Earlier quoted context omitted.
Since they'd reverse the charges anyway if it wasn't you who made them, what exactly is the problem here?
This is where things start to get tricky. I've read up on "chip and PIN" in Europe, where purchasers have to insert their cards into a reader and enter the numeric code that is stored on the card. From what I've found online, chip-PIN does indeed reduce fraud, but when fraud does happen, it becomes extraordinarily difficult for the cardholder to get a refund from the bank. I could see fingerprint scanning going the s…
Chaos Computer Club breaks Apple TouchID
331–340 of 458 posts
Re: Chaos Computer Club breaks Apple TouchID
#332Earlier quoted context omitted.
Since they'd reverse the charges anyway if it wasn't you who made them, what exactly is the problem here?
This is where things start to get tricky. I've read up on "chip and PIN" in Europe, where purchasers have to insert their cards into a reader and enter the numeric code that is stored on the card. From what I've found online, chip-PIN does indeed reduce fraud, but when fraud does happen, it becomes extraordinarily difficult for the cardholder to get a refund from the bank. I could see fingerprint scanning going the s…
Re: Chaos Computer Club breaks Apple TouchID
#333Earlier quoted context omitted.
I don't think I've seen anyone parry an appeal to authority with an ad hominem lately. Good one.
Citing the Google Chrome Security team regarding security is the exact opposite of the appeal to authority fallacy. It's an appropriate expert for the context.
Re: Chaos Computer Club breaks Apple TouchID
#334Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…
> fingerprint biometrics is unsuitable as access control method and should be avoided.
What happens when the next set of hackers figure out how to remotely access and extract the fingerprints (hashed, secured, whatever) stored on the iPhone itself?
Re: Chaos Computer Club breaks Apple TouchID
#335Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…
Except, there is a larger point that CCC is making: > fingerprint biometrics is unsuitable as access control method and should be avoided. What happens when the next set of hackers figure out how to remotely access and extract the fingerprints (hashed, secured, whatever) stored on the iPhone itself?
The fingerprint information stored in the 'secure enclave' of the A7 is a combination of the data related to the fingerprint combined with unique information for that specific device. So even if the data could be extracted, using it for any purpose other than unlocking that specific phone would be impossible.
Re: Chaos Computer Club breaks Apple TouchID
#336Earlier quoted context omitted.
Except, there is a larger point that CCC is making: > fingerprint biometrics is unsuitable as access control method and should be avoided. What happens when the next set of hackers figure out how to remotely access and extract the fingerprints (hashed, secured, whatever) stored on the iPhone itself?
I don't really think it is relevant. The iTunes authorisation for example wouldn't be sent the fingerprint information, it would be sent the response 'yes the person passed the test'. The fingerprint information stored in the 'secure enclave' of the A7 is a combination of the data related to the fingerprint combined with unique information for that specific device. So even if the data could be extracted, using it for…
No, it wouldn't send that response at all. That's called a client-side security control, and I'm sure you can think of why that's out of the question in any system.
Re: Chaos Computer Club breaks Apple TouchID
#337Earlier quoted context omitted.
People actually do other actions on their phone after unlocking it. If somebody swipes on their homescreen, browse the web, etc, the trail would not be just the unlock pattern. The exploit you're talking about may work if you get hold of the phone right after the user unlocks it since the trail only has the pattern.
True enough, there is other "noise" on the phone, in the form of point-like finger prints, and even other trails. But you're imagining a blank phone, where you have to try and discern one trail from another. Now turn the phone on, and the unlock background appears. Which trails intersect all of the dots of the unlock background? It's much easier that you imagine. I've been using my phone as I normally do throughout t…
Re: Chaos Computer Club breaks Apple TouchID
#338Earlier quoted context omitted.
Thefts are not limited by passwords, the thief will just reset the phone.
I don't know, reproducing a fingerprint is relatively easy to understand (just scan and print), while cracking a password can be more exotic to 'traditional' thieves. When today they'd just wipe the phone, tomorrow they make take the extra step of pulling out the SIM card and unlock with the fingerprint, and sell the data as well.
Even if your phone was unlocked, they probably wouldn't bother more than a cursory glance. They have more phones to steal than to bother with is on some random person's phone. When the data is important, the theft will be more targeted.
Re: Chaos Computer Club breaks Apple TouchID
#339Earlier quoted context omitted.
This is where things start to get tricky. I've read up on "chip and PIN" in Europe, where purchasers have to insert their cards into a reader and enter the numeric code that is stored on the card. From what I've found online, chip-PIN does indeed reduce fraud, but when fraud does happen, it becomes extraordinarily difficult for the cardholder to get a refund from the bank. I could see fingerprint scanning going the s…
So you're going with a slippery slope argument? This thing could cause that thing that could cause that bad thing, so this thing is bad? I suppose that is something that could happen in the future. It's not a likely problem to complain about with this particular implementation.
You're baselessly asserting your position, though.
If you write your pin on your ATM card, they will not refund you. That is policy and they ask everytime you lose your card. The bank views this as lack of due care. Likewise, if you leave copies of your fingerprints on your payment device, they could argue that you are likewise acting with un-reasonable care.
Now that this has been (so easily?) spoofed, is it reasonable to believe it is secure? That is a valid concern. Unlike a pin, you cannot reset a fingerprint security mechanism. So when it is compromised, it is over. So, the result is messy in that it puts you in a problem using today's standard practices, but at the same time, the standard practice "defense" is not applicable, and lacks an obvious alternative.
This is not a strawman, its a legitimate edge case.
Re: Chaos Computer Club breaks Apple TouchID
#340Earlier quoted context omitted.
Giving Apple a break? Just another layer of security? That's not how Apple describes it: http://support.apple.com/kb/HT5949?viewlocale=en_US And selling a stolen iPhone on eBay does not need a password or a fingerprint, a jailbreak is enough …
Only an idiot would buy a jailbroken phone without a clean ESN on it. Those who do, know what they are getting. And you're forgetting Activation Lock, which a jailbreak will not defeat.