"Biometrics is fundamentally a technology designed for oppression and control, not for securing everyday device access."
It explains why Brazil is trying to put biometric scanners on the electronic voting machines.
191–200 of 458 posts
"Biometrics is fundamentally a technology designed for oppression and control, not for securing everyday device access."
It explains why Brazil is trying to put biometric scanners on the electronic voting machines.
If we've learned anything over the past few months, it is that security is an illusion when it comes to Google, Apple and Facebook. The fingerprint scanner is not intended to protect your personal data from being accessed by nefarious cyber-spooks or crackers. The $5 dollar wrench technique is fairly effective in bypassing such security anyway. The fingerprint scanner is there so that when your phone is nicked by a m…
Except where I live there is organized phone snatching. A crew of phone hackers hire drug addicts to yoink phones off transit riders and then pay them 10% of the value. They then go to work on the phone changing the IMEI and I would imagine easily bypassing this fingerprint auth. They make use of the data for fraud purposes and then wipe and sell the phone on the street, a block away from where I live outside a run d…
Honestly, TouchID is better than what we have today; a 4 digit useless passcode. If somebody has to take a photo of my fingerprint off a glass surface to gain access to my phone, so be it.
4 digit pin? I use a 12+ character alphanumeric password on Android.
The point of TouchID was to have a more secure default for most than a 4 digit pin or, more commonly, no pin or password at all. Few people would be happy with having to enter a 12+ character alphanumeric password each time they wanted to use their phone, you're an outlier there.
Earlier quoted context omitted.
Really, how do you trivially break a passcode on an iOS device? There is a way that I know about, and it is very much non-trivial.
Just use brute force or dictionary attack over the wire. Given that most users use 4-digit pass codes, this can be done usually in minutes, almost always in less than an hour. Or, if your target is paranoid and uses a very long passcode, target the charger rather than the device itself. iOS assumes any physical device to which it is connected when unlocked is secure. Replace the usb brick with a small computer (e.g.…
What is the resolution of the fingerprint image stored in biometric passport, i.e., the kind of passport you need to enter the US? Biometric passports store an actual fingerprint image and not just a hash like the iPhone 5S. So if the resolution was high enough, everyone with access to a biometric passport – for example by scanning people carrying such passports around at an airport – could forge fingerprints …
Earlier quoted context omitted.
Just use brute force or dictionary attack over the wire. Given that most users use 4-digit pass codes, this can be done usually in minutes, almost always in less than an hour. Or, if your target is paranoid and uses a very long passcode, target the charger rather than the device itself. iOS assumes any physical device to which it is connected when unlocked is secure. Replace the usb brick with a small computer (e.g.…
> Just use brute force or dictionary attack over the wire. Given that most users use 4-digit pass codes, this can be done usually in minutes, almost always in less than an hour. It's clear you've never actually attempted this. The timeout between passcode entries increases with the number of consecutive failures. Get 10 wrong in a row, and the device is wiped (if the user has chosen that option). > Or, if your target…
> The timeout between passcode entries increases with the number of consecutive failures. Get 10 wrong in a row, and the device is wiped (if the user has chosen that option).
Only if you're typing in pass codes to the lock screen, which isn't how its done. An attacker would instead image the flash, grab the Dkey from effaceable storage, and decrypt the filesystem. Indeed this is exactly how professional iOS forensic analysis kits work. This will get you access to SMS, photos, and anything else that doesn't fall under Data Protection.
Data Protection, a second level of encryption that uses your passcode to generate keys, is only used on the keychain block and emails by default. To crack Data Protection, use brute force on the copied data, not on the iDevice itself.
>This no longer works on iOS 7. The user has to manually choose to trust the computer they're attached to prior to any communication going across the wire.
Cool, I didn't know that.
EDIT:
Here's a good overview: http://mobappsectriathlon.blogspot.com/2012/09/how-do-you-pr...
Earlier quoted context omitted.
Really, how do you trivially break a passcode on an iOS device? There is a way that I know about, and it is very much non-trivial.
Just use brute force or dictionary attack over the wire. Given that most users use 4-digit pass codes, this can be done usually in minutes, almost always in less than an hour. Or, if your target is paranoid and uses a very long passcode, target the charger rather than the device itself. iOS assumes any physical device to which it is connected when unlocked is secure. Replace the usb brick with a small computer (e.g.…
Your latter attack is an entirely different threat model, and can't be used on a stolen device.
Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…
Touch ID is not "pretty good security" it's not even "good security" it's simply very bad security. Touch ID is better than nothing and that people use Touch ID instead of nothing is better than the current state but not by much and this definitely isn't a huge achievement. Which is really the biggest issue with Touch ID, it's advertised as such and people believe it.
TouchID represents a massive increase in security over draw pattern to unlock, and it's easier to use at the same time.
It probably also represents an increase in security over 4 digit PIN codes, though that's shakier.