Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

381–390 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#381
post #339

Earlier quoted context omitted.

So you're going with a slippery slope argument? This thing could cause that thing that could cause that bad thing, so this thing is bad? I suppose that is something that could happen in the future. It's not a likely problem to complain about with this particular implementation.

Since they'd reverse the charges anyway... You're baselessly asserting your position, though. If you write your pin on your ATM card, they will not refund you. That is policy and they ask everytime you lose your card. The bank views this as lack of due care. Likewise, if you leave copies of your fingerprints on your payment device, they could argue that you are likewise acting with un-reasonable care. Now that this h…

The bank has never asked me if I had my PIN written on my card when I've lost it... all they ask is lost or stolen.

Re: Chaos Computer Club breaks Apple TouchID

#382

Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…

What worries me the most is that biometrics can be used to authorize payments, and for anyone that has crafty teenage (or younger) kinds this might sounds a bit risky. Getting access to your parents fingerprint is easy while getting access to their password is much harder.

Getting access to the equipment required to duplicate their fingerprint is much harder...

Re: Chaos Computer Club breaks Apple TouchID

#383

The "How to fake fingerprints" link [1], is one of the scariest things I have seen, given how simple it is, and how much we reply on fingerprints for linking people to crimes. BTW, for anyone who does not know about Chaos Computer Club (CCC) [2], they run a massive conference in EU. You can look at some of their talks @ http://media.ccc.de/ [1] http://dasalte.ccc.de/biometrie/fingerabdruck_kopieren?langu... [2] http:…

Frontline had an excellent piece on the (lack of) reliability behind most of crime forensics. Fingerprints in particular are mentioned as being very unreliable and unscientific. The only scientifically rigorous piece of "CSI" is DNA matching. http://www.pbs.org/wgbh/pages/frontline/real-csi/

Except laboratory error reduces the claimed reliability of DNA massively (to one in a few thousand levels, iirc - not one in a million).

Re: Chaos Computer Club breaks Apple TouchID

#385

Earlier quoted context omitted.

Where the fuck did that come from? It is neither baseless or FUD. That fingerprint will be sent over the wire at some point and the NSA will gladly pick it up. How you think otherwise is beyond me. What operating system I prefer really has nothing to do with it, even if it is linux. Posted from my iPhone, android, third mac mini, 2nd mac air, or first thinkpad who the fuck knows (or cares? oh you obviously)

It's fud until you or someone else posts evidence that the fingerprint is sent over the wire, or that Apple intends to do the same (for example, code that sends the fingerprint that awaits activation by a third party). You're not going to be able to do that. It's shameful that you can't even recognize the fudishness of what you posted, especially if Linux actually is your operating system of choice and you have been…

"It's fud until you or someone else posts evidence that the fingerprint is sent over the wire"

It absolutely isn't. Even if just the hash were sent over the wire (or if it were possible for the authorities to extract it over the wire), it would be perfectly possible for the authorities to run the same hash algorithm on their candidate print and see if the hashes match. Such evidence would likely not be admissible in court but 1) it would be enough to give the authorities a tipoff, 2) for matters deemed important enough, secret trials seem to be all the rage these days.

I would be _very_ surprised if there were no backdoor in iPhones for the authorities. Even their "secure" area. The U.S. authorities simply do not take no for an answer when having a "talk" with a vendor producing a widespread "security" related product.

Re: Chaos Computer Club breaks Apple TouchID

#386
According to the adverts by Apple they specifically select certain points on the finger print and analayze then permit access. If such a technology is broken then I would assume their encryption on the A7 chip where the fingerprint is stored also can be broken.

If lots of people do not use passwords on their phones for the sake of comfort then it is not anyones fault that their phones are logged into or information stolen. Information is stolen because the user is lazy to secure the device.

When Apple says one can use finger print to do transactions then I have to assume that the transaction cannot be done by anyone other than me and by any other means through the phone.

Re: Chaos Computer Club breaks Apple TouchID

#388
post #202

Earlier quoted context omitted.

More context, for those of us not up-to-date on German politics?

Outcome of the elections. Merkel won. The CDU (Christian Democratic Union) isn't very Internet and hacker friendly.

For the record:

Merkel personally assured Obama that she would refuse Snowden, in case he applied for asylum in Germany.

Makes it pretty clear what the world can (not) expect from Germany.

Re: Chaos Computer Club breaks Apple TouchID

#389
post #238

Earlier quoted context omitted.

This seems correct. Apple's moved the bar to breaking into those phones from having the phone and a 4 digit or no passcode to having: -- the phone -- a 2400 dpi resolution image of the correct fingerprint -- a 1200 dpi laser printer & transparent paper -- pink latex milk or white woodglue -- a non-trivial amount of time

That's what I was thinking, too. The fingerprint scanner is a bit like a LoJack - it's still possible to steal a car with a "The Club" on it, but most thieves will probably just move on to another car (although I've heard that car thieves, like pick pockets, don't really steal cars anymore, just components and loose gear.)

>although I've heard that car thieves, like pick pockets, don't really steal cars anymore, just components and loose gear.

I heard that too, airbags, satnav and entertainment systems are the target...

Re: Chaos Computer Club breaks Apple TouchID

#390
post #142

Earlier quoted context omitted.

The most secure computer is the one locked in a room and unplugged. There has never been a method of security that is secure. The first thing you learn when dealing with security is there are tradeoffs between opportunity, time, money. and usability.

While I agree with the spirit of your post, there is in fact a method of security that is definitively unbreakable (if used correctly/precluding side-channelling): the one-time-pad. But as you imply, the reason we don't use it is because the opportunity cost and hassle of using it are too high for many uses.

You proved my point by needing to exclude side-channel attacks. You also need keying material, and a way to communicate that material, for a one-time pad and that's vulnerable to a whole host of attacks.
Post reply on HN