Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

411–420 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#411
[Regarding the point that this is only supposed to be convenient for users, not to be unhackable...]

Today: "Fingerprint scanning on my phone ... that's super convenient."

Tomorrow: "Fingerprint scan required by government ... oh well, I already use that on my phone."

FTA:

"We hope that this finally puts to rest the illusions people have about fingerprint biometrics. It is plain stupid to use something that you can´t change and that you leave everywhere every day as a security token", said Frank Rieger, spokesperson of the CCC. "The public should no longer be fooled by the biometrics industry with false security claims. Biometrics is fundamentally a technology designed for oppression and control, not for securing everyday device access." Fingerprint biometrics in passports has been introduced in many countries despite the fact that by this global roll-out no security gain can be shown.

iPhone users should avoid protecting sensitive data with their precious biometric fingerprint not only because it can be easily faked, as demonstrated by the CCC team. Also, you can easily be forced to unlock your phone against your will when being arrested. Forcing you to give up your (hopefully long) passcode is much harder under most jurisdictions than just casually swiping your phone over your handcuffed hands.

Re: Chaos Computer Club breaks Apple TouchID

#412

Earlier quoted context omitted.

> From what I've found online, chip-PIN does indeed reduce fraud, but when fraud does happen, it becomes extraordinarily difficult for the cardholder to get a refund from the bank. I live in Europe, and twice in the last two years or so my card details have been compromised, and both times my bank has rang me to notify me of suspicious transactions before I'd even noticed. It depends on the bank (and the country most…

When Chip and PIN came in, as part of the TOS that you accepted by using the card, it included a clause that the bank is not liable for any fraud on the card as Chip/PIN is unbreakable (the implication being you must have given away your PIN). I believe that this has now changed (although I've not had a new card recently and I don't remember seeing any new TOS).

The big gaping problem of course being that most fraud does not involve chip+pin transactions, but online transactions that are no better protected than before.

Re: Chaos Computer Club breaks Apple TouchID

#413

Earlier quoted context omitted.

> Most security experts that I know agree that if an intruder has physical access to a device, it can be considered compromised because it is just a matter of time. Anyone who says this is not a security expert. That hasn't been true since full disk encryption became available. A properly encrypted device is a brick if stolen, which is the only reason to have full disk encryption in the first place.

I take it you're not a security researcher either, because "A properly encrypted device is a brick if stolen, which is the only reason to have full disk encryption in the first place" is insufficient, too. Cold boot attacks, copying the drive and hacking the bootloader to get the drive password the next time you log in are two trivial methods, both of which have been used already. Once you lose physical access to you…

I like how you refer to things that you have never tried as "trivial". And the defense against those is easy. Don't reuse it after it was stolen then returned. That's a different threat.

Re: Chaos Computer Club breaks Apple TouchID

#414
post #385

Earlier quoted context omitted.

It's fud until you or someone else posts evidence that the fingerprint is sent over the wire, or that Apple intends to do the same (for example, code that sends the fingerprint that awaits activation by a third party). You're not going to be able to do that. It's shameful that you can't even recognize the fudishness of what you posted, especially if Linux actually is your operating system of choice and you have been…

"It's fud until you or someone else posts evidence that the fingerprint is sent over the wire" It absolutely isn't. Even if just the hash were sent over the wire (or if it were possible for the authorities to extract it over the wire), it would be perfectly possible for the authorities to run the same hash algorithm on their candidate print and see if the hashes match. Such evidence would likely not be admissible in…

> I would be _very_ surprised if there were no backdoor

I'm not sure if you understand what FUD means. Your surprise or lack thereof does not count as evidence, and is irrelevant to whether something is FUD or not.

> MS Exec: "I'd be very surprised if Linux had a lower TCO than Windows Server."

Canonical example of FUD. EXACT same thing as you're saying, just in a different context.

Re: Chaos Computer Club breaks Apple TouchID

#415

Earlier quoted context omitted.

Well... yeah, but there is quite a lot of smearing. Will the quality of the finger print you can extract that way using whatever means you have be of high enough quality? It is not obvious to me that you'll be able to get something that is 2400 DPI quality.

Look at your finger. Actual ridges are not that dense. A sampling frequency of 20 points per mm is high enough to visualise a fingerprint in sufficient detail for identification purposes https://en.wikipedia.org/wiki/Fingerprint#Research Random #s: 20dpmm = 5,080dpi? Sounds like 2400dpi sensing is certainly insufficient for research-grade identification... and therefore maybe easy to fool? :)

DPI refers to the number of samples in a straight line one inch long, not to the number of samples in a 1 inch square.

