Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

261–270 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#261
post #169

Earlier quoted context omitted.

Touch ID is not "pretty good security" it's not even "good security" it's simply very bad security. Touch ID is better than nothing and that people use Touch ID instead of nothing is better than the current state but not by much and this definitely isn't a huge achievement. Which is really the biggest issue with Touch ID, it's advertised as such and people believe it.

While I don't have data to back it up, I believe most Android users use the draw pattern to unlock method. This feature is absolutely trivial to defeat - you can simply hold the phone up to the light, see the trails of oil left on the phone, and follow that trail. People have done this to my own phone with just a few tries. TouchID represents a massive increase in security over draw pattern to unlock, and it's easier…

Doesn't the trail get cleaned off when you put it in your pocket?

Re: Chaos Computer Club breaks Apple TouchID

#262
post #254

Earlier quoted context omitted.

Reportedly when making purchases it "will still prompt you for your password every so often to 'renew Touch ID purchases.'" Source: http://www.cultofmac.com/246572/iphone-5s-first-impressions-... .

'every so often' seems a bit casual, for a payment [1,2] [1] From the citation: "Passcodes and passwords aren’t completely eliminated by Touch ID, then, but they almost certainly will be later on." [2] The glass screen will have your fingerprint on it, somewhere. That can be CSI'd by anyone who finds it. Anyone serious enough to do that (and its not much) can start escalating.

Since they'd reverse the charges anyway if it wasn't you who made them, what exactly is the problem here?

Re: Chaos Computer Club breaks Apple TouchID

#263
post #254

Earlier quoted context omitted.

Reportedly when making purchases it "will still prompt you for your password every so often to 'renew Touch ID purchases.'" Source: http://www.cultofmac.com/246572/iphone-5s-first-impressions-... .

'every so often' seems a bit casual, for a payment [1,2] [1] From the citation: "Passcodes and passwords aren’t completely eliminated by Touch ID, then, but they almost certainly will be later on." [2] The glass screen will have your fingerprint on it, somewhere. That can be CSI'd by anyone who finds it. Anyone serious enough to do that (and its not much) can start escalating.

When most payments are under $5 it's probably ok. It's good enough for the credit/debit card payment industry, at least. (They relaxed the rules so you don't have to sign or enter a PIN for small purchases.)

Re: Chaos Computer Club breaks Apple TouchID

#264

Earlier quoted context omitted.

> Touch ID is better than nothing... but not by much You can't be serious. A completely unlocked phone that anybody can trivially access with a swipe.. vs. a scanner that you'd have to lift and reconstruct someone's fingerprint to bypass. That is definitely a significant improvement.

> That is definitely a significant improvement. Sure is a significant improvement for some people at least. http://t.co/EK3sdeloUX

Baseless FUD is OK as long as Linux ain't the target, right?

Re: Chaos Computer Club breaks Apple TouchID

#265
post #212

Earlier quoted context omitted.

"Only if you're typing in pass codes to the lock screen, which isn't how its done. An attacker would instead image the flash, grab the Dkey from effaceable storage, and decrypt the filesystem. Indeed this is exactly how professional iOS forensic analysis kits work. This will get you access to SMS, photos, and anything else that doesn't fall under Data Protection." Yep, as I suspected, you haven't done this ;) Please…

I didn't say "simple." I said "trivial" :) Nope, I've never done this live. For this I'm reliant upon what I've read. Feel free to tell me what's wrong. Stating how it works, or pointing the way to an accurate source, is infinitely more helpful than saying "you're wrong", even if it might feel satisfying. Here's my understanding of how the initial loading works. BootROM uses a series of RSA validity checks on the cha…

I just told you. You need a bootrom exploit. That's the non-trivial part. Nobody has one, and they haven't since 2010. I mean, the NSA might, but the forensics companies don't, and there aren't any public ones. Hence, it's far from trivial.

Even with the multi-thousand dollar forensics kits, you cannot even begin a brute force PIN attack on any bootrom for any iphone or ipad still on sale. The last devices it worked on was iphone 4 (not 4S) and ipad 2.

Re: Chaos Computer Club breaks Apple TouchID

#266
In the comments there is so much focus on the convenient aspect of TouchID. I agree, but the main point I think is that we have a situation where:

- fingerprint authentication will be seen as more casual and mainstream than it was before [1]

- people will still leave fingerprints everywhere, including around and on the fingerprint sensors

- once a high resolution image of a fingerprint is done, it can be re-used for literaly a lifetime (imagine keeping track of someone for years and use his/her fingerprints anytime it's needed)

- if enough applications rely on fingeprint authentication, exchanging fingerprint databases might become lucrative enough

From this point of view, seeing TouchID as just a cute way adding some security to a phone is too candid I think. It will have an immediate positive effect for casual phone locking, but would bring much worse effects down the line.

Optimisticly no one would rely on fingerprints alone to authenticate users for anything important. But the definition of what's important is blurry, and there is so many situations now where weak passwords are used, but it would be so tempting to switch to fingerprints (door unlock for instance...).

[1] laptops had finger unlock features for years now, but it never really made it to the wild masses I think. Fujitsu phones had a fingerprint reader too, but again, I don't remember other makers picking up the feature.

Re: Chaos Computer Club breaks Apple TouchID

#267
post #44

Considering that people generally don't wear gloves when they use their phones this is like having a picture of your key on your door. Combine that with what we know you can do with pictures of keys[1] and yes it's obviously not a very good idea. [1]: https://news.ycombinator.com/item?id=6167246

no no no no no. This is not being done by lifting an existing print from the existing device. They're taking a photo of the authorised FINGER and using that to create their fake finger... I don't see how this could be considered a significant issue unless you are going to steal someones phone AND somehow get a still 2400 dpi photo of the surface of their finger

You are incorrect. Second sentence of the article: "A fingerprint of the phone user, photographed from a glass surface, was enough to create a fake finger that could unlock an iPhone 5s secured with TouchID."

Re: Chaos Computer Club breaks Apple TouchID

#269

Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…

> The goal is to get more consumers to move from zero security to pretty good security.

One might argue that Touch ID is too strong to be used where there was no security before. In an arms race with thefts and hackers, leaping too far forwards might not be the best option in the long term.

Re: Chaos Computer Club breaks Apple TouchID

#270
post #109

Honestly, TouchID is better than what we have today; a 4 digit useless passcode. If somebody has to take a photo of my fingerprint off a glass surface to gain access to my phone, so be it.

4 digit pin? I use a 12+ character alphanumeric password on Android.

Sure, a few people use long passwords on their phones (usually when forced to do so by corporate security policies. However, most don't, because it's impractical. Many don't even use a pin lock.
Post reply on HN