Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

311–320 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#311

Earlier quoted context omitted.

> Pretty good security would be to require both the fingerprint and a PIN You're missing the point. Right now lots of people have no password at all. Touch ID is a big improvement over having no password.

IT managers will either be thanking or cursing the CCC at this point...

I understand that iPhone (and iPad) allow IT to enforce setting of password (1). I think from the security perspective, IT is more worried about ability to remotely manage the device (like remote wipes in case of loss etc).

1. http://images.apple.com/iphone/business/docs/iOS_6_Security_...

Edit: I realized that the link is for iOS 6 - though I wouldn't expect them to reduce business IT functionality, not sure if these options are still in iOS 7.

Re: Chaos Computer Club breaks Apple TouchID

#313
post #306
post #238

Earlier quoted context omitted.

This seems correct. Apple's moved the bar to breaking into those phones from having the phone and a 4 digit or no passcode to having: -- the phone -- a 2400 dpi resolution image of the correct fingerprint -- a 1200 dpi laser printer & transparent paper -- pink latex milk or white woodglue -- a non-trivial amount of time

The problem here is your implying getting past the 4 digit code is substantially easier then cloning a finger print. The code is in someone's head, or you have to deconvolute it from screen smudges. Your fingerprints are literally everywhere you go.

I think it would be pretty easy to get many people's phone password -- just by being in the right place when they unlock it, and watching closely. Most people I know don't cover up their phone at all when they enter it, even in public.

So you don't need to get "in someone's head". You just need a good view of them using it.

Granted, getting an iTunes Store password by just watching would be a lot harder. But compared to the 4-digit lock screen pw (or even the Android shape pw) TouchID seems a bit more secure, at least to me.

Re: Chaos Computer Club breaks Apple TouchID

#315
First off I want to say I agree with most of the people here that Touch ID was not meant to be in breakable but rather an easy to use system that vastly improved users security over 4 digit PINs or no PIN.

That said, hypothetically, let's say I get arrested and the police take my phone. My phone has my fingerprints all over it. What is to stop them, legally, from using my prints on the phone to unlock my device?

I say this not to spark an argument but as a real question, I bought an iPhone 5S and I really am interested to know if any law would protect my phone if it was taken in such a situation?

Re: Chaos Computer Club breaks Apple TouchID

#316

Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…

What worries me the most is that biometrics can be used to authorize payments, and for anyone that has crafty teenage (or younger) kinds this might sounds a bit risky. Getting access to your parents fingerprint is easy while getting access to their password is much harder.

Re: Chaos Computer Club breaks Apple TouchID

#317
post #308
post #134

Earlier quoted context omitted.

Difficulty of lifting a good print is probably proportional to the resolution needed. Ie, you need a higher quality print to get a higher resolution image to contain additional information.

I'm actually pretty skeptical this is the case. Fingerprint data is noisy - it has to tolerate a high degree of error. I suspect the problem is actually that you need to smooth it out appropriately to make the sensor not get tripped up by non-biological noise. I'd be really curious to see what you could do with a high-resolution smartphone camera and a little image processing.

I am guessing I can beat it with a good pen. As you say it has to be tolerant. If you have a little grunge on your finger, or a cut, or get a tan or there is grunge on the sensor it still has to work.

Also, there are a lot fewer fingerprints than the world has been lead to believe. Especially since we each have 10 to try, since the phone only checks 1.

Re: Chaos Computer Club breaks Apple TouchID

#318

We see him register his index finger. Then he places his supposedly artificial index finger on his middle finger, and the phone unlocks. Since it uses RF and goes beyond the outer layer of skin, how do we know that the middle finger wasn't already registered?

Because it's the CCC, and they're very reputable.

Re: Chaos Computer Club breaks Apple TouchID

#320

Earlier quoted context omitted.

You are incorrect. Second sentence of the article: "A fingerprint of the phone user, photographed from a glass surface, was enough to create a fake finger that could unlock an iPhone 5s secured with TouchID."

Which glass surface? The oleophobic glass on the iPhone itself? If the print was copied directly from one of the phone surfaces, you'd think that the CCC would want to include that little tidbit.

>> Which glass surface? The oleophobic glass on the iPhone itself?

That brings up another interesting point -- I wonder how many people are going to put screen protectors on their 5S's that are not oleophobic.

Post reply on HN