Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

371–380 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#371
post #266

In the comments there is so much focus on the convenient aspect of TouchID. I agree, but the main point I think is that we have a situation where: - fingerprint authentication will be seen as more casual and mainstream than it was before [1] - people will still leave fingerprints everywhere, including around and on the fingerprint sensors - once a high resolution image of a fingerprint is done, it can be re-used for…

[deleted]

Re: Chaos Computer Club breaks Apple TouchID

#372

Earlier quoted context omitted.

This is where things start to get tricky. I've read up on "chip and PIN" in Europe, where purchasers have to insert their cards into a reader and enter the numeric code that is stored on the card. From what I've found online, chip-PIN does indeed reduce fraud, but when fraud does happen, it becomes extraordinarily difficult for the cardholder to get a refund from the bank. I could see fingerprint scanning going the s…

> From what I've found online, chip-PIN does indeed reduce fraud, but when fraud does happen, it becomes extraordinarily difficult for the cardholder to get a refund from the bank. I live in Europe, and twice in the last two years or so my card details have been compromised, and both times my bank has rang me to notify me of suspicious transactions before I'd even noticed. It depends on the bank (and the country most…

When Chip and PIN came in, as part of the TOS that you accepted by using the card, it included a clause that the bank is not liable for any fraud on the card as Chip/PIN is unbreakable (the implication being you must have given away your PIN).

I believe that this has now changed (although I've not had a new card recently and I don't remember seeing any new TOS).

Re: Chaos Computer Club breaks Apple TouchID

#373

Despite all the claims of how insecure this is, I've just checked a bunch of my stuff. I cannot find a single clear print. There are a few smudged prints on my laptop and coffee cup. My phone is just smudges all over. So what is a realistic way to clandestinely grab a print?

The CCC previously published a German minister's fingerprint. They acquired it by lifting a water glass he had used at a public event. http://www.edri.org/edrigram/number6.7/fingerprint-schauble

Re: Chaos Computer Club breaks Apple TouchID

#374
post #28

Here's an idea that would improve security in conjunction with the new sensor: Create a random pattern of ridges and, using the technique outlined in the OP, build a latex key. Attach that to your keychain (in some sort of case to improve durability, maybe). Then, enjoy 2-factor auth, between the phone's pass code and the synthetic fingerprint.

Wow cool idea, someone needs to test that

Re: Chaos Computer Club breaks Apple TouchID

#375

Earlier quoted context omitted.

Since they'd reverse the charges anyway if it wasn't you who made them, what exactly is the problem here?

This is where things start to get tricky. I've read up on "chip and PIN" in Europe, where purchasers have to insert their cards into a reader and enter the numeric code that is stored on the card. From what I've found online, chip-PIN does indeed reduce fraud, but when fraud does happen, it becomes extraordinarily difficult for the cardholder to get a refund from the bank. I could see fingerprint scanning going the s…

In particular, it turned out that there was a flaw in the Chip and PIN specification which made it possible to bypass the PIN requirement. There's some evidence this was exploited fairly widely in the wild before security researchers found the flaw, but since the banks erased the logs that recorded whether a PIN was actually used all the customers ended up liable for the fraudulent charges.

Re: Chaos Computer Club breaks Apple TouchID

#376

Earlier quoted context omitted.

> Touch ID is better than nothing... but not by much You can't be serious. A completely unlocked phone that anybody can trivially access with a swipe.. vs. a scanner that you'd have to lift and reconstruct someone's fingerprint to bypass. That is definitely a significant improvement.

Yes, how many people run $10,000 dollar competitions to get past the default swipe to unlock screen?

Based on what they've said previously, I'm pretty sure the people who ran that competition expected TouchID to be a lot harder than this to bypass and were doing it as a publicity stunt to try and demonstrate that.

Re: Chaos Computer Club breaks Apple TouchID

#377
post #43

I have accidentally seen basically all of my friends' passcodes as they type it in at bars etc. I could get into their phones easily. TouchID is more secure than that simply because someone needs to take a 2400dpi image of the person's finger to do it. Locks (when physical access to a device is available) are to keep honest people honest. Most security experts that I know agree that if an intruder has physical access…

I have accidentally seen basically all of my friends' passcodes as they type it in at bars etc. I could get into their phones easily. And your friends could change their password 365 times per year every year for the rest of their lives. With fingerprints, they get 10 password changes.

How do you change password with one finger left?

I'd say 9 password changes...

Re: Chaos Computer Club breaks Apple TouchID

#378

Earlier quoted context omitted.

> I think they're missing the point. The passcode on an iPhone defends against other people in your environment - family members, coworkers, roommates - getting your information opportunistically. It doesn't defend against hackers, the government, or even slightly savvy thieves. The Google Chrome Security team begs to differ [1]. According to them giving someone the illusion of security is bad. [1] https://news.ycomb…

Giving someone the illusion of security is bad because it displaces their understanding of security. An understanding of security will reveal that security is not a binary state of affairs. It's perfectly reasonable to trust known-imperfect mechanisms like the iPhone fingerprint reader to keep honest people honest and discourage ordinary muggers and thieves. I don't need military-grade access control for my personal…

You are completely detached from normal practical realities, as such your beliefs on security can be safely disregarded.

Re: Chaos Computer Club breaks Apple TouchID

#379

If we've learned anything over the past few months, it is that security is an illusion when it comes to Google, Apple and Facebook. The fingerprint scanner is not intended to protect your personal data from being accessed by nefarious cyber-spooks or crackers. The $5 dollar wrench technique is fairly effective in bypassing such security anyway. The fingerprint scanner is there so that when your phone is nicked by a m…

> It's _not_ the panacea to all our security woes, and they have never claimed it was. But they've never said it wasn't, either. It's important that everyone is in the clear about how secure TouchID is. I'm going to use it anyway, but the other decision is how much personal data I want to store on my phone.

TouchID*

* Note: TouchID is not the panacea to all our security woes. will not cure cancer, create world peace, does not kill kittens, [continues on listing everything it's not for 9 trillion pages]

Re: Chaos Computer Club breaks Apple TouchID

#380
post #254

Earlier quoted context omitted.

'every so often' seems a bit casual, for a payment [1,2] [1] From the citation: "Passcodes and passwords aren’t completely eliminated by Touch ID, then, but they almost certainly will be later on." [2] The glass screen will have your fingerprint on it, somewhere. That can be CSI'd by anyone who finds it. Anyone serious enough to do that (and its not much) can start escalating.

The primary use case here is keeping kids from buying apps or in-app purchases when their parents lend them the phone to play games. A casual solution is perfectly acceptable. If someone is going to go through the trouble of stealing my phone and cloning my fingerprint I'm guessing they would want more than purchasing music or apps under my iTunes account.

And if you know your phone is stolen you can disable it anyways.
Post reply on HN