.

That's hyperbolic. How often can someone see your passcode over your shoulder? Or have it picked up by a security camera? Fingerprint scanning absolutely has advantages over pass codes.

Security is all about trade-offs. This result was to be expected (in some form). What will be worry me is if the "secure enclave" where the fingerprint data is stored is cracked (and I wouldn't be surprised if that happens too eventually).

Post reply on HN