Live data from Hacker News

Fingerprints are Usernames, not Passwords

blog.dustinkirkland.com

151–160 of 261 posts

Re: Fingerprints are Usernames, not Passwords

#151
post #108

Earlier quoted context omitted.

Except TouchID, from what I gather, actually works. Not "works" in the sense of keeping bad people out, but "works" in the sense that when I use it my phone unlocks. I tried face unlock briefly on the Google Nexus I've got and disabled it shortly after when I found that it was unreliable. Poor lighting, too much lighting, a bad hair day, it wasn't even at 80% for successful unlocks.

Fake unlock was slow and unreliable when it first came out 2 years ago but is pretty darn good nowadays, and just as fast as TouchID. No, it doesn't work in pitch dark or if you're wearing sunglasses. But I'll take "works 90% of the time" over an unlock feature that requires a hardware component that pretty much locks you into 1 form factor.

The problem is that you need to think about this when you unlock your phone. With TouchID you always unlock your phone with your finger.

Re: Fingerprints are Usernames, not Passwords

#152

Earlier quoted context omitted.

but can probably lift the print right off the phone itself That doesn't seem to be the case to my knowledge. The evidence from the successful attack is that you need an excellent-quality print from one of the specific fingers that has been programmed into the phone. Some phones probably have that on them, but it appears likely that many do not.

Can't someone write an app that stays in the background on their phone and copies fingerprints of people who touch your button?

Under the assumption that the sandbox works, no.

Re: Fingerprints are Usernames, not Passwords

#153
post #82
post #61

Earlier quoted context omitted.

Maybe you should say what story he's pointing to that's obviously fake? I'm sure you mean the "Apple is sharing fingerprints with the NSA" link...

Clearly. http://www.theguardian.com/technology/2013/sep/27/no-nsa-iph...

Well, I've never heard anywhere that Apple was sharing the fingerprints with the NSA. As far as I know, nobody said that... It's just the obvious* default assumption.

And the matter of default assumptions is that you need evidence that they are false. Apple denying it is no evidence. But yeah, the point about the microphone and camera stands.

* And it is obvious, no point is arguing against that. When everybody makes the same assumptin the first time they have a new piece of data, the assumption is obvious.

Re: Fingerprints are Usernames, not Passwords

#154
post #43

"Once your fingerprint is compromised how do you change it?" This is the central question for all biometrics for me and I believe one of the hardest problems to solve. There are many people who believe they are solving this by using ever more intricate biometric identifiers, thus increasing the bar to reproduce them beyond what they believe currently feasible. But I'm yet to see that central question addressed. What…

https://news.ycombinator.com/item?id=6478343

> they'd have a few attempts to unlock it with a fake fingerprint, and then they'd have to enter my code. And if they fail to enter my code 10 times, the phone is wiped.

I don't use it, but it seems there's a fallback password after __ failed attemps.

Re: Fingerprints are Usernames, not Passwords

#155
post #139

Earlier quoted context omitted.

Apparently that can be defeated with Photoshop.

Or maybe a animated GIF image.

Animated gifs would today work. What if the camera focused on something behind you first and then the face? Would that bypass a 2D method?

Re: Fingerprints are Usernames, not Passwords

#156

Earlier quoted context omitted.

Nope. If it's not a hardware lock, it will be bypassed.

Correct me if I'm wrong, but I'm pretty sure Apple's new iOS7 activation lock has not been defeated yet. Keep in mind that if these criminals can't figure it out by googling it, they will give up and move on. The typical phone thief isn't a security expert with the knowledge to invent a previously unknown exploit.

Well, it's possible that the fence they sell the phones to would be motivated to find an exploit.

Re: Fingerprints are Usernames, not Passwords

#157
post #136
post #100

Earlier quoted context omitted.

