Just in time. Who knows how long these research projects stay legal in Germany.
Chaos Computer Club breaks Apple TouchID
141–150 of 458 posts
Re: Chaos Computer Club breaks Apple TouchID
#142At this rate, no method of security is secure.
The most secure computer is the one locked in a room and unplugged. There has never been a method of security that is secure. The first thing you learn when dealing with security is there are tradeoffs between opportunity, time, money. and usability.
But as you imply, the reason we don't use it is because the opportunity cost and hassle of using it are too high for many uses.
Re: Chaos Computer Club breaks Apple TouchID
#143Earlier quoted context omitted.
And now even DNA is being called into question. http://mobile.nytimes.com/2013/09/17/science/dna-double-take...
In addition to the chimeric qualities cited in the NYT article (I skimmed), IIRC some DNA sampling has in the past used and may still use a fairly limited profile of markers. The statistically likelihood of matches between distinct parties is in some cases well under the population of the world. Never read into it in detail, but I was left with the impression that "unique identifier" can be an over-statement/qualific…
In addition to that, there are problems with bias and statistical independence. A given marker is unlikely to be present in exactly 50% of the population, and to the extent that it isn't it can reduce the probability by that amount that a test match is a true match. Meanwhile the suspect pool for a given crime is likely to encompass several (perhaps many) members of the same extended family, who for the obvious reason are significantly more likely than random members of the world population to have the tested markers match one another. Even within a city you will generally see concentrations of specific ethnicities who may have a higher statistical incidence of specific genetic markers than other populations, which can screw up the numbers by an amount that historically hasn't even knowable because we don't have good numbers on the statistical incidence of specific markers within geographical populations.
The place where this is most pernicious is when they get a sample from a crime scene and run it against some "DNA database" to find a hit. Then everybody is talking about the probability that X suspect would match the DNA at the crime scene rather than the probability that someone in the database would match even if the actual perpetrator wasn't in the database.
Re: Chaos Computer Club breaks Apple TouchID
#144Much more convienient than a passcode with a little less security. I'd still use it unless I was a CIA agent.
How is it less security though? You don't have to follow someone for very long with a high zoom camera before you can get their passcode and that is a lot easier than duplicating their fingerprint. And yeh it is much much more convenient.
Re: Chaos Computer Club breaks Apple TouchID
#145Earlier quoted context omitted.
> I think they're missing the point. The passcode on an iPhone defends against other people in your environment - family members, coworkers, roommates - getting your information opportunistically. It doesn't defend against hackers, the government, or even slightly savvy thieves. The Google Chrome Security team begs to differ [1]. According to them giving someone the illusion of security is bad. [1] https://news.ycomb…
Which is ironic coming from a company known to be sharing information directly with the NSA. Name one security technology that is 100% foolproof. They don't exist. So the point isn't to rely on one thing, but to rely on many things that, used in concert, increase the risk, complexity and cost associated with subverting the entire system--not its individual components.
Re: Chaos Computer Club breaks Apple TouchID
#146iOS security is trivial to break if you have physical access to the device. TouchID (and passcodes) should be considered little more than a convenience, not a serious security measure.
Really, how do you trivially break a passcode on an iOS device? There is a way that I know about, and it is very much non-trivial.
Or, if your target is paranoid and uses a very long passcode, target the charger rather than the device itself. iOS assumes any physical device to which it is connected when unlocked is secure. Replace the usb brick with a small computer (e.g. Raspberry Pi) in a convincing looking Apple-esque case. Then wait until your target plugs in his iDevice and unlocks it. You can then dump the drive, or side load malicious code.
Re: Chaos Computer Club breaks Apple TouchID
#147Earlier quoted context omitted.
So, if this can be accomplished with keys, have you removed all the locks from your house? Do you rotate your locks every 3-6 months?
My front door does not have a picture of my key on it. My phone has tons of fingerprints though. It's a touch screen phone. One of those words is "touch" which clearly implies your finger coming in contact with it. Even if you wanted to use gloves you need special ones for it to work properly with the capacitive screen. Unless you are continuously wiping it (the screen, not the data) it will have you prints on it.
Does that mean you couldn't find my prints in other places? Sure. But I can probably find your keys in other places, too.
We know that SSL is generally not implemented properly, that the CAs are probably all hacked or subverted by the NSA, that the NSA may have developed backdoors to a number of the more popular encryption suites, but I don't hear anyone running around demanding Google or Facebook disable SSL.
If you are doing something that requires sufficient security that you don't want someone to access it via your fingerprint alone, add additional layers of security.
If you are doing something potentially incriminating ... don't do it on your freaking phone because it's probably been exploited in a dozen other ways by various authorities who can use it to find out most of what they need without being in physical possession of the phone anyway.
Most people aren't worried about the mafia or the CIA or the NSA. Most people don't even bother using a passcode, let alone a passphrase on their phones. If you can add something as easy to use as this, then it adds an additional layer of security against the casual abuse most people will find themselves subjected to (random people making calls from your phone, spouses spying on their email, etc.).
If you are worried about the CIA and the NSA, using a phone at all for anything is probably not in your best interest at this point.
Re: Chaos Computer Club breaks Apple TouchID
#148Earlier quoted context omitted.
You are overcomplicatimg things. The hypothetical cop could just smash your phone to pieces. Same result, less effort.
Not the same result at all. You now have lost your phone and the cop has to argue that you smashed it yourself out of spite. There may be more witnesses or evidence after smashing a phone. Presumably there are even phone company records showing when and where a device went dead. I am not a lawyer but it seems to me, 9 times out 10, the cop would prefer a cleaner result - they confiscate your device, and oops, when yo…
Re: Chaos Computer Club breaks Apple TouchID
#149They don't show if they can scan the finger print off the phone. I would imagine that it could be quite tricky to get that level of resolution.
I would like to see a complete hack purely based on a finger print on the phone.
Re: Chaos Computer Club breaks Apple TouchID
#150The "How to fake fingerprints" link [1], is one of the scariest things I have seen, given how simple it is, and how much we reply on fingerprints for linking people to crimes. BTW, for anyone who does not know about Chaos Computer Club (CCC) [2], they run a massive conference in EU. You can look at some of their talks @ http://media.ccc.de/ [1] http://dasalte.ccc.de/biometrie/fingerabdruck_kopieren?langu... [2] http:…
It's a bit old now but it's still as valid.