Live data from Hacker News

Fingerprints are Usernames, not Passwords

blog.dustinkirkland.com

251–260 of 261 posts

Re: Fingerprints are Usernames, not Passwords

#251
post #230
post #227

Earlier quoted context omitted.

I'm pretty sure that iPhones have encrypted their data since the 3GS. That's how they "remote wipe" it. They send a message to the phone to delete the encryption key.

AFAIK the encryption key is stored in plaintext unless you also set a passcode (many people don't), and even if you set a passcode, most of the time it's just a short number that would be trivial to brute-force in an offline attack. Of course it's also possible to use eCryptFS with a four-digit passcode, but it's strongly recommended against. The main difference between FBI-proof encryption and pickpocket-proof encry…

Yeah, I was specifically addressing "The contents of the phone usually aren't encrypted". If you have a passcode (which is required for TouchID) then your iPhone is encrypted.

You can definitely brute force it. I saw an article somewhere (probably here on HN) addressing the fact. I can't find it, but if I remember correctly, it said something about Apple or an associated company quietly offering forensic help to police on bypassing the password. I think it implied they were using a ramdisk to brute force the encryption.

edit: Found an Ars article about Apple doing it, but it doesn't mention anything about a ramdisk. http://arstechnica.com/apple/2013/05/apple-will-reportedly-u...

Re: Fingerprints are Usernames, not Passwords

#252
post #207

Earlier quoted context omitted.

> I haven't used face unlock Face unlock is very fast - generally I turn device towards me to start using it and face unlock has unlocked it before I even realise it was locked (less than half a second). When it fails to recognise you, you can enter a pin/password/pattern. There is a menu option to 'Improve Matches' so it can pick up whatever is different this time. Every release has improved dramatically. After my m…

The answer is probably no, but does it work if you've got sunglasses on?? I know that Picasa's face detection works even if I am wearing sunglasses... thats the only reason I ask.

If it doesn't work first time with sunglasses then you use the "Improve Matching" to take a pic of you wearing sunglasses. They don't want identical pics of you - they want pics of how you vary. (Same story with facial hair etc)

Re: Fingerprints are Usernames, not Passwords

#253

Earlier quoted context omitted.

Consider the thorny issues of courts forcing people to turn over passwords to decrypt phones to implicate themselves. Typically, it's a constitution tarpit as you should not be forced to implicate yourself. However, your fingerprint is a username in that case because it is all over the place. The police already have it. Don't be fooled, there are certainly kits being sold to law enforcement to dupe TouchID. You're da…

This is a disadvantage only when you are on trial. That's a pretty extreme contingency, and I think most people who aren't internet privacy advocates wouldn't be particularly worried about their phones , of all things, after they've been arrested and indicted. Outside the HN bubble, this is an acceptable tradeoff. People who are concerned can continue to use passwords.

Not just on trial; on trial with incriminating information that's exclusively available on your iPhone and stored unencrypted without any additional passcode or password protection.

Re: Fingerprints are Usernames, not Passwords

#254
post #229

Earlier quoted context omitted.

My friend's 12-month old baby reset the unlock code on her mother's phone and they ended up having to wipe it completely in order to recover.

This is completely unrelated, but why do people say "12 months", "18 months", and "24 months" rather than 1 year, 1.5 years, and 2 years? I don't get it. I'd understand if they're younger than a year old (eg "My son is seven months old!"), but not once the age can be expressed in years.

Because numbers like the following are less clear:

- 1.0833 years old: 13 months

- 1.4166 years old: 17 months

- 1.8333 years old: 22 months

So, is it easier to use years on the clean decimals and months whenever it gets hairy, or to just settle on months?

Re: Fingerprints are Usernames, not Passwords

#255
post #187

Earlier quoted context omitted.

An ideology of "Its good enough to thwart 99.9% of the population, therefore its good enough for me." is a very harmful ideology to have when it comes to security because you do nothing to deter mass adoption of the insecure technology. While an individual person might not be at that great of risk because the amount of crackers willing to exploit touchID is limited to a minute demographic of people, the real harm com…

Does this go for the locks on your front door as well? As in "nobody should have front door locks that aren't 100% secure even against eg. terrorists"?

If such a lock existed (it doesn't, AFAIK), I would certainly want it on my door. I would still seriously consider it even if it was dramatically more expensive than a regular lock. Just because there are trade offs in security doesn't mean that anyone should be content with the state of the art and not push for improvements, or push against regressions. I'm not sure myself, but people see TouchID as a regression.

Re: Fingerprints are Usernames, not Passwords

#256

#66 on the Evil Overlord list: My security keypad will actually be a fingerprint scanner. Anyone who watches someone press a sequence of buttons or dusts the pad for fingerprints then subsequently tries to enter by repeating that sequence will trigger the alarm system. Why not have the sequence remain the password, but also scan fingerprints? If you have the wrong fingerprints (username), the right password still won…

"fingerprint or pin" means that when the fingerprint scanner doesn't work, you can use the pin to unlock your phone. "fingerprint and pin" means that when the scanner stops working, you are locked out. Apple has obviously decided this is more of a risk/inconvenience than the extra security justifies.

