Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

221–230 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#221
post #87

Earlier quoted context omitted.

You leave finger prints on the phone. Just snap a photo with a decent camera - it's probably enough detail. Print it. Stick some latex or glue on it (literally available everywhere). That's it . This is not rocket science or time consuming like brute forcing. You don't even have to shoulder-surf to catch their password.

Importantly, this has been demonstrated. The CCC has been doing it for years and published a howto with material costs in the low one-digit Euro range. http://translate.google.com/translate?sl=de&tl=en&js=n&prev=...

Actually it hasn't been demonstrated at all. They dusted a carefully made high quality fingerprint to defeat TouchID, not an opportunistic one taken from something an unwitting victim left behind.

Until they do that, this doesn't really indicate much about how weak TouchID is in the real world.

Re: Chaos Computer Club breaks Apple TouchID

#222

Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…

Right. Yesterday, people clamored for a browser API to allow for that stuff to login, now that it is broken it has magically morphed into a mere 'convenience feature', a sidenote, a little fix.

(Of course, this post ends with Apple has succeeded. Sigh.)

Re: Chaos Computer Club breaks Apple TouchID

#223

Earlier quoted context omitted.

It's also not stored on the device. Hashes, not fingerprints, are stored. You need the fingerprints themselves to fake out the hardware.

Rare is the phone without the owner's fingerprints stored all over it.

Nobody has been able to use those low quality fingerprints to defeat TouchID.

Re: Chaos Computer Club breaks Apple TouchID

#224

Its an improvement. The typical pass has 4 characters so 10,000 possible combinations. Doing about 1 per second would find the password in the worst case scenario in about 3 hours; simply by trying all possible combinations. I think trying to lift a usable fingerprint off a glass surface would be significantly more difficult than that.

No, each failure increases the time between tries until you brick the phone.

Re: Chaos Computer Club breaks Apple TouchID

#225
post #127
post #7

Expected. Still much, much better security than no code at all. I will use it (with full knowledge of its downsides and tradeoffs) and it would behoove the CCC to not portray security as a binary state. (Just as much as it would behoove Apple to be truthful in their marketing.) Don't use it if thieves would consider going through all the effort of faking out the scanner. That's what I take from this no doubt valuable…

Not that expected. I know a lot of people were BSing about how much more secure Apple's fingerprint sensor was and how the usual techniques for faking a finger wouldn't work on it, including some security researchers.

Those techniques still haven't been shown to work in practice because CCC was only ago to unlock the device using a carefully made high quality print, not one lifted in an ecologically valid situation.

What matters is the rate at which copies of real prints are rejected, not the fact that one carefully made print can be made to work.

Re: Chaos Computer Club breaks Apple TouchID

#226
post #140

Earlier quoted context omitted.

Yes, we often say security and think it means total protection. It doesn't. Its rare to see any security feature that cannot be bypassed or broken by some means. This is why we implement security in layers. If it were a binary state then a single layer would be sufficient. The idea is to make it so difficult to break through every layer of security that it becomes impractical but there will always be someone who does…

> Fingerprint scanning is absolutely better than a pass code How often can you change your fingerprint? I can change my pass code virtually an infinite number of times. How often do you inadvertently leave your pass code in random places just by touching things? A good pass code is absolutely better than fingerprint scanning.

Even worse: Other manufacturers will jump ship and this sort of device becomes omnipresent on smartphones.

Probably, apps will get access to capture raw prints themselves at some time. Someone will start to store real and unhashed fp's in their database. As happening frequently with databases containing CC numbers (and even CC pins), that DB will eventually get copied and accessible on the net.

Buying one's fp data will become possible at some point.

Re: Chaos Computer Club breaks Apple TouchID

#227
post #205

Earlier quoted context omitted.

While I don't have data to back it up, I believe most Android users use the draw pattern to unlock method. This feature is absolutely trivial to defeat - you can simply hold the phone up to the light, see the trails of oil left on the phone, and follow that trail. People have done this to my own phone with just a few tries. TouchID represents a massive increase in security over draw pattern to unlock, and it's easier…

People actually do other actions on their phone after unlocking it. If somebody swipes on their homescreen, browse the web, etc, the trail would not be just the unlock pattern. The exploit you're talking about may work if you get hold of the phone right after the user unlocks it since the trail only has the pattern.

True enough, there is other "noise" on the phone, in the form of point-like finger prints, and even other trails. But you're imagining a blank phone, where you have to try and discern one trail from another. Now turn the phone on, and the unlock background appears. Which trails intersect all of the dots of the unlock background?

It's much easier that you imagine. I've been using my phone as I normally do throughout the day, and I can see the unlock pattern clearly on the phone.

Re: Chaos Computer Club breaks Apple TouchID

#229

Earlier quoted context omitted.

And now even DNA is being called into question. http://mobile.nytimes.com/2013/09/17/science/dna-double-take...

In addition to the chimeric qualities cited in the NYT article (I skimmed), IIRC some DNA sampling has in the past used and may still use a fairly limited profile of markers. The statistically likelihood of matches between distinct parties is in some cases well under the population of the world. Never read into it in detail, but I was left with the impression that "unique identifier" can be an over-statement/qualific…

I thought they used restriction digests with gel electrophoresis, I'm pretty sure full genomic sequencing would be too expensive.

Re: Chaos Computer Club breaks Apple TouchID

#230
A further argument against biometrics, for those in the United States, is that your "right to silence" (under the 5th amendment) doesn't protect you against the government compelling you to use your fingerprint to unlock something (however it does protect you against revealing a PIN code)...
Post reply on HN