Earlier quoted context omitted.
Frontline had an excellent piece on the (lack of) reliability behind most of crime forensics. Fingerprints in particular are mentioned as being very unreliable and unscientific. The only scientifically rigorous piece of "CSI" is DNA matching. http://www.pbs.org/wgbh/pages/frontline/real-csi/
Maybe we should lick the iPhone to provide accurate DNA biometric lol
Chaos Computer Club breaks Apple TouchID
131–140 of 458 posts
Re: Chaos Computer Club breaks Apple TouchID
#132Earlier quoted context omitted.
I have accidentally seen basically all of my friends' passcodes as they type it in at bars etc. I could get into their phones easily. And your friends could change their password 365 times per year every year for the rest of their lives. With fingerprints, they get 10 password changes.
20 if they use their toes.
Re: Chaos Computer Club breaks Apple TouchID
#133Were people saying that this was secure? I thought it was just another fancy unlocking method like Google's "use your face to unlock"
"As for the tech itself, Rogers explains fingerprint scanning as a whole is more secure than the four-digit passcode. Copying someone's fingerprints remains a cumbersome process, not to mention pricey -- as much as $200,000, by some estimates."
Edit - and http://daringfireball.net/linked/2013/09/12/5s-fingerprint-s... which someone linked elsewhere in this discussion:
" And like the sensor in the iPhone 5S, the sensors ... can detect the ridge and valley pattern of your fingerprint not from the layer of dead skin on the outside of your finger (which a fake finger can easily replicate), but from the living layer of skin under the surface of your finger, using an RF signal. This will protect you from thieves trying to chop off your finger when they mug you for your phone (assuming they’re tech-literate thieves, of course), as well as from people with fake fingers using the fingerprint they lifted from your phone screen."
Re: Chaos Computer Club breaks Apple TouchID
#134Earlier quoted context omitted.
It is considerably harder to fake.
Considerably harder? From the article: "In reality, Apple's sensor has just a higher resolution compared to the sensors so far. So we only needed to ramp up the resolution of our fake",
Re: Chaos Computer Club breaks Apple TouchID
#135Expected. Still much, much better security than no code at all. I will use it (with full knowledge of its downsides and tradeoffs) and it would behoove the CCC to not portray security as a binary state. (Just as much as it would behoove Apple to be truthful in their marketing.) Don't use it if thieves would consider going through all the effort of faking out the scanner. That's what I take from this no doubt valuable…
Not that expected. I know a lot of people were BSing about how much more secure Apple's fingerprint sensor was and how the usual techniques for faking a finger wouldn't work on it, including some security researchers.
Re: Chaos Computer Club breaks Apple TouchID
#136If we've learned anything over the past few months, it is that security is an illusion when it comes to Google, Apple and Facebook. The fingerprint scanner is not intended to protect your personal data from being accessed by nefarious cyber-spooks or crackers. The $5 dollar wrench technique is fairly effective in bypassing such security anyway. The fingerprint scanner is there so that when your phone is nicked by a m…
> The $5 dollar wrench technique I prefer Schneier's original rubber hose technique . Leaves fewer broken bones and bruises, but just as effective.
Re: Chaos Computer Club breaks Apple TouchID
#137Expected. Still much, much better security than no code at all. I will use it (with full knowledge of its downsides and tradeoffs) and it would behoove the CCC to not portray security as a binary state. (Just as much as it would behoove Apple to be truthful in their marketing.) Don't use it if thieves would consider going through all the effort of faking out the scanner. That's what I take from this no doubt valuable…
Not that expected. I know a lot of people were BSing about how much more secure Apple's fingerprint sensor was and how the usual techniques for faking a finger wouldn't work on it, including some security researchers.
Re: Chaos Computer Club breaks Apple TouchID
#138Earlier quoted context omitted.
It's not as useless as all that. Assuming Apple has properly used their key derivation function, and the phone locks you out after ~10 failed attempts, and there's no way to access a locked phone's data, then a four digit passcode is actually quite secure.
A KDF wouldn't help with a 4 digit PIN
Re: Chaos Computer Club breaks Apple TouchID
#139Re: Chaos Computer Club breaks Apple TouchID
#140Expected. Still much, much better security than no code at all. I will use it (with full knowledge of its downsides and tradeoffs) and it would behoove the CCC to not portray security as a binary state. (Just as much as it would behoove Apple to be truthful in their marketing.) Don't use it if thieves would consider going through all the effort of faking out the scanner. That's what I take from this no doubt valuable…
Yes, we often say security and think it means total protection. It doesn't. Its rare to see any security feature that cannot be bypassed or broken by some means. This is why we implement security in layers. If it were a binary state then a single layer would be sufficient. The idea is to make it so difficult to break through every layer of security that it becomes impractical but there will always be someone who does…
How often can you change your fingerprint? I can change my pass code virtually an infinite number of times. How often do you inadvertently leave your pass code in random places just by touching things?
A good pass code is absolutely better than fingerprint scanning.