Chaos Computer Club breaks Apple TouchID
201–210 of 458 posts
Re: Chaos Computer Club breaks Apple TouchID
#202Re: Chaos Computer Club breaks Apple TouchID
#203Earlier quoted context omitted.
> Just use brute force or dictionary attack over the wire. Given that most users use 4-digit pass codes, this can be done usually in minutes, almost always in less than an hour. It's clear you've never actually attempted this. The timeout between passcode entries increases with the number of consecutive failures. Get 10 wrong in a row, and the device is wiped (if the user has chosen that option). > Or, if your target…
I'll ignore the needless snark. > The timeout between passcode entries increases with the number of consecutive failures. Get 10 wrong in a row, and the device is wiped (if the user has chosen that option). Only if you're typing in pass codes to the lock screen, which isn't how its done. An attacker would instead image the flash, grab the Dkey from effaceable storage, and decrypt the filesystem. Indeed this is exactl…
Yep, as I suspected, you haven't done this ;) Please don't discuss how "simple" it is if you're getting your info from third parties. You can't image the flash. None of this works how you think it does, because the forensics toolkits left out a crucial detail in their marketing.
The dirty secret? You need a 0day bootrom exploit. The professional kits use the limera1n exploit, which was patched years ago.
Re: Chaos Computer Club breaks Apple TouchID
#204Earlier quoted context omitted.
Except where I live there is organized phone snatching. A crew of phone hackers hire drug addicts to yoink phones off transit riders and then pay them 10% of the value. They then go to work on the phone changing the IMEI and I would imagine easily bypassing this fingerprint auth. They make use of the data for fraud purposes and then wipe and sell the phone on the street, a block away from where I live outside a run d…
I don't think it's possible to change the IMEI on an iPhone at all, and "easily bypassing" touchID involves collecting the user's fingerprint, which I guess is not included in the drug addicts' service offerings.
Re: Chaos Computer Club breaks Apple TouchID
#205Earlier quoted context omitted.
Touch ID is not "pretty good security" it's not even "good security" it's simply very bad security. Touch ID is better than nothing and that people use Touch ID instead of nothing is better than the current state but not by much and this definitely isn't a huge achievement. Which is really the biggest issue with Touch ID, it's advertised as such and people believe it.
While I don't have data to back it up, I believe most Android users use the draw pattern to unlock method. This feature is absolutely trivial to defeat - you can simply hold the phone up to the light, see the trails of oil left on the phone, and follow that trail. People have done this to my own phone with just a few tries. TouchID represents a massive increase in security over draw pattern to unlock, and it's easier…
If somebody swipes on their homescreen, browse the web, etc, the trail would not be just the unlock pattern.
The exploit you're talking about may work if you get hold of the phone right after the user unlocks it since the trail only has the pattern.
Re: Chaos Computer Club breaks Apple TouchID
#206Earlier quoted context omitted.
> I think they're missing the point. The passcode on an iPhone defends against other people in your environment - family members, coworkers, roommates - getting your information opportunistically. It doesn't defend against hackers, the government, or even slightly savvy thieves. The Google Chrome Security team begs to differ [1]. According to them giving someone the illusion of security is bad. [1] https://news.ycomb…
Giving someone the illusion of security is bad because it displaces their understanding of security. An understanding of security will reveal that security is not a binary state of affairs. It's perfectly reasonable to trust known-imperfect mechanisms like the iPhone fingerprint reader to keep honest people honest and discourage ordinary muggers and thieves. I don't need military-grade access control for my personal…
It is perfectly reasonable to expect an application to provide more security than the user account provides because in the real world, we know that people don't always lock their computers. Not all applications are risky, but one that centralizes a users credentials is clearly so.
Pretending otherwise is simply not acknowledging the real world.
Re: Chaos Computer Club breaks Apple TouchID
#207I think trying to lift a usable fingerprint off a glass surface would be significantly more difficult than that.
Re: Chaos Computer Club breaks Apple TouchID
#208Reasonable technically informed paranoia is what made the NSA releases fairly unsurprising to me as well. My rule with security is that if it can be done, then it will be abused. It's basically a Murphy's law for humanity.
Trust nothing. Trust no one. Doubt everything.
Re: Chaos Computer Club breaks Apple TouchID
#209Earlier quoted context omitted.
Or someone just being careful with his DNA at the crime he commits, that then places someone else's DNA that he wants to frame?
That would work in the sort of Hollywood movie where the government has everyone's DNA on file. Then again, I guess we've seen that you literally cannot be too paranoid.
You don't have to have "everyone's DNA on file". It's actually pretty trivial even for your neighbor or whoever to get your DNA.
As for the police falsifying evidence, there's a wikipedia-long history of cases, in Europe, Latin America, Asia, etc. Especially in politically charged times, like the sixties and seventies. Heck, something like half of Italy's government in the 70's have been proved in later Italian courts to be involved in such things.
Re: Chaos Computer Club breaks Apple TouchID
#210They tried to make a fingerprint readers more sophisticated and added a temperature registers to avoid fakes or (more in more gruesome case - a cut off finger), but hackers managed to make so called rubber fingers or peel dead finger and fill with a warm salty water. Anything can be hacked. But I think they are missing the point. If Apple wanted its phones to be a secure gimmick at Pentagon - that was silly. But for…
The exact same arguments could be made for having crappy passwords, which, I might remind you, are defeated hundreds of thousands of times a day, at a massive cost to its victims.