Earlier quoted context omitted.
Touch ID is not "pretty good security" it's not even "good security" it's simply very bad security. Touch ID is better than nothing and that people use Touch ID instead of nothing is better than the current state but not by much and this definitely isn't a huge achievement. Which is really the biggest issue with Touch ID, it's advertised as such and people believe it.
While I don't have data to back it up, I believe most Android users use the draw pattern to unlock method. This feature is absolutely trivial to defeat - you can simply hold the phone up to the light, see the trails of oil left on the phone, and follow that trail. People have done this to my own phone with just a few tries. TouchID represents a massive increase in security over draw pattern to unlock, and it's easier…
Chaos Computer Club breaks Apple TouchID
261–270 of 458 posts
Re: Chaos Computer Club breaks Apple TouchID
#262Earlier quoted context omitted.
Reportedly when making purchases it "will still prompt you for your password every so often to 'renew Touch ID purchases.'" Source: http://www.cultofmac.com/246572/iphone-5s-first-impressions-... .
'every so often' seems a bit casual, for a payment [1,2] [1] From the citation: "Passcodes and passwords aren’t completely eliminated by Touch ID, then, but they almost certainly will be later on." [2] The glass screen will have your fingerprint on it, somewhere. That can be CSI'd by anyone who finds it. Anyone serious enough to do that (and its not much) can start escalating.
Re: Chaos Computer Club breaks Apple TouchID
#263Earlier quoted context omitted.
Reportedly when making purchases it "will still prompt you for your password every so often to 'renew Touch ID purchases.'" Source: http://www.cultofmac.com/246572/iphone-5s-first-impressions-... .
'every so often' seems a bit casual, for a payment [1,2] [1] From the citation: "Passcodes and passwords aren’t completely eliminated by Touch ID, then, but they almost certainly will be later on." [2] The glass screen will have your fingerprint on it, somewhere. That can be CSI'd by anyone who finds it. Anyone serious enough to do that (and its not much) can start escalating.
Re: Chaos Computer Club breaks Apple TouchID
#264Earlier quoted context omitted.
> Touch ID is better than nothing... but not by much You can't be serious. A completely unlocked phone that anybody can trivially access with a swipe.. vs. a scanner that you'd have to lift and reconstruct someone's fingerprint to bypass. That is definitely a significant improvement.
> That is definitely a significant improvement. Sure is a significant improvement for some people at least. http://t.co/EK3sdeloUX
Re: Chaos Computer Club breaks Apple TouchID
#265Earlier quoted context omitted.
"Only if you're typing in pass codes to the lock screen, which isn't how its done. An attacker would instead image the flash, grab the Dkey from effaceable storage, and decrypt the filesystem. Indeed this is exactly how professional iOS forensic analysis kits work. This will get you access to SMS, photos, and anything else that doesn't fall under Data Protection." Yep, as I suspected, you haven't done this ;) Please…
I didn't say "simple." I said "trivial" :) Nope, I've never done this live. For this I'm reliant upon what I've read. Feel free to tell me what's wrong. Stating how it works, or pointing the way to an accurate source, is infinitely more helpful than saying "you're wrong", even if it might feel satisfying. Here's my understanding of how the initial loading works. BootROM uses a series of RSA validity checks on the cha…
Even with the multi-thousand dollar forensics kits, you cannot even begin a brute force PIN attack on any bootrom for any iphone or ipad still on sale. The last devices it worked on was iphone 4 (not 4S) and ipad 2.
Re: Chaos Computer Club breaks Apple TouchID
#266- fingerprint authentication will be seen as more casual and mainstream than it was before [1]
- people will still leave fingerprints everywhere, including around and on the fingerprint sensors
- once a high resolution image of a fingerprint is done, it can be re-used for literaly a lifetime (imagine keeping track of someone for years and use his/her fingerprints anytime it's needed)
- if enough applications rely on fingeprint authentication, exchanging fingerprint databases might become lucrative enough
From this point of view, seeing TouchID as just a cute way adding some security to a phone is too candid I think. It will have an immediate positive effect for casual phone locking, but would bring much worse effects down the line.
Optimisticly no one would rely on fingerprints alone to authenticate users for anything important. But the definition of what's important is blurry, and there is so many situations now where weak passwords are used, but it would be so tempting to switch to fingerprints (door unlock for instance...).
[1] laptops had finger unlock features for years now, but it never really made it to the wild masses I think. Fujitsu phones had a fingerprint reader too, but again, I don't remember other makers picking up the feature.
Re: Chaos Computer Club breaks Apple TouchID
#267Considering that people generally don't wear gloves when they use their phones this is like having a picture of your key on your door. Combine that with what we know you can do with pictures of keys[1] and yes it's obviously not a very good idea. [1]: https://news.ycombinator.com/item?id=6167246
no no no no no. This is not being done by lifting an existing print from the existing device. They're taking a photo of the authorised FINGER and using that to create their fake finger... I don't see how this could be considered a significant issue unless you are going to steal someones phone AND somehow get a still 2400 dpi photo of the surface of their finger
Re: Chaos Computer Club breaks Apple TouchID
#268YOUR FINGER PRINTS ARE ON THE PHONE...
Don't lose it !! =D
Re: Chaos Computer Club breaks Apple TouchID
#269Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…
One might argue that Touch ID is too strong to be used where there was no security before. In an arms race with thefts and hackers, leaping too far forwards might not be the best option in the long term.
Re: Chaos Computer Club breaks Apple TouchID
#270Honestly, TouchID is better than what we have today; a 4 digit useless passcode. If somebody has to take a photo of my fingerprint off a glass surface to gain access to my phone, so be it.
4 digit pin? I use a 12+ character alphanumeric password on Android.