Live data from Hacker News

Fingerprints are Usernames, not Passwords

blog.dustinkirkland.com

181–190 of 261 posts

Re: Fingerprints are Usernames, not Passwords

#181
post #139

Earlier quoted context omitted.

Or maybe a animated GIF image.

Animated gifs would today work. What if the camera focused on something behind you first and then the face? Would that bypass a 2D method?

On a camera with effectively infinite depth of field? Probably not.

Re: Fingerprints are Usernames, not Passwords

#182
post #79

All security is based on either something you know, something you have, something you are, or a combination of the three. - A username is something you know. - A password is something you know. - A pinpad is something you have. - A finger print is something you have.

- A finger print is something you are.

You can copy finger prints rather easily, they are something you have.

Re: Fingerprints are Usernames, not Passwords

#183

Earlier quoted context omitted.

What are people going to do when, in the all-too-near future, criminals begin sharing and selling databases of stolen high resolution finger prints? One theft isn't practical? How about a million? Driven by a never-ending pursuit of monetary gain via crime; with criminals always happy to conquer the latest technology wave. There's absolutely no reason to think that criminals won't amass substantial finger print recor…

OK, you are a criminal and got 1000 000 fingerprints. You can start collecting them right now, on every surface you have access too. Then what? You will print them all using whatever technology required to fool fingerprint scanner and try one by one? Wouldn't it be just easier to try and lift one off the device itself? > It's about a consumer shift to finger prints as a primary > security feature No. It's about shift…

The fingerprint databases would probably also include identity information.

Re: Fingerprints are Usernames, not Passwords

#184
Have there been any attempts to ascertain PINs by analyzing the finger residue left on touch screens? That strikes me as something that would be pretty easy (for an expert with the right gear), especially if patterns were used.

Re: Fingerprints are Usernames, not Passwords

#185
post #34

All these academic arguments about the security of fingerprints are interesting but completely are detached from the day-to-day use of TouchID. I've been using it for about a week or so now. It's incredibly convenient. It unlocks my phone almost instantly. It prevents random people near by phone from being unable to unlock it. If a thief got their hands on it, they'd have a few attempts to unlock it with a fake finge…

> a few attempts to unlock it with a fake fingerprint, and then they'd have to enter my code. And if they fail to enter my code 10 times, the phone is wiped. Are you saying that random people can pick up your phone when you go to the bathroom, touch the home button 3 times, and then enter "1111" 10 times, and wipe your phone? Is there some protection against this?

Well, you do have to explicitly turn that option on. It's in no means a default.

If you use the iPhone Configuration Utility, you can even reduce the attempts down 2 before it wipes itself.

I guess it's useful in circumstances where the data on the phone is more valuable than the phone itself.

Re: Fingerprints are Usernames, not Passwords

#186

Earlier quoted context omitted.

> a few attempts to unlock it with a fake fingerprint, and then they'd have to enter my code. And if they fail to enter my code 10 times, the phone is wiped. Are you saying that random people can pick up your phone when you go to the bathroom, touch the home button 3 times, and then enter "1111" 10 times, and wipe your phone? Is there some protection against this?

Protection against what ? That is the desired behaviour of most people. And if it isn't then you can simple disable the behaviour. It's not like you will lose data since it is backed up to iCloud.

I think you misunderstood. The person entering bogus passwords is not a thief, but an otherwise trusted prankster. For example, a brother.

Re: Fingerprints are Usernames, not Passwords

#187
post #34

All these academic arguments about the security of fingerprints are interesting but completely are detached from the day-to-day use of TouchID. I've been using it for about a week or so now. It's incredibly convenient. It unlocks my phone almost instantly. It prevents random people near by phone from being unable to unlock it. If a thief got their hands on it, they'd have a few attempts to unlock it with a fake finge…

An ideology of "Its good enough to thwart 99.9% of the population, therefore its good enough for me." is a very harmful ideology to have when it comes to security because you do nothing to deter mass adoption of the insecure technology. While an individual person might not be at that great of risk because the amount of crackers willing to exploit touchID is limited to a minute demographic of people, the real harm com…

Does this go for the locks on your front door as well? As in "nobody should have front door locks that aren't 100% secure even against eg. terrorists"?

Re: Fingerprints are Usernames, not Passwords

#188
post #82

Earlier quoted context omitted.

Clearly. http://www.theguardian.com/technology/2013/sep/27/no-nsa-iph...

Well, I've never heard anywhere that Apple was sharing the fingerprints with the NSA. As far as I know, nobody said that... It's just the obvious* default assumption. And the matter of default assumptions is that you need evidence that they are false. Apple denying it is no evidence. But yeah, the point about the microphone and camera stands. * And it is obvious, no point is arguing against that. When everybody makes…

"As far as I know, nobody said that"

The OP linked to an article which said that, which sourced from the article referenced by the link to the rebuttal I posted.

"And it is obvious, no point is arguing against that."

No, it's really not obvious. Apple made very specific claims about the functionality of their product. Unless you can prove those claims wrong, you're just spreading a conspiracy theory.

Re: Fingerprints are Usernames, not Passwords

#189
This is a great point, but I'd love to see a passcode system that isn't vulnarable.

The "swipe puzzle" things (I'm not sure what to call them.)? I've been able to see people enter them once and unlock their phone. Passcodes? Even if people used secure ones, with a combo of looking while they're entering it and the smudges it leaves, it's not that hard to get.

Those are the 2 most frequent models of password input I've seen, both flawed. Any ideas for a better one?

Re: Fingerprints are Usernames, not Passwords

#190
post #161
post #131

Earlier quoted context omitted.

> but can probably lift the print right off the phone itself What utter unmitigated rubbish. It is extremely unlikely that even a fully qualified CSI would be able to lift a full print from a mobile phone, let alone one that that can be reliably reproduced in the manner CCC described.

On release, people were saying it was unhackable. Molds were made that faked it within a week. You really want to bet that no one will make this work? With a target this high profile? My 5 year old son was quite literally dusting for fingerprints at the local science museum last weekend. We have some shockingly high fidelity prints of both our thumbs showing all the ridges. And all we had to do was squeeze a piece of…

It's amazing rant with any Apple story, there you are with an 'expert' opinion followed by a thinly veiled troll. I want to see your 5 year old son lift near perfect prints from a typical iPhone, no deliberate placing of prints mind you. I then want to see you recreate the CCC "hack" with the correct print. It's time to put up or shut up.
Post reply on HN