Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

251–260 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#251

Earlier quoted context omitted.

Here's Apple's main marketing text on the subject: > Put your finger on the Home button, and just like that your iPhone unlocks. It’s a convenient and highly secure way to access your phone. Your fingerprint can also approve purchases from iTunes Store, the App Store, and the iBooks Store, so you don’t have to enter your password. It is definitely intended to replace passwords. Pretty good security would be to requir…

> Pretty good security would be to require both the fingerprint and a PIN You're missing the point. Right now lots of people have no password at all. Touch ID is a big improvement over having no password.

IT managers will either be thanking or cursing the CCC at this point...

Re: Chaos Computer Club breaks Apple TouchID

#252
post #169

Earlier quoted context omitted.

Touch ID is not "pretty good security" it's not even "good security" it's simply very bad security. Touch ID is better than nothing and that people use Touch ID instead of nothing is better than the current state but not by much and this definitely isn't a huge achievement. Which is really the biggest issue with Touch ID, it's advertised as such and people believe it.

> Touch ID is better than nothing... but not by much You can't be serious. A completely unlocked phone that anybody can trivially access with a swipe.. vs. a scanner that you'd have to lift and reconstruct someone's fingerprint to bypass. That is definitely a significant improvement.

Yes, how many people run $10,000 dollar competitions to get past the default swipe to unlock screen?

Re: Chaos Computer Club breaks Apple TouchID

#254

Earlier quoted context omitted.

Well, no password on their phone unlocks. But I thought Apple intended to replace your passwords in application services as well. Now, I didn't read the article at all (not a single damn word), so maybe the hack only applies to phone unlocks. If that is not the case however, then I think _you_ are missing the point. This would compromise all passwords replaced by finger print scans, right?

Reportedly when making purchases it "will still prompt you for your password every so often to 'renew Touch ID purchases.'" Source: http://www.cultofmac.com/246572/iphone-5s-first-impressions-... .

'every so often' seems a bit casual, for a payment [1,2]

[1] From the citation: "Passcodes and passwords aren’t completely eliminated by Touch ID, then, but they almost certainly will be later on."

[2] The glass screen will have your fingerprint on it, somewhere. That can be CSI'd by anyone who finds it. Anyone serious enough to do that (and its not much) can start escalating.

Re: Chaos Computer Club breaks Apple TouchID

#255

Earlier quoted context omitted.

My front door does not have a picture of my key on it. My phone has tons of fingerprints though. It's a touch screen phone. One of those words is "touch" which clearly implies your finger coming in contact with it. Even if you wanted to use gloves you need special ones for it to work properly with the capacitive screen. Unless you are continuously wiping it (the screen, not the data) it will have you prints on it.

If you slightly smear your finger every time you remove it from the sensor you shouldn't have this problem. Additionally, if you are keeping your phone in your pocket, as I do, pull it out and take a look (like I just did) and you'll be hard pressed to see much of anything resembling a useful print. I use my phone pretty much all day long and it is devoid of useful prints. Does that mean you couldn't find my prints i…

Assuming someone did steal your phone and look for prints, they would need to know which print to lift and that it's enrolled with Touch ID. After they, they only get 5 goes to be successful before the phone insists on your passcode.

CCC made it look easy but I bet it didn't work for them first try or even 5th try...

Re: Chaos Computer Club breaks Apple TouchID

#256
I don't think the goal of Touch ID is better security nor is it an attempt by Apple to prevent the loss of iPhones from theft. The goal of Touch ID at the end of the day is to make it easier for people to make purchases, entering passwords to make an iTunes/App store purchase is a hindrance to Apple's bottom line. Currently because of the steps involved, people have the ability to rethink their purchases during the time it takes to enter and confirm they want to make a purchase. Touch ID takes away a few seconds of time to make a purchase, touch your finger on the reader and BAM! instant purchase.

The steps in which the Chaos Computer Club took to break into an iPhone, no criminal would even think of undertaking. In the criminal world the longer it takes to steal something, the higher the chance you'll be caught. It's no different to an engine immobiliser that prevents a car from being stolen. If a criminal were to take their time, they could pop the bonnet and start the car, but most criminals will just take your stereo and car contents and leave the car if they can't get it started within a couple of minutes...

Although, having said that. Apple's marketing speak does make Touch ID sound much more secure than it actually is. This might come back to bite them in the behind one day if the wrong person has their iPhone and data stolen and decides to act upon Apple's somewhat deceivingly clever marketing speak in a court room with dollars to spare.

And besides making it easier for people to spend money without having time to think, a fingerprint scanner to the not-so-technology inclined sounds futuristic and cutting-edge, which in turn will sell millions upon millions of iPhone units. While many who frequent HN can see past the marketing spin and realise a fingerprint scanner isn't all that exciting or new, the lowest common denominator who buys an iPhone sees things differently.

Re: Chaos Computer Club breaks Apple TouchID

#257

Earlier quoted context omitted.

I'd be willing to bet that over the next couple of years millions of people will try to log into somebodys iPhone that they shouldn't have access to, but in the process are prevented from doing so by the fingerprint based security. I also bet, in 99.9999% or more of those cases, the attacker doesn't even attempt to bypass the security by faking the users fingerprint. I'd also be willing to bet that these figures are…

But you have to consider potential damage from the successful attack. It doesn't matter if 99% of low damage attacks are unsuccessful but 1% high damage attacks will go through. The solution is fine by itself but millions of people will use it and not understand the real level of protection.

The potential damage is zero. You (and everyone else in this thread) are forgetting that you can't steal an iPhone for more than 30 seconds anymore without Activation Lock locking you and everyone else out, forever, period, paragraph.

Activation Lock + Touch ID = all the security that almost anyone needs on a phone and much higher security than any of us have been used to up to now.

Re: Chaos Computer Club breaks Apple TouchID

#258
We see him register his index finger. Then he places his supposedly artificial index finger on his middle finger, and the phone unlocks.

Since it uses RF and goes beyond the outer layer of skin, how do we know that the middle finger wasn't already registered?

Re: Chaos Computer Club breaks Apple TouchID

#259
post #18

If we've learned anything over the past few months, it is that security is an illusion when it comes to Google, Apple and Facebook. The fingerprint scanner is not intended to protect your personal data from being accessed by nefarious cyber-spooks or crackers. The $5 dollar wrench technique is fairly effective in bypassing such security anyway. The fingerprint scanner is there so that when your phone is nicked by a m…

Giving Apple a break? Just another layer of security? That's not how Apple describes it: http://support.apple.com/kb/HT5949?viewlocale=en_US And selling a stolen iPhone on eBay does not need a password or a fingerprint, a jailbreak is enough …

Only an idiot would buy a jailbroken phone without a clean ESN on it. Those who do, know what they are getting. And you're forgetting Activation Lock, which a jailbreak will not defeat.

Re: Chaos Computer Club breaks Apple TouchID

#260

Earlier quoted context omitted.

What's the opinion? Apple said you can use this to replace your password. No one had an iTunes Store account without a password before, so this would 100% be replacing a password.

Actually, I did. I have a tweak from Cydia which autocompletes my Apple ID password when making a purchase from the App/iTunes Store.

If it autocompletes your name as well, would you say you don't have a name?
Post reply on HN