Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

321–330 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#321
post #254

Earlier quoted context omitted.

Reportedly when making purchases it "will still prompt you for your password every so often to 'renew Touch ID purchases.'" Source: http://www.cultofmac.com/246572/iphone-5s-first-impressions-... .

'every so often' seems a bit casual, for a payment [1,2] [1] From the citation: "Passcodes and passwords aren’t completely eliminated by Touch ID, then, but they almost certainly will be later on." [2] The glass screen will have your fingerprint on it, somewhere. That can be CSI'd by anyone who finds it. Anyone serious enough to do that (and its not much) can start escalating.

The primary use case here is keeping kids from buying apps or in-app purchases when their parents lend them the phone to play games. A casual solution is perfectly acceptable. If someone is going to go through the trouble of stealing my phone and cloning my fingerprint I'm guessing they would want more than purchasing music or apps under my iTunes account.

Re: Chaos Computer Club breaks Apple TouchID

#322
post #238

Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…

This seems correct. Apple's moved the bar to breaking into those phones from having the phone and a 4 digit or no passcode to having: -- the phone -- a 2400 dpi resolution image of the correct fingerprint -- a 1200 dpi laser printer & transparent paper -- pink latex milk or white woodglue -- a non-trivial amount of time

and also the fingerprint.

Re: Chaos Computer Club breaks Apple TouchID

#323

Earlier quoted context omitted.

Jailbreak is enough... When it exists. And for now it doesn't.

taking past trends into consideration, it looks like you're betting on the wrong horse, here. it will exist.

Judging by latest Apple TV jailbreak status, it still might never appear.

Re: Chaos Computer Club breaks Apple TouchID

#324

Earlier quoted context omitted.

What's the opinion? Apple said you can use this to replace your password. No one had an iTunes Store account without a password before, so this would 100% be replacing a password.

>> "Pretty good security would be to require both the fingerprint and a PIN (for unlocking the phone, at that stage a fingerprint is fine for authenticating iTunes' digital purchases)." I believe that's the opinion being referred to.

Yes, thanks.

Re: Chaos Computer Club breaks Apple TouchID

#325
post #254

Earlier quoted context omitted.

'every so often' seems a bit casual, for a payment [1,2] [1] From the citation: "Passcodes and passwords aren’t completely eliminated by Touch ID, then, but they almost certainly will be later on." [2] The glass screen will have your fingerprint on it, somewhere. That can be CSI'd by anyone who finds it. Anyone serious enough to do that (and its not much) can start escalating.

Since they'd reverse the charges anyway if it wasn't you who made them, what exactly is the problem here?

This is where things start to get tricky. I've read up on "chip and PIN" in Europe, where purchasers have to insert their cards into a reader and enter the numeric code that is stored on the card.

From what I've found online, chip-PIN does indeed reduce fraud, but when fraud does happen, it becomes extraordinarily difficult for the cardholder to get a refund from the bank.

I could see fingerprint scanning going the same way -- with vendors saying "what do you mean you aren't the one who made this purchase? The device was unlocked with your unique fingerprint!"

Re: Chaos Computer Club breaks Apple TouchID

#326
post #63

Earlier quoted context omitted.

From what I've read, Apple's sensor is still more accurate than competing sensors. It works much faster, and is better at recognizing your finger in various positions. It's also faster/easier than a 4 digit passcode. Let's be fair. Apple said it was easy to use and improved security (compared to the previous iPhone). They didn't say it was designed to the standards needed to protect DOD secrets. This seems like CCC i…

"They didn't say it was designed to the standards needed to protect DOD secrets." I'm sorry, but this is so much backpedaling. Do i really need to start pulling out comments from the last discussion where people were quoting Apple's press conference about how revolutionary and secure this was?

People will here what they want (you included), i'm not entirely sure what you're getting at though.

Re: Chaos Computer Club breaks Apple TouchID

#327

Earlier quoted context omitted.

Since they'd reverse the charges anyway if it wasn't you who made them, what exactly is the problem here?

This is where things start to get tricky. I've read up on "chip and PIN" in Europe, where purchasers have to insert their cards into a reader and enter the numeric code that is stored on the card. From what I've found online, chip-PIN does indeed reduce fraud, but when fraud does happen, it becomes extraordinarily difficult for the cardholder to get a refund from the bank. I could see fingerprint scanning going the s…

So you're going with a slippery slope argument? This thing could cause that thing that could cause that bad thing, so this thing is bad? I suppose that is something that could happen in the future. It's not a likely problem to complain about with this particular implementation.

Re: Chaos Computer Club breaks Apple TouchID

#328
Despite all the claims of how insecure this is, I've just checked a bunch of my stuff. I cannot find a single clear print. There are a few smudged prints on my laptop and coffee cup. My phone is just smudges all over.

So what is a realistic way to clandestinely grab a print?

Re: Chaos Computer Club breaks Apple TouchID

#329
post #269

Earlier quoted context omitted.

> The goal is to get more consumers to move from zero security to pretty good security. One might argue that Touch ID is too strong to be used where there was no security before. In an arms race with thefts and hackers, leaping too far forwards might not be the best option in the long term.

Thefts are not limited by passwords, the thief will just reset the phone.

I don't know, reproducing a fingerprint is relatively easy to understand (just scan and print), while cracking a password can be more exotic to 'traditional' thieves. When today they'd just wipe the phone, tomorrow they make take the extra step of pulling out the SIM card and unlock with the fingerprint, and sell the data as well.

Re: Chaos Computer Club breaks Apple TouchID

#330

Earlier quoted context omitted.

Since they'd reverse the charges anyway if it wasn't you who made them, what exactly is the problem here?

This is where things start to get tricky. I've read up on "chip and PIN" in Europe, where purchasers have to insert their cards into a reader and enter the numeric code that is stored on the card. From what I've found online, chip-PIN does indeed reduce fraud, but when fraud does happen, it becomes extraordinarily difficult for the cardholder to get a refund from the bank. I could see fingerprint scanning going the s…

> From what I've found online, chip-PIN does indeed reduce fraud, but when fraud does happen, it becomes extraordinarily difficult for the cardholder to get a refund from the bank.

I live in Europe, and twice in the last two years or so my card details have been compromised, and both times my bank has rang me to notify me of suspicious transactions before I'd even noticed. It depends on the bank (and the country most likely) with regards to getting a refund. I got refunds no problem, but I've heard people having problems in the UK. The fraud happened online (not sure how, I'm reasonably tech savvy and careful with my card details).

Post reply on HN