Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

401–410 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#401
post #370
post #169

Earlier quoted context omitted.

Touch ID is not "pretty good security" it's not even "good security" it's simply very bad security. Touch ID is better than nothing and that people use Touch ID instead of nothing is better than the current state but not by much and this definitely isn't a huge achievement. Which is really the biggest issue with Touch ID, it's advertised as such and people believe it.

Having a lock in your front door is not perfect but it is much better than not having one at all. The way that Apple haters use stunts like this to suspend normal logic and reasoning in order to express their juvenile spite is staggering. No one, ever, claimed TouchID was impregnable, but it is very good security and is better than what the vast majority of people do at present. Anyone prepared to devote the time and…

Is not about Apple haters is that the security code is actually more secure than TouchID.

If having TouchID will increase the amount of people that doesn't lock thir phone I'm up for it. But is not this amazing super-secure technology that will revolutionize the world.

Re: Chaos Computer Club breaks Apple TouchID

#402
post #370
post #169

Earlier quoted context omitted.

Touch ID is not "pretty good security" it's not even "good security" it's simply very bad security. Touch ID is better than nothing and that people use Touch ID instead of nothing is better than the current state but not by much and this definitely isn't a huge achievement. Which is really the biggest issue with Touch ID, it's advertised as such and people believe it.

Having a lock in your front door is not perfect but it is much better than not having one at all. The way that Apple haters use stunts like this to suspend normal logic and reasoning in order to express their juvenile spite is staggering. No one, ever, claimed TouchID was impregnable, but it is very good security and is better than what the vast majority of people do at present. Anyone prepared to devote the time and…

The problem is not so much what CCC has done, but CCC has started. In the days/month ahead.. there is now a possibility of building a more practical attack. Remember the firefox plugin which allowed users to steal FB user sessions in a cafe with Free WiFi (or any WiFi hotspot)? That wasn't a new attack.. just made an existing attack easier (and hence caught a LOT of attention).

The threat is similar. Now there is an exploit.. now the collective security researcher (and hacktivist) will work to make the hack easier by building a tool.. THERE lies the real danger.

I still commend Apple for trying. The real issue will be if I can steal the "Hash" of the fingerprint and reverse it to know who it is... so far TouchId has done well. The way that happens, Apple users will need to rethink using TouchID

Re: Chaos Computer Club breaks Apple TouchID

#403
post #333

Earlier quoted context omitted.

Citing the Google Chrome Security team regarding security is the exact opposite of the appeal to authority fallacy. It's an appropriate expert for the context.

No. It's appeal to authority.

It is an appeal to authority, but a non fallacious one. As the authority being quoted has the relevant position.

Re: Chaos Computer Club breaks Apple TouchID

#404

Earlier quoted context omitted.

> That would work in the sort of Hollywood movie where the government has everyone's DNA on file. You don't have to have "everyone's DNA on file". It's actually pretty trivial even for your neighbor or whoever to get your DNA. As for the police falsifying evidence, there's a wikipedia-long history of cases, in Europe, Latin America, Asia, etc. Especially in politically charged times, like the sixties and seventies. H…

> You don't have to have "everyone's DNA on file". It's actually pretty trivial even for your neighbor or whoever to get your DNA. Sorry, I wasn't clear. I can dump a gallon of your blood and semen onto a dead guy in an alley, but how would the government trace that blood and semen back to you?

A, sure.

Well, as the culprit, you can always arrange some things or leave other stuff that also points to me.

Also, your main benefit is that the police will more easily believe that it wasn't you (since your DNA won't match).

Re: Chaos Computer Club breaks Apple TouchID

#405
post #254

Earlier quoted context omitted.

'every so often' seems a bit casual, for a payment [1,2] [1] From the citation: "Passcodes and passwords aren’t completely eliminated by Touch ID, then, but they almost certainly will be later on." [2] The glass screen will have your fingerprint on it, somewhere. That can be CSI'd by anyone who finds it. Anyone serious enough to do that (and its not much) can start escalating.

