Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

181–190 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#181

If we've learned anything over the past few months, it is that security is an illusion when it comes to Google, Apple and Facebook. The fingerprint scanner is not intended to protect your personal data from being accessed by nefarious cyber-spooks or crackers. The $5 dollar wrench technique is fairly effective in bypassing such security anyway. The fingerprint scanner is there so that when your phone is nicked by a m…

Apple claims that "The technology within Touch ID is some of the most advanced hardware and software we've put in any device." [1]. This attack showed that increasing sensor resolution only requires increasing the resolution on the fake print to match. This attack is an interesting data point in the debate over using biometrics in access control systems. Apple was hyped to have introduced something new and exciting i…

Well, since they've never put a fingerprint authentication system in their hardware, I think that their claim still holds...

Re: Chaos Computer Club breaks Apple TouchID

#182
post #127
post #7

Expected. Still much, much better security than no code at all. I will use it (with full knowledge of its downsides and tradeoffs) and it would behoove the CCC to not portray security as a binary state. (Just as much as it would behoove Apple to be truthful in their marketing.) Don't use it if thieves would consider going through all the effort of faking out the scanner. That's what I take from this no doubt valuable…

Not that expected. I know a lot of people were BSing about how much more secure Apple's fingerprint sensor was and how the usual techniques for faking a finger wouldn't work on it, including some security researchers.

I was disappointed to see that this hack shows the sensor isn't relying on the "microscopic capacitive surface" being claimed by Apple. So it's really just another CCD camera under the button?

Re: Chaos Computer Club breaks Apple TouchID

#183

Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…

To corroborate your point, here is the transcript from the 5S launch:

"The third feature is all about security. Now we have so much personal information on our devices that we want to protect. So we have to protect them. The most common wave of course is to set up a passcode. Simple four digit passcode or more complex one if you want. This is something you do, dozens of times a day to unlock and get access to your phone. Unfortunately, some people find that's too cumbersome and they don't set it up. In fact in our research about half of smartphone customers do not set up a passcode on the device and they really, really should. That's the team has worked so hard in the brand new technology to make this easy and fun to do."

http://www.earningsimpact.com/Transcript/83555/AAPL/Launch-o...

Re: Chaos Computer Club breaks Apple TouchID

#185
post #169

Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…

Touch ID is not "pretty good security" it's not even "good security" it's simply very bad security. Touch ID is better than nothing and that people use Touch ID instead of nothing is better than the current state but not by much and this definitely isn't a huge achievement. Which is really the biggest issue with Touch ID, it's advertised as such and people believe it.

>Touch ID is better than nothing and that people use Touch ID instead of nothing is better than the current state

That makes it great security.

Re: Chaos Computer Club breaks Apple TouchID

#186

Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…

Here's Apple's main marketing text on the subject: > Put your finger on the Home button, and just like that your iPhone unlocks. It’s a convenient and highly secure way to access your phone. Your fingerprint can also approve purchases from iTunes Store, the App Store, and the iBooks Store, so you don’t have to enter your password. It is definitely intended to replace passwords. Pretty good security would be to requir…

"you don’t have to enter your password" != "you don't need a password"

As I understand it every now and again Apple will prompt you to enter your passcode/password, such as when you restart your device or if you haven't unlocked it in two days. Hardly a signal that passwords are done.

Re: Chaos Computer Club breaks Apple TouchID

#187
post #146

Earlier quoted context omitted.

Really, how do you trivially break a passcode on an iOS device? There is a way that I know about, and it is very much non-trivial.

Just use brute force or dictionary attack over the wire. Given that most users use 4-digit pass codes, this can be done usually in minutes, almost always in less than an hour. Or, if your target is paranoid and uses a very long passcode, target the charger rather than the device itself. iOS assumes any physical device to which it is connected when unlocked is secure. Replace the usb brick with a small computer (e.g.…

> Just use brute force or dictionary attack over the wire. Given that most users use 4-digit pass codes, this can be done usually in minutes, almost always in less than an hour.

It's clear you've never actually attempted this. The timeout between passcode entries increases with the number of consecutive failures. Get 10 wrong in a row, and the device is wiped (if the user has chosen that option).

> Or, if your target is paranoid and uses a very long passcode, target the charger rather than the device itself. iOS assumes any physical device to which it is connected when unlocked is secure. Replace the usb brick with a small computer (e.g. Raspberry Pi) in a convincing looking Apple-esque case. Then wait until your target plugs in his iDevice and unlocks it. You can then dump the drive, or side load malicious code.

This no longer works on iOS 7. The user has to manually choose to trust the computer they're attached to prior to any communication going across the wire.

Re: Chaos Computer Club breaks Apple TouchID

#188

Earlier quoted context omitted.

> Most security experts that I know agree that if an intruder has physical access to a device, it can be considered compromised because it is just a matter of time. Anyone who says this is not a security expert. That hasn't been true since full disk encryption became available. A properly encrypted device is a brick if stolen, which is the only reason to have full disk encryption in the first place.

Most people outside of this community are not using disk encryption. With that said and the caveat that I am not an encryption expert myself: given an infinite amount of computing power and an infinite amount of time, can full disk encryption not be broken? If so, then it is just a question of computing power and time, not of whether it is possible to get to the data.

Combinatorical problems tend to grow in the amount of effort to try out all possible elements quite quickly, and quickly growing things in turns often hit physical limits. The following post on Security.Stackexchange explains it quite nicely; excerpt: the sun doesn't emit enough energy over its lifetime to power an extremely efficient computer able to try all combinations.

http://security.stackexchange.com/a/25878/25947

So basically we need some new form of computer (one that's not flipping individual physical bits), and not "just faster" ones, to crack certain encryptions by brute force.

Re: Chaos Computer Club breaks Apple TouchID

#189
post #50

Earlier quoted context omitted.

Even DNA can provide false negatives in the case of human chimeras.

Or just someone skilled enough to place fake dna in his body such that the person taking the sample is fooled into taking it from the fake dna. Yes, this really happened - at least once that we know of: https://en.wikipedia.org/wiki/John_Schneeberger

How in the world did he get off with only 4 years in prison after "repeatedly" raping multiple people?

Re: Chaos Computer Club breaks Apple TouchID

#190

If we've learned anything over the past few months, it is that security is an illusion when it comes to Google, Apple and Facebook. The fingerprint scanner is not intended to protect your personal data from being accessed by nefarious cyber-spooks or crackers. The $5 dollar wrench technique is fairly effective in bypassing such security anyway. The fingerprint scanner is there so that when your phone is nicked by a m…

Except where I live there is organized phone snatching. A crew of phone hackers hire drug addicts to yoink phones off transit riders and then pay them 10% of the value. They then go to work on the phone changing the IMEI and I would imagine easily bypassing this fingerprint auth. They make use of the data for fraud purposes and then wipe and sell the phone on the street, a block away from where I live outside a run down sketchy bar.

Police caught the "muggers" slipping the phones into faraday bags so they couldn't be remotely wiped which led them to the ringleaders. They were busted but I'm sure there's a new crew doing it

Post reply on HN