Live data from Hacker News

Fingerprints are Usernames, not Passwords

blog.dustinkirkland.com

141–150 of 261 posts

Re: Fingerprints are Usernames, not Passwords

#141
post #133

Earlier quoted context omitted.

>> Having a matching fingerprint is evidence that an authorized user is authorized to use that identity. Considering that you leave your fingerprint everywhere you touch with your bare hands, is that really true?

There is a reason I chose the word "evidence" and not the word "proof". Yes, it is evidence. No, it is not proof. Further note that possession of a password ("something you know") is also merely evidence, not proof. Also, "something you have" is not proof either; having a token is merely evidence, not proof. We have no method of proof. If that is the standard you are looking for, then I have some bad news: It is impo…

>> what's the payback for cracking a fingerprint scanner, just to get access to a metaphorical Grandma's phone?

Well, if said Grandma is rich and is sharing dirty selfies with someone she doesn't want Grandpa to know about... being able to steal and use that information will probably be worth much more than the value of the phone itself.

Re: Fingerprints are Usernames, not Passwords

#144
post #136
post #100

Earlier quoted context omitted.

I'm pretty sure the GP was talking about the likelihood of a given phone having an appropriate-quality print [1], which does seem low. But putting that aside, your hypothetical app would -- using the demonstrated method -- 'lift' that excellent quality print, scan it at 2400 dpi, (clean up said print), print it on a transparency at 1200 dpi, mask it onto photosensitive PCB, develop/etch/clean the PCB, spray graphite…

I find it amazing that when faced with a general question about a "security" feature the median internet tech nerd responds with an attitude of absolute paranoia (c.f. 4096 bit RSA keys, multi-word pass phrase choices, ssh key forwarding pedantry, general NSA tinfoil hatism....) Except when confronted with an Apple product. Then it's all "Nah bro, relax. No way could you lift a fingerprint from a glossy phone screen"…

Clever use of the word median to obscure the fact that you're conflating a two different attitudes which likely don't exist in the same person.

Re: Fingerprints are Usernames, not Passwords

#145
post #18

Earlier quoted context omitted.

What I think he is saying is that because it is now on iPhone, more devices/services/whatever may be likely to use finger prints for auth. This is dangerous because you can't change your fingerprint in the unlikely case someone dupes your print. If more and more things rely on finger prints, the value of duping goes up, right? What happens when your prints are duped once?

or could home 3d printing be used to create fingers with fingerprints?

A default Reprap won't be able to reproduce a fingerprint, but all it would take is increasing the reduction rate of the motors, using a smaller hole at the hot end, and a material that flows better (or increasing the temperature).

It would probably take a few tries, but seems well within a person-sized budget.

Re: Fingerprints are Usernames, not Passwords

#146
post #58

Earlier quoted context omitted.

Depends on scenario. If you steal a phone from a bag on the subway, you'll never be able to get that photo but can probably lift the print right off the phone itself. So maybe iOS has better-yet-still-mediocre protection against snooping yet inferiorly-mediocre guards against identity theft. Yawn. In neither case is the phone meaningfully protected against serious attack. Why must we have this argument? It's a cute f…

but can probably lift the print right off the phone itself That doesn't seem to be the case to my knowledge. The evidence from the successful attack is that you need an excellent-quality print from one of the specific fingers that has been programmed into the phone. Some phones probably have that on them, but it appears likely that many do not.

Can't someone write an app that stays in the background on their phone and copies fingerprints of people who touch your button?

Re: Fingerprints are Usernames, not Passwords

#147
post #110

Earlier quoted context omitted.

How does this work? I sold my old iphone to amazon. I never reported it "unstolen" or whatever to apple. Amazon paid me $200 for iPhone parts?

It's new in iOS 7. You'll have to explicitly wipe & reset your iPhone before selling it from now on. So if it works as advertised, stolen iPhones and iPads will only be worth the sum of their parts.

removing that wipe feature would be a nice tidy way to destroy the secondary market for iphones...

did I just predict iOS8?

