Live data from Hacker News

Apple Opens Up Touch ID To All Apps

techcrunch.com

1–10 of 23 posts

Re: Apple Opens Up Touch ID To All Apps

#3
post #2

This is going to be a big game changer for 2 factor authentication. No longer will you have to deal with a series of numbers, but should be able to just auth with your phone.

To ask a silly question - how? 2FA apps like Authy don't communicate with the service they provide for. An app per 2FA application would be extremely clunky.

Re: Apple Opens Up Touch ID To All Apps

#5
I'm still creeped out by Touch ID (not this opening up, just Touch ID in general): The recent Snowden files revealed that the NSA actively searches for and indexes pictures of faces and fingerprints.

I doubt this is 100% secure (since all the code, including the TouchID code can be updated in iOS updates, you can add a leak function to a future iOS update).

When that happens, an attacker can nicely cross-reference your fingerprint with all the other data.

Anybody else feel that way?

Re: Apple Opens Up Touch ID To All Apps

#6
I'll be interested to see how this is used. I've never liked biometrics as a password, as once it is compromised, it cannot be changed. They are much more useful as a username, in my opinion. Does anyone here have any specific uses in mind?

Re: Apple Opens Up Touch ID To All Apps

#7
post #2

This is going to be a big game changer for 2 factor authentication. No longer will you have to deal with a series of numbers, but should be able to just auth with your phone.

It won't. Even your grandmother can fool a fingerprint scanner. https://www.youtube.com/watch?v=geTgSzrKYdc

Re: Apple Opens Up Touch ID To All Apps

#8
post #5

I'm still creeped out by Touch ID (not this opening up, just Touch ID in general): The recent Snowden files revealed that the NSA actively searches for and indexes pictures of faces and fingerprints. I doubt this is 100% secure (since all the code, including the TouchID code can be updated in iOS updates, you can add a leak function to a future iOS update). When that happens, an attacker can nicely cross-reference yo…

Just like you don't store a plaintext password, neither does TouchID store your fingerprint as anything recognizable - it's stored as a hashed and salted representation of your fingerprint. I'd venture to guess that it's device specific too, I doubt that your fingerprint hash stored on one phone is identical to the same fingerprint hash stored on a different phone.

Check out the whitepaper here: http://images.apple.com/iphone/business/docs/iOS_Security_Fe... if you're curious about details.

Re: Apple Opens Up Touch ID To All Apps

#9
post #5

I'm still creeped out by Touch ID (not this opening up, just Touch ID in general): The recent Snowden files revealed that the NSA actively searches for and indexes pictures of faces and fingerprints. I doubt this is 100% secure (since all the code, including the TouchID code can be updated in iOS updates, you can add a leak function to a future iOS update). When that happens, an attacker can nicely cross-reference yo…

I'd be more worried about the camera, microphone, and GPS that every iPhone has.
Post reply on HN