In the comments there is so much focus on the convenient aspect of TouchID. I agree, but the main point I think is that we have a situation where: - fingerprint authentication will be seen as more casual and mainstream than it was before [1] - people will still leave fingerprints everywhere, including around and on the fingerprint sensors - once a high resolution image of a fingerprint is done, it can be re-used for…
Chaos Computer Club breaks Apple TouchID
371–380 of 458 posts
Re: Chaos Computer Club breaks Apple TouchID
#372Earlier quoted context omitted.
This is where things start to get tricky. I've read up on "chip and PIN" in Europe, where purchasers have to insert their cards into a reader and enter the numeric code that is stored on the card. From what I've found online, chip-PIN does indeed reduce fraud, but when fraud does happen, it becomes extraordinarily difficult for the cardholder to get a refund from the bank. I could see fingerprint scanning going the s…
> From what I've found online, chip-PIN does indeed reduce fraud, but when fraud does happen, it becomes extraordinarily difficult for the cardholder to get a refund from the bank. I live in Europe, and twice in the last two years or so my card details have been compromised, and both times my bank has rang me to notify me of suspicious transactions before I'd even noticed. It depends on the bank (and the country most…
I believe that this has now changed (although I've not had a new card recently and I don't remember seeing any new TOS).
Re: Chaos Computer Club breaks Apple TouchID
#373Despite all the claims of how insecure this is, I've just checked a bunch of my stuff. I cannot find a single clear print. There are a few smudged prints on my laptop and coffee cup. My phone is just smudges all over. So what is a realistic way to clandestinely grab a print?
Re: Chaos Computer Club breaks Apple TouchID
#374Here's an idea that would improve security in conjunction with the new sensor: Create a random pattern of ridges and, using the technique outlined in the OP, build a latex key. Attach that to your keychain (in some sort of case to improve durability, maybe). Then, enjoy 2-factor auth, between the phone's pass code and the synthetic fingerprint.
Re: Chaos Computer Club breaks Apple TouchID
#375Earlier quoted context omitted.
Since they'd reverse the charges anyway if it wasn't you who made them, what exactly is the problem here?
This is where things start to get tricky. I've read up on "chip and PIN" in Europe, where purchasers have to insert their cards into a reader and enter the numeric code that is stored on the card. From what I've found online, chip-PIN does indeed reduce fraud, but when fraud does happen, it becomes extraordinarily difficult for the cardholder to get a refund from the bank. I could see fingerprint scanning going the s…
Re: Chaos Computer Club breaks Apple TouchID
#376Earlier quoted context omitted.
> Touch ID is better than nothing... but not by much You can't be serious. A completely unlocked phone that anybody can trivially access with a swipe.. vs. a scanner that you'd have to lift and reconstruct someone's fingerprint to bypass. That is definitely a significant improvement.
Yes, how many people run $10,000 dollar competitions to get past the default swipe to unlock screen?
Re: Chaos Computer Club breaks Apple TouchID
#377I have accidentally seen basically all of my friends' passcodes as they type it in at bars etc. I could get into their phones easily. TouchID is more secure than that simply because someone needs to take a 2400dpi image of the person's finger to do it. Locks (when physical access to a device is available) are to keep honest people honest. Most security experts that I know agree that if an intruder has physical access…
I have accidentally seen basically all of my friends' passcodes as they type it in at bars etc. I could get into their phones easily. And your friends could change their password 365 times per year every year for the rest of their lives. With fingerprints, they get 10 password changes.
I'd say 9 password changes...
Re: Chaos Computer Club breaks Apple TouchID
#378Earlier quoted context omitted.
> I think they're missing the point. The passcode on an iPhone defends against other people in your environment - family members, coworkers, roommates - getting your information opportunistically. It doesn't defend against hackers, the government, or even slightly savvy thieves. The Google Chrome Security team begs to differ [1]. According to them giving someone the illusion of security is bad. [1] https://news.ycomb…
Giving someone the illusion of security is bad because it displaces their understanding of security. An understanding of security will reveal that security is not a binary state of affairs. It's perfectly reasonable to trust known-imperfect mechanisms like the iPhone fingerprint reader to keep honest people honest and discourage ordinary muggers and thieves. I don't need military-grade access control for my personal…
Re: Chaos Computer Club breaks Apple TouchID
#379If we've learned anything over the past few months, it is that security is an illusion when it comes to Google, Apple and Facebook. The fingerprint scanner is not intended to protect your personal data from being accessed by nefarious cyber-spooks or crackers. The $5 dollar wrench technique is fairly effective in bypassing such security anyway. The fingerprint scanner is there so that when your phone is nicked by a m…
> It's _not_ the panacea to all our security woes, and they have never claimed it was. But they've never said it wasn't, either. It's important that everyone is in the clear about how secure TouchID is. I'm going to use it anyway, but the other decision is how much personal data I want to store on my phone.
* Note: TouchID is not the panacea to all our security woes. will not cure cancer, create world peace, does not kill kittens, [continues on listing everything it's not for 9 trillion pages]
Re: Chaos Computer Club breaks Apple TouchID
#380Earlier quoted context omitted.
'every so often' seems a bit casual, for a payment [1,2] [1] From the citation: "Passcodes and passwords aren’t completely eliminated by Touch ID, then, but they almost certainly will be later on." [2] The glass screen will have your fingerprint on it, somewhere. That can be CSI'd by anyone who finds it. Anyone serious enough to do that (and its not much) can start escalating.
The primary use case here is keeping kids from buying apps or in-app purchases when their parents lend them the phone to play games. A casual solution is perfectly acceptable. If someone is going to go through the trouble of stealing my phone and cloning my fingerprint I'm guessing they would want more than purchasing music or apps under my iTunes account.