Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

301–310 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#301
post #63
post #9

Wasn't Gruber getting awfully excited about how amazing and revolutionary Apple's finger print sensor was? Will he be claim chowdering?

From what I've read, Apple's sensor is still more accurate than competing sensors. It works much faster, and is better at recognizing your finger in various positions. It's also faster/easier than a 4 digit passcode. Let's be fair. Apple said it was easy to use and improved security (compared to the previous iPhone). They didn't say it was designed to the standards needed to protect DOD secrets. This seems like CCC i…

"They didn't say it was designed to the standards needed to protect DOD secrets."

I'm sorry, but this is so much backpedaling. Do i really need to start pulling out comments from the last discussion where people were quoting Apple's press conference about how revolutionary and secure this was?

Re: Chaos Computer Club breaks Apple TouchID

#302
post #269

Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…

> The goal is to get more consumers to move from zero security to pretty good security. One might argue that Touch ID is too strong to be used where there was no security before. In an arms race with thefts and hackers, leaping too far forwards might not be the best option in the long term.

Thefts are not limited by passwords, the thief will just reset the phone.

Re: Chaos Computer Club breaks Apple TouchID

#303

Earlier quoted context omitted.

Jailbreak is enough... When it exists. And for now it doesn't.

taking past trends into consideration, it looks like you're betting on the wrong horse, here. it will exist.

Past trends do indicate that. However, the very recent past indicates that Apple is getting progressively better at foiling jailbreaks. It's taking greenpois0n and those folks longer and longer to crack each successive version of iOS. Took a long time for there to be an untethered jailbreak of iOS 6 and the latest rev of iOS 6 wasn't cracked til about two weeks ago. There was no jailbreak of any kind on the iPhone 5 for several months after its release, which is a long time considering that the time between device generations is one year.

Re: Chaos Computer Club breaks Apple TouchID

#304

Earlier quoted context omitted.

It's also not stored on the device. Hashes, not fingerprints, are stored. You need the fingerprints themselves to fake out the hardware.

Rare is the phone without the owner's fingerprints stored all over it.

Not true at all. There are quite a large number of cases out there that would be hard to lift fingerprints from. If the owner has this sort of case, and if the owner has cleaned the screen recently or just had the phone pocketed, thus wiping the screen off rather well...I think there are a large number of phones from which you would get no prints.

Re: Chaos Computer Club breaks Apple TouchID

#305
post #169

Earlier quoted context omitted.

Touch ID is not "pretty good security" it's not even "good security" it's simply very bad security. Touch ID is better than nothing and that people use Touch ID instead of nothing is better than the current state but not by much and this definitely isn't a huge achievement. Which is really the biggest issue with Touch ID, it's advertised as such and people believe it.

Touch ID is competing against pins chosen from a universe of 10,000. This isn't great security, but it's appropriate security for unlocking a device you already must have physical access to.

Actually doesn't that highlight one of the biggest flaws with this, in that your finger prints will already be all over the device? Lift the device, get the authorisation token for free. At least with a password you also need to either crack it or discover it from some other means.

Re: Chaos Computer Club breaks Apple TouchID

#306
post #238

Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…

This seems correct. Apple's moved the bar to breaking into those phones from having the phone and a 4 digit or no passcode to having: -- the phone -- a 2400 dpi resolution image of the correct fingerprint -- a 1200 dpi laser printer & transparent paper -- pink latex milk or white woodglue -- a non-trivial amount of time

The problem here is your implying getting past the 4 digit code is substantially easier then cloning a finger print.

The code is in someone's head, or you have to deconvolute it from screen smudges. Your fingerprints are literally everywhere you go.

Re: Chaos Computer Club breaks Apple TouchID

#307

Earlier quoted context omitted.

> That would work in the sort of Hollywood movie where the government has everyone's DNA on file. You don't have to have "everyone's DNA on file". It's actually pretty trivial even for your neighbor or whoever to get your DNA. As for the police falsifying evidence, there's a wikipedia-long history of cases, in Europe, Latin America, Asia, etc. Especially in politically charged times, like the sixties and seventies. H…

> You don't have to have "everyone's DNA on file". It's actually pretty trivial even for your neighbor or whoever to get your DNA. Sorry, I wasn't clear. I can dump a gallon of your blood and semen onto a dead guy in an alley, but how would the government trace that blood and semen back to you?

They don't have to necessarily trace it back to me, as long as they can't trace it back to you.

Re: Chaos Computer Club breaks Apple TouchID

#308
post #134

Earlier quoted context omitted.

Considerably harder? From the article: "In reality, Apple's sensor has just a higher resolution compared to the sensors so far. So we only needed to ramp up the resolution of our fake",

Difficulty of lifting a good print is probably proportional to the resolution needed. Ie, you need a higher quality print to get a higher resolution image to contain additional information.

I'm actually pretty skeptical this is the case. Fingerprint data is noisy - it has to tolerate a high degree of error. I suspect the problem is actually that you need to smooth it out appropriately to make the sensor not get tripped up by non-biological noise.

I'd be really curious to see what you could do with a high-resolution smartphone camera and a little image processing.

Re: Chaos Computer Club breaks Apple TouchID

#309

Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…

>Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security.

Agreed. Complaining about this hack would be like people saying locks are "hackable" if you steal someones key and make a copy. There's always a way around any system, if a criminal is dedicated enough to get past it.

Re: Chaos Computer Club breaks Apple TouchID

#310

Earlier quoted context omitted.

no no no no no. This is not being done by lifting an existing print from the existing device. They're taking a photo of the authorised FINGER and using that to create their fake finger... I don't see how this could be considered a significant issue unless you are going to steal someones phone AND somehow get a still 2400 dpi photo of the surface of their finger

You are incorrect. Second sentence of the article: "A fingerprint of the phone user, photographed from a glass surface, was enough to create a fake finger that could unlock an iPhone 5s secured with TouchID."

A meticulously placed fingerprint was made on a clean and polished glass surface as if it was being taken by the police. Nothing like a normal fingerprint left by accident.
Post reply on HN