Live data from Hacker News

Apple Opens Up Touch ID To All Apps

techcrunch.com

21–23 of 23 posts

Re: Apple Opens Up Touch ID To All Apps

#21
post #18
post #14

Earlier quoted context omitted.

Thanks for the link! Apple sent out at least 1 update to TouchID as part of a regular iOS update. In my view, from a few miles up, the fact that you can update TouchID doesn't install a lot of confidence in this tech. Apple can change its workings, and it can also interface with TouchID from outside in order to update it. Would you care to elaborate why you're still sure that Apple (or the NSA) couldn't change TouchI…

Do you have a link to the touchID update? Because there's touchID the software, and touchID the hardware. The software interfaces with the actual circuitry but can still only basically say "can you please encrypt this?" and "can you please decrypt this", in addition to saying "hey was that fingerprint valid?" - that's it. Even the OS-level software doesn't have access to fingerprint data. Heck, even the physical WIRE…

Sure:

http://support.apple.com/kb/DL1736

"Further improvements to Touch ID fingerprint recognition".

TouchID was updated in system updates 7.0.1, 7.1 and 7.11:

https://en.wikipedia.org/wiki/IOS_7#7.0.1

Re: Apple Opens Up Touch ID To All Apps

#22
post #20
post #17

Earlier quoted context omitted.

Why does it scare you that they put out an update to change how they work with what is essentially irreversible hashes of the original high resolution scan of your fingerprints?

Because those hashes, when leaked to an outside party with a big database of fingerprints (say, the NSA), can be easily be combined to find matches in that database and identify somebody. Hashes don't solve all the problems, cmelbye, the identifying info is still there!

If the NSA gets access to your phone, there are hundreds of easier ways to identify who you are than having to go through the schlep of reconstructing your fingerprint.

Re: Apple Opens Up Touch ID To All Apps

#23
post #20

Earlier quoted context omitted.

Because those hashes, when leaked to an outside party with a big database of fingerprints (say, the NSA), can be easily be combined to find matches in that database and identify somebody. Hashes don't solve all the problems, cmelbye, the identifying info is still there!

If the NSA gets access to your phone, there are hundreds of easier ways to identify who you are than having to go through the schlep of reconstructing your fingerprint.

You did not understand me correctly. The problem is that this can be done remotely, over the air, even when you're not in the US.
Post reply on HN