Earlier quoted context omitted.
if it causes people to behave recklessly because they have the false impression of security, when they would otherwise have taken better custodianship of their device and their data, then yes ... it can be worse than nothing.
That shouldn't be an issue considering most people don't have a passcode set.
Chaos Computer Club breaks Apple TouchID
171–180 of 458 posts
Re: Chaos Computer Club breaks Apple TouchID
#172Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…
Touch ID is not "pretty good security" it's not even "good security" it's simply very bad security. Touch ID is better than nothing and that people use Touch ID instead of nothing is better than the current state but not by much and this definitely isn't a huge achievement. Which is really the biggest issue with Touch ID, it's advertised as such and people believe it.
Re: Chaos Computer Club breaks Apple TouchID
#173Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…
Touch ID is not "pretty good security" it's not even "good security" it's simply very bad security. Touch ID is better than nothing and that people use Touch ID instead of nothing is better than the current state but not by much and this definitely isn't a huge achievement. Which is really the biggest issue with Touch ID, it's advertised as such and people believe it.
I also bet, in 99.9999% or more of those cases, the attacker doesn't even attempt to bypass the security by faking the users fingerprint.
I'd also be willing to bet that these figures are substantially better than the current situation where people don't bother to lock their phone at all. People will use it because it's a gimmick, not because of it's security properties, but it will still work.
Re: Chaos Computer Club breaks Apple TouchID
#174Earlier quoted context omitted.
Or just someone skilled enough to place fake dna in his body such that the person taking the sample is fooled into taking it from the fake dna. Yes, this really happened - at least once that we know of: https://en.wikipedia.org/wiki/John_Schneeberger
Or someone just being careful with his DNA at the crime he commits, that then places someone else's DNA that he wants to frame?
Then again, I guess we've seen that you literally cannot be too paranoid.
Re: Chaos Computer Club breaks Apple TouchID
#175Earlier quoted context omitted.
That's a matter of opinion, not fact.
What's the opinion? Apple said you can use this to replace your password. No one had an iTunes Store account without a password before, so this would 100% be replacing a password.
I believe that's the opinion being referred to.
Re: Chaos Computer Club breaks Apple TouchID
#176Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…
Touch ID is not "pretty good security" it's not even "good security" it's simply very bad security. Touch ID is better than nothing and that people use Touch ID instead of nothing is better than the current state but not by much and this definitely isn't a huge achievement. Which is really the biggest issue with Touch ID, it's advertised as such and people believe it.
Re: Chaos Computer Club breaks Apple TouchID
#177Earlier quoted context omitted.
That's a matter of opinion, not fact.
What's the opinion? Apple said you can use this to replace your password. No one had an iTunes Store account without a password before, so this would 100% be replacing a password.
Re: Chaos Computer Club breaks Apple TouchID
#178Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…
Here's Apple's main marketing text on the subject: > Put your finger on the Home button, and just like that your iPhone unlocks. It’s a convenient and highly secure way to access your phone. Your fingerprint can also approve purchases from iTunes Store, the App Store, and the iBooks Store, so you don’t have to enter your password. It is definitely intended to replace passwords. Pretty good security would be to requir…
>You check your iPhone dozens and dozens of times a day, probably more. Entering a passcode each time just slows you down. But you do it because making sure no one else has access to your iPhone is important. With iPhone 5s, getting into your phone is faster, easier, and even a little futuristic. Introducing Touch ID — a new fingerprint identity sensor.
Put your finger on the Home button, and just like that your iPhone unlocks. It’s a convenient and highly secure way to access your phone. Your fingerprint can also approve purchases from iTunes Store, the App Store, and the iBooks Store, so you don’t have to enter your password. And Touch ID is capable of 360-degree readability. Which means no matter what its orientation — portrait, landscape, or anything in between — your iPhone reads your fingerprint and knows who you are. And because Touch ID lets you enroll multiple fingerprints, it knows the people you trust, too.
Re: Chaos Computer Club breaks Apple TouchID
#179Earlier quoted context omitted.
> It's one thing to leave fingerprints all around your environment, but there is now the potential to steal your biometrics over the internet. Correct me if I'm wrong, but the biometric data never leaves the device.
It's also not stored on the device. Hashes, not fingerprints, are stored. You need the fingerprints themselves to fake out the hardware.
For example, the obvious approach is to store fingerprint features, which will be then matched by any print that has the same features in the same positions. If you do a good enough job of generating the new print you might even be able to fool police investigations, since they compare prints the same way.
Re: Chaos Computer Club breaks Apple TouchID
#180Earlier quoted context omitted.
Yes. I anxiously await Gruber's lengthy post-mortem about the fingerprint reader being just as bad as all previous fingerprint readers, equal in number, length and enthusiasm to his previous posts about how wonderful and advanced it is.
I know folks love to have on Gruber, but looking at df.net I don't see where he has compared the security of TouchID to other fingerprint readers - rather he's compared the convenience and performance of TouchID to other fingerprint implementations, and I don't know that anything in the OP would, or should, change his assessment of that. (not an iPhone or Android user, at least not yet).
There are too many examples to pick from, but here's a recent one.
In his iPhone 5S review he rambles on about how Apple is an innovator and picks out the A7 procesor, TouchID and a new burst-mode camera feature:
"But the real innovation — there’s that word — is software, right there on the device itself, that makes it easy to select only the shots from those bursts that you really want to keep, and to throw away the rest."
Yet Samsung did the same thing for the S3 back in 2012.