I'm pretty sure the GP was talking about the likelihood of a given phone having an appropriate-quality print [1], which does seem low. But putting that aside, your hypothetical app would -- using the demonstrated method -- 'lift' that excellent quality print, scan it at 2400 dpi, (clean up said print), print it on a transparency at 1200 dpi, mask it onto photosensitive PCB, develop/etch/clean the PCB, spray graphite…

I find it amazing that when faced with a general question about a "security" feature the median internet tech nerd responds with an attitude of absolute paranoia (c.f. 4096 bit RSA keys, multi-word pass phrase choices, ssh key forwarding pedantry, general NSA tinfoil hatism....) Except when confronted with an Apple product. Then it's all "Nah bro, relax. No way could you lift a fingerprint from a glossy phone screen"…

You see two different classes of responses because there's two different use cases.

There's security that geeks advocate for ourselves and our own implementations (often things we only have to set up and maintain infrequently) and then there's security that normals actually use (often things they have to authenticate with several times a day).

And I must have missed it, if anyone's been arguing this is a serious security mechanism. As far as I've seen, it's been lauded as (not much) better than a passcode, but, primarily, convenient enough to get people to use it instead of nothing, bringing up the relative security of a still-fairly-insecure bunch.

And you may want to re-read the discussion over the faked-print attacks. It isn't about (im)possibility. It's about the time, expertise and equipment involved and the likelihood of success being too expensive to be worthwhile for gaining access to most phones. [1]

And if we're wearing our "serious" security hats, I still don't see any reason to worry too much about print faking, as its core assumption is a skilled attacker who has unfettered physical access to our device, unbeknownst to us and beyond our control. And at that point, the game is already over.

[1] CCC themselves, with ideal source prints, had to significantly complicate their process to generate fakes that worked with a suitable consistency. So even if you think suitable source prints grow on trees, the point of significant skill, equipment, time and resources remains.

Re: Fingerprints are Usernames, not Passwords

#158
In this argument we are trying to find a balance between convenience and security - - but it's not possible. Anything that is easy for me to do to unlock a phone can be faked and/or hacked.

I'd rather just have an NFC chip hidden on my body that I had to tap the phone on before entering a numeric value on a randomized keypad.

Re: Fingerprints are Usernames, not Passwords

#159
post #140
post #138

Earlier quoted context omitted.

You have your phone in your pocket, I want to access your data. With touch unlock, all I need is my buddy to hold you for 3 seconds while I twist your arm and unlock the phone. With passcode unlock, getting the password out of you will take some more effort. Oh, and in this scenario, I can be a thief, or a police officer, or a borders agent, or an abusive husband, or many other things :)

> With passcode unlock, getting the password out of you will take some more effort. Given that there are two people, capable of violence, against the phone owner I'm not sure that getting the password is going to be that much trouble.

Forcing someone to put their finger on a phone is a matter of seconds. No matter how you put it, getting a password is harder and lengthier.

Re: Fingerprints are Usernames, not Passwords

#160
post #34

All these academic arguments about the security of fingerprints are interesting but completely are detached from the day-to-day use of TouchID. I've been using it for about a week or so now. It's incredibly convenient. It unlocks my phone almost instantly. It prevents random people near by phone from being unable to unlock it. If a thief got their hands on it, they'd have a few attempts to unlock it with a fake finge…

I think your response raises an issue of perspective. Are we focusing on fingerprint technology from a user's point of view - or are we considering its implications over many years?

This reminds me of certain U.S. Supreme Court decisions. As someone who's interested in constitutional law, I often find myself defending things that seem trivial and nitpicky. Why does it matter if the police enter one drug dealer's home without a proper warrant? Who cares if we restrict someone's speech, considering that the person was, say, a racist whose ideas were ignorant and offensive?

Of course, the content in this analogy is very different. I'm not comparing fingerprint scanners to crimes. But the logic is very similar: when judging law and technology, respectively, it's important to consider how seemingly small decisions serve as a precedents for bigger trends.

If fingerprint scanners become a common replacement for passwords, and the author's argument is correct, the scanners may dramatically change our security and expectations of privacy.

Post reply on HN