Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

241–250 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#241
post #146

Earlier quoted context omitted.

Really, how do you trivially break a passcode on an iOS device? There is a way that I know about, and it is very much non-trivial.

Just use brute force or dictionary attack over the wire. Given that most users use 4-digit pass codes, this can be done usually in minutes, almost always in less than an hour. Or, if your target is paranoid and uses a very long passcode, target the charger rather than the device itself. iOS assumes any physical device to which it is connected when unlocked is secure. Replace the usb brick with a small computer (e.g.…

> iOS assumes any physical device to which it is connected when unlocked is secure

I thought this was fixed in iOS7?

Re: Chaos Computer Club breaks Apple TouchID

#242
First, the fingerprint of the enroled user is photographed with 2400 dpi resolution. The resulting image is then cleaned up, inverted and laser printed with 1200 dpi onto transparent sheet with a thick toner setting. Finally, pink latex milk or white woodglue is smeared into the pattern created by the toner onto the transparent sheet. After it cures, the thin latex sheet is lifted from the sheet, breathed on to make it a tiny bit moist and then placed onto the sensor to unlock the phone.

Yeah, easy as pie.

Finger chopping should be added to this xkcd:

Security:

http://xkcd.com/538/

Re: Chaos Computer Club breaks Apple TouchID

#243

Earlier quoted context omitted.

Here's Apple's main marketing text on the subject: > Put your finger on the Home button, and just like that your iPhone unlocks. It’s a convenient and highly secure way to access your phone. Your fingerprint can also approve purchases from iTunes Store, the App Store, and the iBooks Store, so you don’t have to enter your password. It is definitely intended to replace passwords. Pretty good security would be to requir…

"you don’t have to enter your password" != "you don't need a password" As I understand it every now and again Apple will prompt you to enter your passcode/password, such as when you restart your device or if you haven't unlocked it in two days. Hardly a signal that passwords are done.

I love the psuedo lawyer speak in this thread

Re: Chaos Computer Club breaks Apple TouchID

#244

Earlier quoted context omitted.

Here's Apple's main marketing text on the subject: > Put your finger on the Home button, and just like that your iPhone unlocks. It’s a convenient and highly secure way to access your phone. Your fingerprint can also approve purchases from iTunes Store, the App Store, and the iBooks Store, so you don’t have to enter your password. It is definitely intended to replace passwords. Pretty good security would be to requir…

> Pretty good security would be to require both the fingerprint and a PIN You're missing the point. Right now lots of people have no password at all. Touch ID is a big improvement over having no password.

[deleted]

Re: Chaos Computer Club breaks Apple TouchID

#245

Earlier quoted context omitted.

> Pretty good security would be to require both the fingerprint and a PIN You're missing the point. Right now lots of people have no password at all. Touch ID is a big improvement over having no password.

Well, no password on their phone unlocks. But I thought Apple intended to replace your passwords in application services as well. Now, I didn't read the article at all (not a single damn word), so maybe the hack only applies to phone unlocks. If that is not the case however, then I think _you_ are missing the point. This would compromise all passwords replaced by finger print scans, right?

Reportedly when making purchases it "will still prompt you for your password every so often to 'renew Touch ID purchases.'"

Source: http://www.cultofmac.com/246572/iphone-5s-first-impressions-....

Re: Chaos Computer Club breaks Apple TouchID

#246
post #169

Earlier quoted context omitted.

Touch ID is not "pretty good security" it's not even "good security" it's simply very bad security. Touch ID is better than nothing and that people use Touch ID instead of nothing is better than the current state but not by much and this definitely isn't a huge achievement. Which is really the biggest issue with Touch ID, it's advertised as such and people believe it.

> Touch ID is better than nothing... but not by much You can't be serious. A completely unlocked phone that anybody can trivially access with a swipe.. vs. a scanner that you'd have to lift and reconstruct someone's fingerprint to bypass. That is definitely a significant improvement.

> That is definitely a significant improvement.

Sure is a significant improvement for some people at least. http://t.co/EK3sdeloUX

Re: Chaos Computer Club breaks Apple TouchID

#247
post #238

Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…

This seems correct. Apple's moved the bar to breaking into those phones from having the phone and a 4 digit or no passcode to having: -- the phone -- a 2400 dpi resolution image of the correct fingerprint -- a 1200 dpi laser printer & transparent paper -- pink latex milk or white woodglue -- a non-trivial amount of time

That's what I was thinking, too. The fingerprint scanner is a bit like a LoJack - it's still possible to steal a car with a "The Club" on it, but most thieves will probably just move on to another car (although I've heard that car thieves, like pick pockets, don't really steal cars anymore, just components and loose gear.)

Re: Chaos Computer Club breaks Apple TouchID

#248

Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…

I don't put any passcode because thieves will throw aways SIM card and they won't be able to connect to wifi/internet. Then I will not be able to track it.

Apple should implement a way to let them connect wifi and browse basic stuff like a "guest" mode. Meanwhile we track them.

Re: Chaos Computer Club breaks Apple TouchID

#249

Earlier quoted context omitted.

I'd be willing to bet that over the next couple of years millions of people will try to log into somebodys iPhone that they shouldn't have access to, but in the process are prevented from doing so by the fingerprint based security. I also bet, in 99.9999% or more of those cases, the attacker doesn't even attempt to bypass the security by faking the users fingerprint. I'd also be willing to bet that these figures are…

But you have to consider potential damage from the successful attack. It doesn't matter if 99% of low damage attacks are unsuccessful but 1% high damage attacks will go through. The solution is fine by itself but millions of people will use it and not understand the real level of protection.

Well right now I'd guess that the percent of high damage attacks that go through are significantly higher than 1%, so lowering that to "1%" isn't an improvement?
Post reply on HN