Earlier quoted context omitted.
Which is ironic coming from a company known to be sharing information directly with the NSA. Name one security technology that is 100% foolproof. They don't exist. So the point isn't to rely on one thing, but to rely on many things that, used in concert, increase the risk, complexity and cost associated with subverting the entire system--not its individual components.
I don't think I've seen anyone parry an appeal to authority with an ad hominem lately. Good one.
Chaos Computer Club breaks Apple TouchID
271–280 of 458 posts
Re: Chaos Computer Club breaks Apple TouchID
#272Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…
I feel like we just went through this very same drill with the Chrome team refusing to hide web site passwords behind a master password, something that all browsers, except Chrome, support. Given how stubborn the Chrome team has been in its handling of this situation, I think fighting that TouchId battle is going to be equally challenging.
Common sense is, sadly, not very common, not even among the security circles.
Re: Chaos Computer Club breaks Apple TouchID
#273Earlier quoted context omitted.
"you don’t have to enter your password" != "you don't need a password" As I understand it every now and again Apple will prompt you to enter your passcode/password, such as when you restart your device or if you haven't unlocked it in two days. Hardly a signal that passwords are done.
I love the psuedo lawyer speak in this thread
Re: Chaos Computer Club breaks Apple TouchID
#274Re: Chaos Computer Club breaks Apple TouchID
#275Re: Chaos Computer Club breaks Apple TouchID
#276I think they're missing the point. The passcode on an iPhone defends against other people in your environment - family members, coworkers, roommates - getting your information opportunistically. It doesn't defend against hackers, the government, or even slightly savvy thieves. Also, if a fingerprint sensor is significantly easier to use, and in practice will deter a class of privacy violations, it could increase over…
...the people closest to you in your environment ( kids, parents, spouse, boss, co-workers) are the ones who can most easily obtain your fingerprints...
Re: Chaos Computer Club breaks Apple TouchID
#277Earlier quoted context omitted.
Here's Apple's main marketing text on the subject: > Put your finger on the Home button, and just like that your iPhone unlocks. It’s a convenient and highly secure way to access your phone. Your fingerprint can also approve purchases from iTunes Store, the App Store, and the iBooks Store, so you don’t have to enter your password. It is definitely intended to replace passwords. Pretty good security would be to requir…
"you don’t have to enter your password" != "you don't need a password" As I understand it every now and again Apple will prompt you to enter your passcode/password, such as when you restart your device or if you haven't unlocked it in two days. Hardly a signal that passwords are done.
Re: Chaos Computer Club breaks Apple TouchID
#278If we've learned anything over the past few months, it is that security is an illusion when it comes to Google, Apple and Facebook. The fingerprint scanner is not intended to protect your personal data from being accessed by nefarious cyber-spooks or crackers. The $5 dollar wrench technique is fairly effective in bypassing such security anyway. The fingerprint scanner is there so that when your phone is nicked by a m…
Apple claims that "The technology within Touch ID is some of the most advanced hardware and software we've put in any device." [1]. This attack showed that increasing sensor resolution only requires increasing the resolution on the fake print to match. This attack is an interesting data point in the debate over using biometrics in access control systems. Apple was hyped to have introduced something new and exciting i…
Just to clarify, it wasn't just the increased resolution that was required here, but "latex milk", I assume to simulate a living finger, as well. It's not as simple as print-of-print = unlock.
Re: Chaos Computer Club breaks Apple TouchID
#279Earlier quoted context omitted.
While I don't have data to back it up, I believe most Android users use the draw pattern to unlock method. This feature is absolutely trivial to defeat - you can simply hold the phone up to the light, see the trails of oil left on the phone, and follow that trail. People have done this to my own phone with just a few tries. TouchID represents a massive increase in security over draw pattern to unlock, and it's easier…
Doesn't the trail get cleaned off when you put it in your pocket?
Re: Chaos Computer Club breaks Apple TouchID
#280Earlier quoted context omitted.
> That is definitely a significant improvement. Sure is a significant improvement for some people at least. http://t.co/EK3sdeloUX
Baseless FUD is OK as long as Linux ain't the target, right?
What operating system I prefer really has nothing to do with it, even if it is linux.
Posted from my iPhone, android, third mac mini, 2nd mac air, or first thinkpad who the fuck knows (or cares? oh you obviously)