Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

211–220 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#211

Earlier quoted context omitted.

> It's one thing to leave fingerprints all around your environment, but there is now the potential to steal your biometrics over the internet. Correct me if I'm wrong, but the biometric data never leaves the device.

It's also not stored on the device. Hashes, not fingerprints, are stored. You need the fingerprints themselves to fake out the hardware.

Looks like fingerprints have 30-40ish bits of entropy depending on how forgiving the device is, so unless they're doing some key stretching it should be practical to produce an image of a similar fingerprint by brute-forcing the hash with every biologically likely fingerprint.

http://lukenotricks.blogspot.com/2009/04/on-entropy-of-finge...

Re: Chaos Computer Club breaks Apple TouchID

#212
post #198

Earlier quoted context omitted.

I'll ignore the needless snark. > The timeout between passcode entries increases with the number of consecutive failures. Get 10 wrong in a row, and the device is wiped (if the user has chosen that option). Only if you're typing in pass codes to the lock screen, which isn't how its done. An attacker would instead image the flash, grab the Dkey from effaceable storage, and decrypt the filesystem. Indeed this is exactl…

"Only if you're typing in pass codes to the lock screen, which isn't how its done. An attacker would instead image the flash, grab the Dkey from effaceable storage, and decrypt the filesystem. Indeed this is exactly how professional iOS forensic analysis kits work. This will get you access to SMS, photos, and anything else that doesn't fall under Data Protection." Yep, as I suspected, you haven't done this ;) Please…

I didn't say "simple." I said "trivial" :)

Nope, I've never done this live. For this I'm reliant upon what I've read. Feel free to tell me what's wrong. Stating how it works, or pointing the way to an accurate source, is infinitely more helpful than saying "you're wrong", even if it might feel satisfying.

Here's my understanding of how the initial loading works. BootROM uses a series of RSA validity checks on the chain of software components to load the RAMdisk (which is used for update in DFU mode.) To load your own RAMdisk, you need an exploit in bootROM (which are the same exploits used for jailbreaking, and thus of high value for the community to discover.)

Re: Chaos Computer Club breaks Apple TouchID

#213
post #55

Earlier quoted context omitted.

It is considerably harder to fake.

It doesn't look it. From the description in the article it appears to be a very similar process to what has been used before, just with a higher resolution printer, but not one that is outside the realm of photo printers.

Getting a precise enough print is the hard part. Note that they started with a perfect, carefully staged print, so they haven't really cracked it.

Re: Chaos Computer Club breaks Apple TouchID

#214

Earlier quoted context omitted.

That shouldn't be an issue considering most people don't have a passcode set.

Another option would be to just require a PIN (or both a PIN and fingerprint).

Yeah, that's going to move consumer devices. "Now harder to use!"

Re: Chaos Computer Club breaks Apple TouchID

#215
post #53

Earlier quoted context omitted.

Theirs is better than the standard old fingerprint scanners and far better than using 'nothing' which is what they are replacing. They have blown nothing out of proportion.

if it causes people to behave recklessly because they have the false impression of security, when they would otherwise have taken better custodianship of their device and their data, then yes ... it can be worse than nothing.

What would you call more reckless than having no passcode at all?

Re: Chaos Computer Club breaks Apple TouchID

#216
post #205

Earlier quoted context omitted.

While I don't have data to back it up, I believe most Android users use the draw pattern to unlock method. This feature is absolutely trivial to defeat - you can simply hold the phone up to the light, see the trails of oil left on the phone, and follow that trail. People have done this to my own phone with just a few tries. TouchID represents a massive increase in security over draw pattern to unlock, and it's easier…

People actually do other actions on their phone after unlocking it. If somebody swipes on their homescreen, browse the web, etc, the trail would not be just the unlock pattern. The exploit you're talking about may work if you get hold of the phone right after the user unlocks it since the trail only has the pattern.

It also doesn't work nearly as well if you are OCD about wiping your screen often, not that that makes the pattern lock any better but it isn't quite that trivial to defeat

Re: Chaos Computer Club breaks Apple TouchID

#217
even though it was almost expected to be bypassed easily, using fingerprints can still be handy if one wants to establish claim on a device. I believe the thinking was to provide a way to uniquely link the device to an entity - security was just a byproduct (but marketing trumpeted it)

Re: Chaos Computer Club breaks Apple TouchID

#218

Earlier quoted context omitted.

I know folks love to have on Gruber, but looking at df.net I don't see where he has compared the security of TouchID to other fingerprint readers - rather he's compared the convenience and performance of TouchID to other fingerprint implementations, and I don't know that anything in the OP would, or should, change his assessment of that. (not an iPhone or Android user, at least not yet).

Gruber is an ignorant fanboy. There are too many examples to pick from, but here's a recent one. In his iPhone 5S review he rambles on about how Apple is an innovator and picks out the A7 procesor, TouchID and a new burst-mode camera feature: "But the real innovation — there’s that word — is software, right there on the device itself, that makes it easy to select only the shots from those bursts that you really want…

So rather than addressing the point, you attack him on something completely different. Presumably because there are actually no examples where he's been wrong about TouchID.

Re: Chaos Computer Club breaks Apple TouchID

#219
post #169

Earlier quoted context omitted.

Touch ID is not "pretty good security" it's not even "good security" it's simply very bad security. Touch ID is better than nothing and that people use Touch ID instead of nothing is better than the current state but not by much and this definitely isn't a huge achievement. Which is really the biggest issue with Touch ID, it's advertised as such and people believe it.

I'd be willing to bet that over the next couple of years millions of people will try to log into somebodys iPhone that they shouldn't have access to, but in the process are prevented from doing so by the fingerprint based security. I also bet, in 99.9999% or more of those cases, the attacker doesn't even attempt to bypass the security by faking the users fingerprint. I'd also be willing to bet that these figures are…

But you have to consider potential damage from the successful attack. It doesn't matter if 99% of low damage attacks are unsuccessful but 1% high damage attacks will go through. The solution is fine by itself but millions of people will use it and not understand the real level of protection.

Re: Chaos Computer Club breaks Apple TouchID

#220
post #44

Considering that people generally don't wear gloves when they use their phones this is like having a picture of your key on your door. Combine that with what we know you can do with pictures of keys[1] and yes it's obviously not a very good idea. [1]: https://news.ycombinator.com/item?id=6167246

no no no no no.

This is not being done by lifting an existing print from the existing device. They're taking a photo of the authorised FINGER and using that to create their fake finger...

I don't see how this could be considered a significant issue unless you are going to steal someones phone AND somehow get a still 2400 dpi photo of the surface of their finger

Post reply on HN