I keep forgetting that this discussion is iPhone-focused. At this point, I'm thinking about other systems too, such as ATM number pads or entry pads for security gate/secure door systems. What if each button on the ATM was also a very fast fingerprint sensor? (What if the ATM had a cleaning device built in?)

Re: Fingerprints are Usernames, not Passwords

#257

Earlier quoted context omitted.

It's a really neat question, and as a new-ish parent I've given it some thought. In fact, there's even another layer to it: shortly after birth, people tend to count in weeks rather than months. My guess at an answer is that human beings are more comfortable thinking about numbers that are small integers (between 1 and 20 or so?), and that (roughly speaking) we often want to be able to give a bit more precision than…

Chains & rods are what first sprang to mind, but I don't think they were ever common. The definition of 'furlong' from http://physics.info/system-english/ makes it seem like it could have been in common usage: Literally, the length of a furrow. A sensible length for farmers that later evolved into the acre, which is discussed later in this section. A standard furrow is 220 yards long or ⅛ mile Google's ngram tool mak…

Furlongs still are in common usage in certain applications. Horse racing, particularly.

Re: Fingerprints are Usernames, not Passwords

#258

I'm not so sure. How many people are motivated to dupe your fingerprints to get into your iPhone? How many of those people could conceivably get into your iPhone through other ways? Fingerprints are a nice way to keep almost everyone out of your device. And for the rest, well, I really doubt some other locking mechanism would've kept them out.

I'm sure 5s's are fetching at least $400 on the conservative side. If all I have to do is spend like $5 and follow a how-to on a website, I think a lot of people would be willing to make the investment.

It's not that easy. You've got to get a really good, clean, complete print of the correct finger and avoid damaging it during processing (nontrivial).

Re: Fingerprints are Usernames, not Passwords

#259
post #44
post #21

Earlier quoted context omitted.

That's an rather interesting idea. If you could get Cory Doctorow to write "The Day the Password Died" from your prompt, I'd be very happy. Synopsis: an evil government steals the private thoughts and passwords of its citizens, most of whom are unaware of the threat. A few paranoid individuals come up with increasingly bizarre biometric passwords, but the government has secretly approved unauthorized (and speedy) clo…

That would be pretty cool. I can't imagine that nobody else has thought of this idea before, though... What really scares me, though, is when we get to the point of not just being able to read thoughts, but being able to write them. How would you ever know that your memories and emotions have not been tampered with? As far as you know, you've always loved your corporate overlords, and would never do anything to work…

Isn't that the point of 1984?

The protagonist is unable to make a physical record, and so must trust his brain retain any proof of the government's wrongdoing.

However, the brain is a poor vessel for this - it can be manipulated and tortured to discount information. And so, Winston ends up loving Big Brother.

Paper and bits are what we rely upon; there is a reason eye-witness reports are trusted so little in comparison to physical evidence.

Re: Fingerprints are Usernames, not Passwords

#260
post #206

Earlier quoted context omitted.

You touch your iphone's screen to use it, right? Getting a latent print isn't exactly difficult.

Acquiring a high-DPI scan of a fingerprint from someone's phone, printing it to a sheet of plastic with a high-DPI laser printer, then making a copy of the print out of liquid latex doesn't sound easy unless you're in the business of pentesting. Taking a picture of someone (or lifting it from a social network) to access their device does sound relatively easy. If I was the kind of person who was worried about someone…

See the problem here is that a compromised fingerprint betrays more resources than the system it was meant to protect.

Your iPhone has a picture of your fingerprint inside of it now. It's just a picture, and it's likely a very good picture at that.

What happens when I swipe your phone for a second or two, plug it into my machine, and download the high-resolution picture of your fingerprint?

Do you use a fingerprint lock at home? If so, I've just broken into your home.

Do you use a fingerprint lock for the datacenter you administer? I've just gained access.

Do you own a registered gun? How'd you like me to commit a murder with your fingerprint on it?

This kind of attack is the missing piece of my argument. When someone figures out how to do this, these issues are going to become very important very quickly.

Let's suppose that Apple introduces a feature that syncs your fingerprint across many devices. How convenient, right? Let's say that means keeping all of your fingerprints on Apple servers. Let's now suppose that, like a credit card database, an attacker is able to obtain a leaked copy of the fingerprint database of every iPhone user. The recent touchid hack shows that fingerprints can be spoofed for high-end scanners. What then?

Sure, this scenario is very unlikely. I'm totally in slippery-slope land here.

But when we choose to turn up the dial on convenience to sacrifice more security, we must be prudent, carefully considering the consequences of our intentional ignorance.

Post reply on HN