Re: Fingerprints are Usernames, not Passwords

#148
post #34

All these academic arguments about the security of fingerprints are interesting but completely are detached from the day-to-day use of TouchID. I've been using it for about a week or so now. It's incredibly convenient. It unlocks my phone almost instantly. It prevents random people near by phone from being unable to unlock it. If a thief got their hands on it, they'd have a few attempts to unlock it with a fake finge…

An ideology of "Its good enough to thwart 99.9% of the population, therefore its good enough for me." is a very harmful ideology to have when it comes to security because you do nothing to deter mass adoption of the insecure technology.

While an individual person might not be at that great of risk because the amount of crackers willing to exploit touchID is limited to a minute demographic of people, the real harm comes when many iphone owners who share your ideology start using touchID instead of the more secure locking features their phones provide just because its more convenient.

Consider what happens when there are 100,000,000 million insecure phones out in the world. To a motivated cracker/spy/terrorist this is a huge ocean of potential suckers/victims vulnerable to exploitation. While most of these people aren't worth targeting, 1000-10,000 people might be.

This is why rejecting broken security technology is a cause everybody should rally behind. Even if you are never a victim of a black hat, you may very well suffer indirect consequences from the exploitation of somebody else.

Re: Fingerprints are Usernames, not Passwords

#149
post #136
post #100

Earlier quoted context omitted.

I'm pretty sure the GP was talking about the likelihood of a given phone having an appropriate-quality print [1], which does seem low. But putting that aside, your hypothetical app would -- using the demonstrated method -- 'lift' that excellent quality print, scan it at 2400 dpi, (clean up said print), print it on a transparency at 1200 dpi, mask it onto photosensitive PCB, develop/etch/clean the PCB, spray graphite…

I find it amazing that when faced with a general question about a "security" feature the median internet tech nerd responds with an attitude of absolute paranoia (c.f. 4096 bit RSA keys, multi-word pass phrase choices, ssh key forwarding pedantry, general NSA tinfoil hatism....) Except when confronted with an Apple product. Then it's all "Nah bro, relax. No way could you lift a fingerprint from a glossy phone screen"…

It's not at all clear that the absolute paranoiacs and the people saying that it's unlikely that any but a vanishingly small number of regular people will ever have Touch ID hacked are from the same set.

When you say it's not "a serious security mechanism", it sounds as if that's defined in some absolute terms. But if the effort to hack it is hundreds of times more difficult than the possible payoff from hacking it (which appears to be the case for nearly anybody but James Bond), then it acts as a serious security mechanism for that user's context. Literally nobody is going to make a mold of my finger to unlock my iPhone — they'd have to be absolutely insane to think that was worthwhile. So it's a serious security mechanism for me. Would it be a serious security mechanism to cover nuclear launch codes? Of course not.

Re: Fingerprints are Usernames, not Passwords

#150

Earlier quoted context omitted.

What are people going to do when, in the all-too-near future, criminals begin sharing and selling databases of stolen high resolution finger prints? One theft isn't practical? How about a million? Driven by a never-ending pursuit of monetary gain via crime; with criminals always happy to conquer the latest technology wave. There's absolutely no reason to think that criminals won't amass substantial finger print recor…

OK, you are a criminal and got 1000 000 fingerprints. You can start collecting them right now, on every surface you have access too. Then what? You will print them all using whatever technology required to fool fingerprint scanner and try one by one? Wouldn't it be just easier to try and lift one off the device itself? > It's about a consumer shift to finger prints as a primary > security feature No. It's about shift…

In the not so distant future, collecting fingerprints will be just a matter of writting malware, and uploading it. No need for labor intensive procedures such as collecting them from real stuff.

Now, in that world, what will criminals use the fake fingerprints for?

Post reply on HN