Earlier quoted context omitted.
Reportedly when making purchases it "will still prompt you for your password every so often to 'renew Touch ID purchases.'" Source: http://www.cultofmac.com/246572/iphone-5s-first-impressions-... .
'every so often' seems a bit casual, for a payment [1,2] [1] From the citation: "Passcodes and passwords aren’t completely eliminated by Touch ID, then, but they almost certainly will be later on." [2] The glass screen will have your fingerprint on it, somewhere. That can be CSI'd by anyone who finds it. Anyone serious enough to do that (and its not much) can start escalating.
Chaos Computer Club breaks Apple TouchID
321–330 of 458 posts
Re: Chaos Computer Club breaks Apple TouchID
#322Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…
This seems correct. Apple's moved the bar to breaking into those phones from having the phone and a 4 digit or no passcode to having: -- the phone -- a 2400 dpi resolution image of the correct fingerprint -- a 1200 dpi laser printer & transparent paper -- pink latex milk or white woodglue -- a non-trivial amount of time
Re: Chaos Computer Club breaks Apple TouchID
#323Re: Chaos Computer Club breaks Apple TouchID
#324Earlier quoted context omitted.
What's the opinion? Apple said you can use this to replace your password. No one had an iTunes Store account without a password before, so this would 100% be replacing a password.
>> "Pretty good security would be to require both the fingerprint and a PIN (for unlocking the phone, at that stage a fingerprint is fine for authenticating iTunes' digital purchases)." I believe that's the opinion being referred to.
Re: Chaos Computer Club breaks Apple TouchID
#325Earlier quoted context omitted.
'every so often' seems a bit casual, for a payment [1,2] [1] From the citation: "Passcodes and passwords aren’t completely eliminated by Touch ID, then, but they almost certainly will be later on." [2] The glass screen will have your fingerprint on it, somewhere. That can be CSI'd by anyone who finds it. Anyone serious enough to do that (and its not much) can start escalating.
Since they'd reverse the charges anyway if it wasn't you who made them, what exactly is the problem here?
From what I've found online, chip-PIN does indeed reduce fraud, but when fraud does happen, it becomes extraordinarily difficult for the cardholder to get a refund from the bank.
I could see fingerprint scanning going the same way -- with vendors saying "what do you mean you aren't the one who made this purchase? The device was unlocked with your unique fingerprint!"
Re: Chaos Computer Club breaks Apple TouchID
#326Earlier quoted context omitted.
From what I've read, Apple's sensor is still more accurate than competing sensors. It works much faster, and is better at recognizing your finger in various positions. It's also faster/easier than a 4 digit passcode. Let's be fair. Apple said it was easy to use and improved security (compared to the previous iPhone). They didn't say it was designed to the standards needed to protect DOD secrets. This seems like CCC i…
"They didn't say it was designed to the standards needed to protect DOD secrets." I'm sorry, but this is so much backpedaling. Do i really need to start pulling out comments from the last discussion where people were quoting Apple's press conference about how revolutionary and secure this was?
Re: Chaos Computer Club breaks Apple TouchID
#327Earlier quoted context omitted.
Since they'd reverse the charges anyway if it wasn't you who made them, what exactly is the problem here?
This is where things start to get tricky. I've read up on "chip and PIN" in Europe, where purchasers have to insert their cards into a reader and enter the numeric code that is stored on the card. From what I've found online, chip-PIN does indeed reduce fraud, but when fraud does happen, it becomes extraordinarily difficult for the cardholder to get a refund from the bank. I could see fingerprint scanning going the s…
Re: Chaos Computer Club breaks Apple TouchID
#328So what is a realistic way to clandestinely grab a print?
Re: Chaos Computer Club breaks Apple TouchID
#329Earlier quoted context omitted.
> The goal is to get more consumers to move from zero security to pretty good security. One might argue that Touch ID is too strong to be used where there was no security before. In an arms race with thefts and hackers, leaping too far forwards might not be the best option in the long term.
Thefts are not limited by passwords, the thief will just reset the phone.
Re: Chaos Computer Club breaks Apple TouchID
#330Earlier quoted context omitted.
Since they'd reverse the charges anyway if it wasn't you who made them, what exactly is the problem here?
This is where things start to get tricky. I've read up on "chip and PIN" in Europe, where purchasers have to insert their cards into a reader and enter the numeric code that is stored on the card. From what I've found online, chip-PIN does indeed reduce fraud, but when fraud does happen, it becomes extraordinarily difficult for the cardholder to get a refund from the bank. I could see fingerprint scanning going the s…
I live in Europe, and twice in the last two years or so my card details have been compromised, and both times my bank has rang me to notify me of suspicious transactions before I'd even noticed. It depends on the bank (and the country most likely) with regards to getting a refund. I got refunds no problem, but I've heard people having problems in the UK. The fraud happened online (not sure how, I'm reasonably tech savvy and careful with my card details).