Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

281–290 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#281

Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…

Here's Apple's main marketing text on the subject: > Put your finger on the Home button, and just like that your iPhone unlocks. It’s a convenient and highly secure way to access your phone. Your fingerprint can also approve purchases from iTunes Store, the App Store, and the iBooks Store, so you don’t have to enter your password. It is definitely intended to replace passwords. Pretty good security would be to requir…

I think it's more than adequate security for App Store purchases.

My debit card, for example, has "paywave" short range payment support. So anybody who has my card can go around making small purchases, no PIN, no signature needed. I'm fine with this because the convenience far outweighs the security concern.

With the iPhone an attacker who replicates your fingerprint can make purchases to your iTunes account using your phone. They can't purchase to a different account, they can't purchase to a different device. In that sense, requiring a valid fingerprint is more than secure enough — even if faked it's not going to do much damage.

Creating a fake print that can fool the scanner is so much harder than stealing someone's debit/credit card. It's also so much less damaging to the victim (making purchases on their iTunes account vs. making any arbitrary purchase).

I think the balance between security and convenience for this technology is more than reasonable.

Re: Chaos Computer Club breaks Apple TouchID

#282

Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…

I agree. This is just like face unlock on Android. A nice feature, but not bulletproof.

Re: Chaos Computer Club breaks Apple TouchID

#283
post #276
post #24

I think they're missing the point. The passcode on an iPhone defends against other people in your environment - family members, coworkers, roommates - getting your information opportunistically. It doesn't defend against hackers, the government, or even slightly savvy thieves. Also, if a fingerprint sensor is significantly easier to use, and in practice will deter a class of privacy violations, it could increase over…

that's actually kind of ironic... ...the people closest to you in your environment ( kids, parents, spouse, boss, co-workers) are the ones who can most easily obtain your fingerprints...

And are probably least easily able to capture a high resolution image and reproduce a 2400 dpi heavy-ink image that is then used to create mould of your print.

Re: Chaos Computer Club breaks Apple TouchID

#284

So the big question is, how hard is it to get at 2400 DPI finger print? They don't show if they can scan the finger print off the phone. I would imagine that it could be quite tricky to get that level of resolution. I would like to see a complete hack purely based on a finger print on the phone.

How hard is it to get at 2400 DPI finger print?

Left arrow key? Coffee cup? Left button of a mouse? Car door handle?

Re: Chaos Computer Club breaks Apple TouchID

#286

Earlier quoted context omitted.

Baseless FUD is OK as long as Linux ain't the target, right?

Where the fuck did that come from? It is neither baseless or FUD. That fingerprint will be sent over the wire at some point and the NSA will gladly pick it up. How you think otherwise is beyond me. What operating system I prefer really has nothing to do with it, even if it is linux. Posted from my iPhone, android, third mac mini, 2nd mac air, or first thinkpad who the fuck knows (or cares? oh you obviously)

From Apple's site [1]:

> Touch ID does not store any images of your fingerprint. It stores only a mathematical representation of your fingerprint.

> The Secure Enclave is walled off from the rest of A7 and as well as the rest of iOS. Therefore, your fingerprint data is never accessed by iOS or other apps, never stored on Apple servers, and never backed up to iCloud or anywhere else. Only Touch ID uses it and it can't be used to match against other fingerprint databases.

[1] http://support.apple.com/kb/HT5949?viewlocale=en_US

Re: Chaos Computer Club breaks Apple TouchID

#287

Earlier quoted context omitted.

no no no no no. This is not being done by lifting an existing print from the existing device. They're taking a photo of the authorised FINGER and using that to create their fake finger... I don't see how this could be considered a significant issue unless you are going to steal someones phone AND somehow get a still 2400 dpi photo of the surface of their finger

You are incorrect. Second sentence of the article: "A fingerprint of the phone user, photographed from a glass surface, was enough to create a fake finger that could unlock an iPhone 5s secured with TouchID."

Which glass surface? The oleophobic glass on the iPhone itself?

If the print was copied directly from one of the phone surfaces, you'd think that the CCC would want to include that little tidbit.

Re: Chaos Computer Club breaks Apple TouchID

#288

Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…

I took a security class where, amongst other things, we learned how to pick locks. After we learned how to do so with provided equipment, the instructor said "So since these locks are insecure, should I have them in my home? Yes, because if a motivated intruder wanted to come into my home, I still have windows."

Re: Chaos Computer Club breaks Apple TouchID

#289
post #9

Wasn't Gruber getting awfully excited about how amazing and revolutionary Apple's finger print sensor was? Will he be claim chowdering?

I think it is a very innovative step by Apple. It's going to convert a lot of people who never lock their devices into people who use quite a secure and easy-to-use method to lock their devices.

Just because it can be hacked does not mean it is a bad method to use.

Re: Chaos Computer Club breaks Apple TouchID

#290

Earlier quoted context omitted.

Rare is the phone without the owner's fingerprints stored all over it.

Nobody has been able to use those low quality fingerprints to defeat TouchID.

I wouldn't count on that. See https://twitter.com/dotMudge/status/381900643415240704
Post reply on HN