Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

201–210 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#202
post #68

Just in time. Who knows how long these research projects stay legal in Germany.

More context, for those of us not up-to-date on German politics?

Outcome of the elections. Merkel won. The CDU (Christian Democratic Union) isn't very Internet and hacker friendly.

Re: Chaos Computer Club breaks Apple TouchID

#203
post #198

Earlier quoted context omitted.

> Just use brute force or dictionary attack over the wire. Given that most users use 4-digit pass codes, this can be done usually in minutes, almost always in less than an hour. It's clear you've never actually attempted this. The timeout between passcode entries increases with the number of consecutive failures. Get 10 wrong in a row, and the device is wiped (if the user has chosen that option). > Or, if your target…

I'll ignore the needless snark. > The timeout between passcode entries increases with the number of consecutive failures. Get 10 wrong in a row, and the device is wiped (if the user has chosen that option). Only if you're typing in pass codes to the lock screen, which isn't how its done. An attacker would instead image the flash, grab the Dkey from effaceable storage, and decrypt the filesystem. Indeed this is exactl…

"Only if you're typing in pass codes to the lock screen, which isn't how its done. An attacker would instead image the flash, grab the Dkey from effaceable storage, and decrypt the filesystem. Indeed this is exactly how professional iOS forensic analysis kits work. This will get you access to SMS, photos, and anything else that doesn't fall under Data Protection."

Yep, as I suspected, you haven't done this ;) Please don't discuss how "simple" it is if you're getting your info from third parties. You can't image the flash. None of this works how you think it does, because the forensics toolkits left out a crucial detail in their marketing.

The dirty secret? You need a 0day bootrom exploit. The professional kits use the limera1n exploit, which was patched years ago.

Re: Chaos Computer Club breaks Apple TouchID

#204

Earlier quoted context omitted.

Except where I live there is organized phone snatching. A crew of phone hackers hire drug addicts to yoink phones off transit riders and then pay them 10% of the value. They then go to work on the phone changing the IMEI and I would imagine easily bypassing this fingerprint auth. They make use of the data for fraud purposes and then wipe and sell the phone on the street, a block away from where I live outside a run d…

I don't think it's possible to change the IMEI on an iPhone at all, and "easily bypassing" touchID involves collecting the user's fingerprint, which I guess is not included in the drug addicts' service offerings.

You can swap the logic board. They sell these for $80 or just trade with somebody who has a backlisted IMEI in UK/Australia for your US blacklisted phone. There's a bunch of crime forums that offer this service

Re: Chaos Computer Club breaks Apple TouchID

#205
post #169

Earlier quoted context omitted.

Touch ID is not "pretty good security" it's not even "good security" it's simply very bad security. Touch ID is better than nothing and that people use Touch ID instead of nothing is better than the current state but not by much and this definitely isn't a huge achievement. Which is really the biggest issue with Touch ID, it's advertised as such and people believe it.

While I don't have data to back it up, I believe most Android users use the draw pattern to unlock method. This feature is absolutely trivial to defeat - you can simply hold the phone up to the light, see the trails of oil left on the phone, and follow that trail. People have done this to my own phone with just a few tries. TouchID represents a massive increase in security over draw pattern to unlock, and it's easier…

People actually do other actions on their phone after unlocking it.

If somebody swipes on their homescreen, browse the web, etc, the trail would not be just the unlock pattern.

The exploit you're talking about may work if you get hold of the phone right after the user unlocks it since the trail only has the pattern.

Re: Chaos Computer Club breaks Apple TouchID

#206

Earlier quoted context omitted.

> I think they're missing the point. The passcode on an iPhone defends against other people in your environment - family members, coworkers, roommates - getting your information opportunistically. It doesn't defend against hackers, the government, or even slightly savvy thieves. The Google Chrome Security team begs to differ [1]. According to them giving someone the illusion of security is bad. [1] https://news.ycomb…

Giving someone the illusion of security is bad because it displaces their understanding of security. An understanding of security will reveal that security is not a binary state of affairs. It's perfectly reasonable to trust known-imperfect mechanisms like the iPhone fingerprint reader to keep honest people honest and discourage ordinary muggers and thieves. I don't need military-grade access control for my personal…

Teaching users to create separate accounts might be better, but so would any number of impractical suggestions.

It is perfectly reasonable to expect an application to provide more security than the user account provides because in the real world, we know that people don't always lock their computers. Not all applications are risky, but one that centralizes a users credentials is clearly so.

Pretending otherwise is simply not acknowledging the real world.

Re: Chaos Computer Club breaks Apple TouchID

#207
Its an improvement. The typical pass has 4 characters so 10,000 possible combinations. Doing about 1 per second would find the password in the worst case scenario in about 3 hours; simply by trying all possible combinations.

I think trying to lift a usable fingerprint off a glass surface would be significantly more difficult than that.

Re: Chaos Computer Club breaks Apple TouchID

#208
This is fairly unsurprising to anyone with even a modicum of understanding as to how these sensors actually work and the decade long history of researchers breaking them with Photoshop, gummy bears, latex and spit. What concerns me more is the claims they make about the "secure enclave". Maybe I'm just paranoid, but historically if data does exist, then it will be abused. The TouchID sensor, coupled with its strong bullshit security claims by Apple, in addition to the claims made about how data is never sent by Apple because of the "secure enclave", makes me think that this would be a very convenient way to create a global voluntary fingerprint database tied to every aspect of everyone's identity without freaking anyone out. If a government were to release something like this, they'd be sued into the ground and screamed against for breaking core privacy covenants. But when Apple does it's just brilliant and revolutionary.

Reasonable technically informed paranoia is what made the NSA releases fairly unsurprising to me as well. My rule with security is that if it can be done, then it will be abused. It's basically a Murphy's law for humanity.

Trust nothing. Trust no one. Doubt everything.

Re: Chaos Computer Club breaks Apple TouchID

#209

Earlier quoted context omitted.

Or someone just being careful with his DNA at the crime he commits, that then places someone else's DNA that he wants to frame?

That would work in the sort of Hollywood movie where the government has everyone's DNA on file. Then again, I guess we've seen that you literally cannot be too paranoid.

>That would work in the sort of Hollywood movie where the government has everyone's DNA on file.

You don't have to have "everyone's DNA on file". It's actually pretty trivial even for your neighbor or whoever to get your DNA.

As for the police falsifying evidence, there's a wikipedia-long history of cases, in Europe, Latin America, Asia, etc. Especially in politically charged times, like the sixties and seventies. Heck, something like half of Italy's government in the 70's have been proved in later Italian courts to be involved in such things.

Re: Chaos Computer Club breaks Apple TouchID

#210

They tried to make a fingerprint readers more sophisticated and added a temperature registers to avoid fakes or (more in more gruesome case - a cut off finger), but hackers managed to make so called rubber fingers or peel dead finger and fill with a warm salty water. Anything can be hacked. But I think they are missing the point. If Apple wanted its phones to be a secure gimmick at Pentagon - that was silly. But for…

The exact same arguments could be made for having crappy passwords, which, I might remind you, are defeated hundreds of thousands of times a day, at a massive cost to its victims.

I don't see hundreds of thousands of fingerprints being lifted from people to fabricate 2400 dpi fake fingers 'every day'.
Post reply on HN