Potential side effect of TouchID: Due to the mass marketing of this feature it becomes cool for people to learn how to copy fingerprints, causing a massive headache for forensics teams everywhere.
Chaos Computer Club breaks Apple TouchID
361–370 of 458 posts
Re: Chaos Computer Club breaks Apple TouchID
#362Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…
This seems correct. Apple's moved the bar to breaking into those phones from having the phone and a 4 digit or no passcode to having: -- the phone -- a 2400 dpi resolution image of the correct fingerprint -- a 1200 dpi laser printer & transparent paper -- pink latex milk or white woodglue -- a non-trivial amount of time
Re: Chaos Computer Club breaks Apple TouchID
#363Re: Chaos Computer Club breaks Apple TouchID
#364Earlier quoted context omitted.
Regardless of whether or not fingerprint scanners are good security wise, it's a bit silly to think that phone robbing thugs are completely dim. The way it works in my first world modern country is that there are shops everywhere that unlock or reset phones as part of their services, and it isn't thugs running them. It's people with an affinity for 'tech' who just happen to deal with a shadier area. If cracking finge…
No, this is not the same as sim unlock. Circumventing touch id technology by making fake fingerprints is exactly the same case as being called to unlock a locked doors. The specialist knows when he is liable to crime and cannot make a legal bussines out of illegal access.
Re: Chaos Computer Club breaks Apple TouchID
#365Earlier quoted context omitted.
Here's Apple's main marketing text on the subject: > Put your finger on the Home button, and just like that your iPhone unlocks. It’s a convenient and highly secure way to access your phone. Your fingerprint can also approve purchases from iTunes Store, the App Store, and the iBooks Store, so you don’t have to enter your password. It is definitely intended to replace passwords. Pretty good security would be to requir…
> Pretty good security would be to require both the fingerprint and a PIN You're missing the point. Right now lots of people have no password at all. Touch ID is a big improvement over having no password.
Having some shiny new method does not mean these people that do not currently use a pin/password will magically start using this.
Now, if Apple started forcing everyone to use one or the other (or both), that's another story.
Re: Chaos Computer Club breaks Apple TouchID
#366Earlier quoted context omitted.
That's hyperbolic. How often can someone see your passcode over your shoulder? Or have it picked up by a security camera? Fingerprint scanning absolutely has advantages over pass codes. Security is all about trade-offs. This result was to be expected (in some form). What will be worry me is if the "secure enclave" where the fingerprint data is stored is cracked (and I wouldn't be surprised if that happens too eventua…
Your point is moot. As soon as your fp is digitally available online. E.g.,the CCC has captured and published former german minister of the interior, Wolfgang Schäuble's fingerprint in 2008 [1]. This finger of him is not secure any more and readily available via a google image search. [1] http://www.h-online.com/newsticker/news/item/CCC-publishes-f...
Re: Chaos Computer Club breaks Apple TouchID
#367Earlier quoted context omitted.
We don't really know exactly what it stores, but they claim it's a hash of the fingerprint. That is not the same as the actual fingerprint at all, and it should be unusable outside the iPhone 5S ecosystem. I would imagine this hash, is also what they send to the servers to authenticate, but time will tell.
If they send a hash to servers, that still has privacy implications. Apple could build a searchable database of those hashes, and the government could issue subpoenas to search that database for particular fingerprints. Maybe that's not such a bad thing, because it could help to solve crimes, but it's worth thinking about.
http://www.ncbi.nlm.nih.gov/pmc/articles/PMC3093498/ states that even professional forensics required independent verification to eliminate false positives.
The hashes, whatever they are, will not be "binary" in their nature. Matching against a range of visual characteristics requires to allow some level of fuzziness. Even assuming that near future improvements bring the false positive rate to half of that of the best forensic experts (to 0.05%), the law of large numbers guarantees that innocent people will be caught up in investigation dragnets. Just imagine the lives destroyed by these kinds of clerical errors.
The above is the same reason I'm against our national law enforcement getting access to the passport biometric databases. Even discounting the potential for abuse: once the police have a suspect with "matching" fingerprint available, they will have less incentive to find other ones.
Re: Chaos Computer Club breaks Apple TouchID
#368Earlier quoted context omitted.
> My front door does not have a picture of my key on it. Yeah, but as every decent locksmith will attest, very-nearly-almost-all door locks can be easily opened with the right tools. Like picking a lock is a specialist skill, so is lifting a fingerprint and making a copy of it. No security is absolute; it's all trade-offs. Making it such that it's not worth your adversary's time to bother.
Yes, but as the same decent locksmith would attest, it would be foolish to have a picture of a key beside the lock, or anywhere in a public place. And that is what happens with a finger-print based secure system; you inadvertently place the imprint of the key on the phone's display as well as public places.
Re: Chaos Computer Club breaks Apple TouchID
#369Re: Chaos Computer Club breaks Apple TouchID
#370Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…
Touch ID is not "pretty good security" it's not even "good security" it's simply very bad security. Touch ID is better than nothing and that people use Touch ID instead of nothing is better than the current state but not by much and this definitely isn't a huge achievement. Which is really the biggest issue with Touch ID, it's advertised as such and people believe it.
The way that Apple haters use stunts like this to suspend normal logic and reasoning in order to express their juvenile spite is staggering.
No one, ever, claimed TouchID was impregnable, but it is very good security and is better than what the vast majority of people do at present.
Anyone prepared to devote the time and resources that CCC did to breaking your phone has other simpler means at their disposal. I personally believe that no one else will replicate this achievement because it is simply a publicity stunt to get clicks and feed the hordes of anti-Apple zealots.