Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

351–360 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#351

If we've learned anything over the past few months, it is that security is an illusion when it comes to Google, Apple and Facebook. The fingerprint scanner is not intended to protect your personal data from being accessed by nefarious cyber-spooks or crackers. The $5 dollar wrench technique is fairly effective in bypassing such security anyway. The fingerprint scanner is there so that when your phone is nicked by a m…

> It's _not_ the panacea to all our security woes, and they have never claimed it was.

But they've never said it wasn't, either. It's important that everyone is in the clear about how secure TouchID is. I'm going to use it anyway, but the other decision is how much personal data I want to store on my phone.

Re: Chaos Computer Club breaks Apple TouchID

#352

Earlier quoted context omitted.

I don't want to jump in on the "how secure is my phone discussion", I just wanted to point out that with all the revelations and concerns regarding privacy, a single company having fingerprints for some significant portion of North America is nothing to be taken lightly. That said, I sincerely doubt this is the case. I imagine the phone acts as a proxy for the authentication, validating the fingerprint then sending s…

We don't really know exactly what it stores, but they claim it's a hash of the fingerprint. That is not the same as the actual fingerprint at all, and it should be unusable outside the iPhone 5S ecosystem. I would imagine this hash, is also what they send to the servers to authenticate, but time will tell.

If they send a hash to servers, that still has privacy implications. Apple could build a searchable database of those hashes, and the government could issue subpoenas to search that database for particular fingerprints. Maybe that's not such a bad thing, because it could help to solve crimes, but it's worth thinking about.

Re: Chaos Computer Club breaks Apple TouchID

#353
post #238

Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…

This seems correct. Apple's moved the bar to breaking into those phones from having the phone and a 4 digit or no passcode to having: -- the phone -- a 2400 dpi resolution image of the correct fingerprint -- a 1200 dpi laser printer & transparent paper -- pink latex milk or white woodglue -- a non-trivial amount of time

-- a lot of luck, because after 5 failed attempts, you must enter your passcode

Re: Chaos Computer Club breaks Apple TouchID

#354

Earlier quoted context omitted.

Baseless FUD is OK as long as Linux ain't the target, right?

Where the fuck did that come from? It is neither baseless or FUD. That fingerprint will be sent over the wire at some point and the NSA will gladly pick it up. How you think otherwise is beyond me. What operating system I prefer really has nothing to do with it, even if it is linux. Posted from my iPhone, android, third mac mini, 2nd mac air, or first thinkpad who the fuck knows (or cares? oh you obviously)

I would be very surprised if the fingerprint is sent over the wire. Instead, I would expect the "secure enclave" to validate the fingerprint, and then emit a time-limited certificate of some sort to authenticate with servers. The fingerprint information - or derived information such as hashes - never needs to leave the phone.

Re: Chaos Computer Club breaks Apple TouchID

#356

So the big question is, how hard is it to get at 2400 DPI finger print? They don't show if they can scan the finger print off the phone. I would imagine that it could be quite tricky to get that level of resolution. I would like to see a complete hack purely based on a finger print on the phone.

How hard is it to get at 2400 DPI finger print? Left arrow key? Coffee cup? Left button of a mouse? Car door handle?

Well... yeah, but there is quite a lot of smearing.

Will the quality of the finger print you can extract that way using whatever means you have be of high enough quality?

It is not obvious to me that you'll be able to get something that is 2400 DPI quality.

Re: Chaos Computer Club breaks Apple TouchID

#358

Earlier quoted context omitted.

How hard is it to get at 2400 DPI finger print? Left arrow key? Coffee cup? Left button of a mouse? Car door handle?

Well... yeah, but there is quite a lot of smearing. Will the quality of the finger print you can extract that way using whatever means you have be of high enough quality? It is not obvious to me that you'll be able to get something that is 2400 DPI quality.

Look at your finger. Actual ridges are not that dense.

A sampling frequency of 20 points per mm is high enough to visualise a fingerprint in sufficient detail for identification purposes https://en.wikipedia.org/wiki/Fingerprint#Research

Random #s: 20dpmm = 5,080dpi? Sounds like 2400dpi sensing is certainly insufficient for research-grade identification... and therefore maybe easy to fool? :)

Re: Chaos Computer Club breaks Apple TouchID

#359

Earlier quoted context omitted.

Apple claims that "The technology within Touch ID is some of the most advanced hardware and software we've put in any device." [1]. This attack showed that increasing sensor resolution only requires increasing the resolution on the fake print to match. This attack is an interesting data point in the debate over using biometrics in access control systems. Apple was hyped to have introduced something new and exciting i…

> This attack showed that increasing sensor resolution only requires increasing the resolution on the fake print to match. Just to clarify, it wasn't just the increased resolution that was required here, but "latex milk", I assume to simulate a living finger, as well. It's not as simple as print-of-print = unlock.

Latex milk, white glue, grocery-store gelatin— they all work. You just need something thin and flexible that'll take an impression.

Re: Chaos Computer Club breaks Apple TouchID

#360
post #10
post #9

Wasn't Gruber getting awfully excited about how amazing and revolutionary Apple's finger print sensor was? Will he be claim chowdering?

What did he claim?

Along with the other bollocks that has been linked he even chucked this one up just before the weekend, http://daringfireball.net/linked/2013/09/20/touch-id-star trashing the linked news article.

Number 1 on the list from the Toronto Star was "How long before hackers crack the security function?" How 'misinformed' of them.

Post reply on HN