Re: Chaos Computer Club breaks Apple TouchID

#416
post #305

Earlier quoted context omitted.

Touch ID is competing against pins chosen from a universe of 10,000. This isn't great security, but it's appropriate security for unlocking a device you already must have physical access to.

Actually doesn't that highlight one of the biggest flaws with this, in that your finger prints will already be all over the device? Lift the device, get the authorisation token for free. At least with a password you also need to either crack it or discover it from some other means.

So far, nobody has demonstrated an attack that is able to break the fingerprint reader by reading fingerprints off of the device (or another surface). The attack demonstrated by CCC requires them to take a high resolution photograph of your finger. It is likely substantially harder to just lift a good enough quality fingerprint to defeat the system.

Re: Chaos Computer Club breaks Apple TouchID

#417

Earlier quoted context omitted.

In addition to the chimeric qualities cited in the NYT article (I skimmed), IIRC some DNA sampling has in the past used and may still use a fairly limited profile of markers. The statistically likelihood of matches between distinct parties is in some cases well under the population of the world. Never read into it in detail, but I was left with the impression that "unique identifier" can be an over-statement/qualific…

I thought they used restriction digests with gel electrophoresis, I'm pretty sure full genomic sequencing would be too expensive.

I don't really know, but this does sound familiar and is part of what I was speaking to. What type and generation of technology was used? How much was the solicitor of the test willing to pay for it (influencing the choice made within the current range of available technologies/capabilities), as well as how many sequence/data points were targeted.

As one example, combine a fairly limited set of targets with gel chromatography, and varying quality/accuracy of analysis/analysts of same... And you have a lot less "uniqueness" than things like the common, public term "DNA fingerprint" imply.

Yes, it may be a useful tool in combination with proper understanding of its limitations. However, we have (in the U.S., for example) and adversarial judicial process and prosecutors have been shown to often not place such understanding even in context let alone as a primary concern. If the defence is lacking, including simply financially to engage its own "expert witnesses"... misbegotten interpretations can and do rule the day.

Re: Chaos Computer Club breaks Apple TouchID

#418

Earlier quoted context omitted.

When most payments are under $5 it's probably ok. It's good enough for the credit/debit card payment industry, at least. (They relaxed the rules so you don't have to sign or enter a PIN for small purchases.)

Can we agree that Apple should not be marketing this as a "highly secure way to access your phone"?

Did you read the article? To crack the sensor, the would-be malevolent party needs a _2400 DPI photo of the fingerprint._

TouchID is highly secure if the only way to break into it is to have an ultra high-def image of the exact finger the device is looking for. I guess 50 character-long passcodes aren't secure because you could just tell a thief the code?

Re: Chaos Computer Club breaks Apple TouchID

#419

Earlier quoted context omitted.

Well, no password on their phone unlocks. But I thought Apple intended to replace your passwords in application services as well. Now, I didn't read the article at all (not a single damn word), so maybe the hack only applies to phone unlocks. If that is not the case however, then I think _you_ are missing the point. This would compromise all passwords replaced by finger print scans, right?

Reportedly when making purchases it "will still prompt you for your password every so often to 'renew Touch ID purchases.'" Source: http://www.cultofmac.com/246572/iphone-5s-first-impressions-... .

Since Friday, my 5s has prompted me for a password with this message more times than TouchID has worked succesfully.

Re: Chaos Computer Club breaks Apple TouchID

#420
post #385

Earlier quoted context omitted.

"It's fud until you or someone else posts evidence that the fingerprint is sent over the wire" It absolutely isn't. Even if just the hash were sent over the wire (or if it were possible for the authorities to extract it over the wire), it would be perfectly possible for the authorities to run the same hash algorithm on their candidate print and see if the hashes match. Such evidence would likely not be admissible in…

> I would be _very_ surprised if there were no backdoor I'm not sure if you understand what FUD means. Your surprise or lack thereof does not count as evidence, and is irrelevant to whether something is FUD or not. > MS Exec: "I'd be very surprised if Linux had a lower TCO than Windows Server." Canonical example of FUD. EXACT same thing as you're saying, just in a different context.

"EXACT same thing as you're saying"

You've got to be careful when you say things like that, because they're trivial to refute.

The whole point of a backdoor is to be obfuscated and hard to find. So it would be very likely that you would not find one even if one were present. Your example is simply a Microsoft not bothering to do something that's perfectly researchable.

We don't have any _proof_ that Dual EC DRBG is defeatable to the NSA. By your logic we should still be using it happily until we have that proof and until then any caution is simply "FUD".

So if that's "FUD", then I've got news for you: the security world is very sensibly built upon FUD.

Post reply on HN