The primary use case here is keeping kids from buying apps or in-app purchases when their parents lend them the phone to play games. A casual solution is perfectly acceptable. If someone is going to go through the trouble of stealing my phone and cloning my fingerprint I'm guessing they would want more than purchasing music or apps under my iTunes account.

Locks just keep an honest man honest.

If someone wants what you have bad enough, there really isn't anything you can do to stop them.

Re: Chaos Computer Club breaks Apple TouchID

#406

Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…

That comment perfectly sums up what I have been trying to argue with friends the last day or two! Thank you! Presuming you don't mind I will send this over to them!

Re: Chaos Computer Club breaks Apple TouchID

#407
post #306

Earlier quoted context omitted.

The problem here is your implying getting past the 4 digit code is substantially easier then cloning a finger print. The code is in someone's head, or you have to deconvolute it from screen smudges. Your fingerprints are literally everywhere you go.

I think it would be pretty easy to get many people's phone password -- just by being in the right place when they unlock it, and watching closely. Most people I know don't cover up their phone at all when they enter it, even in public. So you don't need to get "in someone's head". You just need a good view of them using it. Granted, getting an iTunes Store password by just watching would be a lot harder. But compared…

Conversely you can just change a phone password. Hell you could rotate it daily if you wanted (surprised that's not a feature yet). But you can't change your fingerprints.

Re: Chaos Computer Club breaks Apple TouchID

#408
If you're really concerned about this, just register part of the finger that isn't the tip, and get in the habit of smudging the home button afterwards. I usually only touch the phone with my finger tips or palm, and you could register, for example, a part of the finger under the knuckle that almost never touches the device except to authenticate the print.

Of course if CCC knows which finger was registered, AND has a perfect print left on the device AND they know which print corresponds to the finger registered on the device, of course they can crack it. But if they have to guess which print on the device cracks it, I'm willing to bet they trigger the 5 failed attempts which then requires a passcode (and 10 failed attempts wiping the phone, although this is optional).

This means there are more than 10 options (which finger AND what part of each finger) you could use as a print. The oft cited scenario of police being able to compel you to input your print assumes they know what part of your hand unlocks the phone. They can't make me divulge the part of my hand thats registered just like they can't make me divulge my password.

Re: Chaos Computer Club breaks Apple TouchID

#409

Earlier quoted context omitted.

Since they'd reverse the charges anyway if it wasn't you who made them, what exactly is the problem here?

This is where things start to get tricky. I've read up on "chip and PIN" in Europe, where purchasers have to insert their cards into a reader and enter the numeric code that is stored on the card. From what I've found online, chip-PIN does indeed reduce fraud, but when fraud does happen, it becomes extraordinarily difficult for the cardholder to get a refund from the bank. I could see fingerprint scanning going the s…

It's not legal (now) for European banks to shift the fraud liability to the Customer with chip-and-PIN, but that hasn't stopped them from trying: http://www.thisismoney.co.uk/money/saving/article-2215223/Vi...

Re: Chaos Computer Club breaks Apple TouchID

#410

If you're really concerned about this, just register part of the finger that isn't the tip, and get in the habit of smudging the home button afterwards. I usually only touch the phone with my finger tips or palm, and you could register, for example, a part of the finger under the knuckle that almost never touches the device except to authenticate the print. Of course if CCC knows which finger was registered, AND has…

So if some of the worlds most elite biometric hacking experts need 48 hours, knowledge of the registered finger AND an almost perfect print left on the phone, I think it actually proves how secure the system actually is. If this was that easy they would have cracked it Friday, but it clearly took them several attempts despite being (some of, if not) the best in the world at forging fingerprints.

Yes you can't change your fingerprint, but you can change which is registered on the device (or with the bank, or whatever) and I'm guessing financial transactions outside of iTunes might require a passcode also. It's just another layer of optional security. Clearly it shouldn't be relied on as a foolproof, 100% secure authentication system but it certainly shrinks to pool of people who can gain access to my phone from "anyone who sees me unlock it several times a day" to "fingerprint forgery experts and highly sophisticated and motivated criminals."

Post reply on HN