Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

161–170 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#161
post #127

Earlier quoted context omitted.

Not that expected. I know a lot of people were BSing about how much more secure Apple's fingerprint sensor was and how the usual techniques for faking a finger wouldn't work on it, including some security researchers.

Yes. I anxiously await Gruber's lengthy post-mortem about the fingerprint reader being just as bad as all previous fingerprint readers, equal in number, length and enthusiasm to his previous posts about how wonderful and advanced it is.

I know folks love to have on Gruber, but looking at df.net I don't see where he has compared the security of TouchID to other fingerprint readers - rather he's compared the convenience and performance of TouchID to other fingerprint implementations, and I don't know that anything in the OP would, or should, change his assessment of that.

(not an iPhone or Android user, at least not yet).

Re: Chaos Computer Club breaks Apple TouchID

#162

Earlier quoted context omitted.

Which is ironic coming from a company known to be sharing information directly with the NSA. Name one security technology that is 100% foolproof. They don't exist. So the point isn't to rely on one thing, but to rely on many things that, used in concert, increase the risk, complexity and cost associated with subverting the entire system--not its individual components.

I don't think I've seen anyone parry an appeal to authority with an ad hominem lately. Good one.

In this case it's valid.

In the same way that you'd afford extra scrutiny to a government agent making claims about what encryption methods to use, you should afford the same scrutiny to companies making security claims who are documented collaborators with the TLAs.

An ad hominem isn't always a fallacy, especially when the credibility of the speaker is legitimately in question. Saying they're automatically wrong would be fallacious (not to mention silly), but questioning credibility based on actual, documented behavior is not.

Re: Chaos Computer Club breaks Apple TouchID

#163
post #109

Honestly, TouchID is better than what we have today; a 4 digit useless passcode. If somebody has to take a photo of my fingerprint off a glass surface to gain access to my phone, so be it.

4 digit pin? I use a 12+ character alphanumeric password on Android.

I have a 5 year old iphone and 6 digit password. So one can be 100 times safer than grandparent without much effort.

I presume longer codes are ok on iphones even today?

Re: Chaos Computer Club breaks Apple TouchID

#164

Earlier quoted context omitted.

So, if this can be accomplished with keys, have you removed all the locks from your house? Do you rotate your locks every 3-6 months?

My front door does not have a picture of my key on it. My phone has tons of fingerprints though. It's a touch screen phone. One of those words is "touch" which clearly implies your finger coming in contact with it. Even if you wanted to use gloves you need special ones for it to work properly with the capacitive screen. Unless you are continuously wiping it (the screen, not the data) it will have you prints on it.

> My front door does not have a picture of my key on it.

Yeah, but as every decent locksmith will attest, very-nearly-almost-all door locks can be easily opened with the right tools. Like picking a lock is a specialist skill, so is lifting a fingerprint and making a copy of it. No security is absolute; it's all trade-offs. Making it such that it's not worth your adversary's time to bother.

Re: Chaos Computer Club breaks Apple TouchID

#165
"[I]t is far too easy to make fake fingers out of lifted prints"

Really? It seemed like this was a lot harder then just shoulder-surfing someone entering their passcode. Touch ID may be hackable, but this is still way harder for the average person to hack than a simple passcode.

AND it's way easier to swipe your finger than type in a code! Touch ID can't be worse for security; it appears it's at least a bit better.

Re: Chaos Computer Club breaks Apple TouchID

#166

Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…

Here's Apple's main marketing text on the subject:

> Put your finger on the Home button, and just like that your iPhone unlocks. It’s a convenient and highly secure way to access your phone. Your fingerprint can also approve purchases from iTunes Store, the App Store, and the iBooks Store, so you don’t have to enter your password.

It is definitely intended to replace passwords. Pretty good security would be to require both the fingerprint and a PIN (for unlocking the phone, at that stage a fingerprint is fine for authenticating iTunes' digital purchases).

Re: Chaos Computer Club breaks Apple TouchID

#167

Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…

Here's Apple's main marketing text on the subject: > Put your finger on the Home button, and just like that your iPhone unlocks. It’s a convenient and highly secure way to access your phone. Your fingerprint can also approve purchases from iTunes Store, the App Store, and the iBooks Store, so you don’t have to enter your password. It is definitely intended to replace passwords. Pretty good security would be to requir…

That's a matter of opinion, not fact.

Re: Chaos Computer Club breaks Apple TouchID

#168

Earlier quoted context omitted.

Frontline had an excellent piece on the (lack of) reliability behind most of crime forensics. Fingerprints in particular are mentioned as being very unreliable and unscientific. The only scientifically rigorous piece of "CSI" is DNA matching. http://www.pbs.org/wgbh/pages/frontline/real-csi/

Even DNA can provide false negatives in the case of human chimeras.

Chimeras are also apparently way more prevalent than we had previously realized.

http://www.nytimes.com/2013/09/17/science/dna-double-take.ht...

> But scientists are finding that it’s quite common for an individual to have multiple genomes. Some people, for example, have groups of cells with mutations that are not found in the rest of the body. Some have genomes that came from other people.

> Women can also gain genomes from their children. After a baby is born, it may leave some fetal cells behind in its mother’s body, where they can travel to different organs and be absorbed into those tissues. “It’s pretty likely that any woman who has been pregnant is a chimera,” Dr. Randolph said

Re: Chaos Computer Club breaks Apple TouchID

#169

Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…

Touch ID is not "pretty good security" it's not even "good security" it's simply very bad security.

Touch ID is better than nothing and that people use Touch ID instead of nothing is better than the current state but not by much and this definitely isn't a huge achievement. Which is really the biggest issue with Touch ID, it's advertised as such and people believe it.

Re: Chaos Computer Club breaks Apple TouchID

#170

Earlier quoted context omitted.

Here's Apple's main marketing text on the subject: > Put your finger on the Home button, and just like that your iPhone unlocks. It’s a convenient and highly secure way to access your phone. Your fingerprint can also approve purchases from iTunes Store, the App Store, and the iBooks Store, so you don’t have to enter your password. It is definitely intended to replace passwords. Pretty good security would be to requir…

That's a matter of opinion, not fact.

What's the opinion? Apple said you can use this to replace your password. No one had an iTunes Store account without a password before, so this would 100% be replacing a password.
Post reply on HN