Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

291–300 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#291

This isn't new, some other guy broke TouchId by making a fake finger from gelatin and soy sauce. http://blog.fortinet.com/iPhone-5s--Basic-Fingerprint-Replic...

It seems that that guy directly made a 'copy' of his own fingerprint in a mold. I agree that it is breaking TouchId, but the CCC did a more realistic crack: making a fake fingerprint without the person's finger.

He was not able to use the moulded version of his finger to access Touch ID. Instead he had to "enrol" his fake finger as a new finger, and from that point was able to unlock the phone.

Re: Chaos Computer Club breaks Apple TouchID

#292
post #226
post #140

Earlier quoted context omitted.

> Fingerprint scanning is absolutely better than a pass code How often can you change your fingerprint? I can change my pass code virtually an infinite number of times. How often do you inadvertently leave your pass code in random places just by touching things? A good pass code is absolutely better than fingerprint scanning.

Even worse: Other manufacturers will jump ship and this sort of device becomes omnipresent on smartphones. Probably, apps will get access to capture raw prints themselves at some time. Someone will start to store real and unhashed fp's in their database. As happening frequently with databases containing CC numbers (and even CC pins), that DB will eventually get copied and accessible on the net. Buying one's fp data w…

> Probably, apps will get access to capture raw prints themselves at some time.

Any company that designs their hardware so this is possible deserves the suit they'll get.

Re: Chaos Computer Club breaks Apple TouchID

#293

Earlier quoted context omitted.

Nobody has been able to use those low quality fingerprints to defeat TouchID.

I wouldn't count on that. See https://twitter.com/dotMudge/status/381900643415240704

That picture shows a carefully polished phone into which someone has meticulously placed 5 careful fingerprints - as if they were being taken at a police station, nothing like the fingerprints you get in normal use.

Re: Chaos Computer Club breaks Apple TouchID

#294

Earlier quoted context omitted.

How is it less security though? You don't have to follow someone for very long with a high zoom camera before you can get their passcode and that is a lot easier than duplicating their fingerprint. And yeh it is much much more convenient.

The Touch ID is less secure because you can force a person to put their fingerprint to unlock their own phone. Forcing the passcode out of someone can prove more difficult and the phone will wipe itself after 10 tries (if you have that feature enabled). I could steal your phone and manage to unlock in the process by taking your hand and unlocking the phone before walking away, somewhat more difficult to do with a pas…

You'd still have to force the correct finger, and Touch ID requires a passcode after five incorrect tries.

Re: Chaos Computer Club breaks Apple TouchID

#295

Earlier quoted context omitted.

Gruber is an ignorant fanboy. There are too many examples to pick from, but here's a recent one. In his iPhone 5S review he rambles on about how Apple is an innovator and picks out the A7 procesor, TouchID and a new burst-mode camera feature: "But the real innovation — there’s that word — is software, right there on the device itself, that makes it easy to select only the shots from those bursts that you really want…

So rather than addressing the point, you attack him on something completely different. Presumably because there are actually no examples where he's been wrong about TouchID.

No, I couldn't be bothered because the man writes guff.

http://daringfireball.net/2013/09/the_iphone_5s_and_5c

> "You know how iOS touch latency and scrolling performance have always been far ahead of its competition? The way you could just tell that internally, Apple had uncompromising standards for how responsive these things needed to be? That’s what Touch ID is like — it’s to all previous fingerprint scanners I’ve seen what the original iPhone was to previous touchscreen computers."

Make that fawning guff. Convenient that he forgets the uncompromising standards of Apple Maps.

> "Touch ID’s extraordinary performance and accuracy fit right into that story."

No benchmarks or comparisons to justify this hype compared to other fingerprint scanners. How do we know it's not the same as a cheap $1 RF scanner from China?

> " a complete experience hosted entirely on the device. Your fingerprint data is not just “not stored in iCloud yet”, it is not stored in iCloud by design, and according to my sources, never will be."

Rubbish. He knows nothing about Apple's roadmap. He always cites his inside "sources" yet he has NEVER broken any story where he had the lead on a scoop. Not on any products or corporate announcements.

I don't care what an armchair blogger thinks about TouchID. I do however care what the Chaos Computer Club thinks because they actually know what they are talking about.

Re: Chaos Computer Club breaks Apple TouchID

#296

Earlier quoted context omitted.

That would work in the sort of Hollywood movie where the government has everyone's DNA on file. Then again, I guess we've seen that you literally cannot be too paranoid.

> That would work in the sort of Hollywood movie where the government has everyone's DNA on file. You don't have to have "everyone's DNA on file". It's actually pretty trivial even for your neighbor or whoever to get your DNA. As for the police falsifying evidence, there's a wikipedia-long history of cases, in Europe, Latin America, Asia, etc. Especially in politically charged times, like the sixties and seventies. H…

> You don't have to have "everyone's DNA on file". It's actually pretty trivial even for your neighbor or whoever to get your DNA.

Sorry, I wasn't clear. I can dump a gallon of your blood and semen onto a dead guy in an alley, but how would the government trace that blood and semen back to you?

Re: Chaos Computer Club breaks Apple TouchID

#297
I am not impressed by this so-called hack at all. This is like people expecting encryption to solve both authenticity, integrity and confidentiality altogether by doing c = E(p,k). We want to see real hack as in actually bypass the system without any fingerprint, or a way to forge a fingerprint.

Re: Chaos Computer Club breaks Apple TouchID

#298

Earlier quoted context omitted.

Baseless FUD is OK as long as Linux ain't the target, right?

Where the fuck did that come from? It is neither baseless or FUD. That fingerprint will be sent over the wire at some point and the NSA will gladly pick it up. How you think otherwise is beyond me. What operating system I prefer really has nothing to do with it, even if it is linux. Posted from my iPhone, android, third mac mini, 2nd mac air, or first thinkpad who the fuck knows (or cares? oh you obviously)

It's fud until you or someone else posts evidence that the fingerprint is sent over the wire, or that Apple intends to do the same (for example, code that sends the fingerprint that awaits activation by a third party). You're not going to be able to do that. It's shameful that you can't even recognize the fudishness of what you posted, especially if Linux actually is your operating system of choice and you have been through the fud wars of the late nineties and early two thousands (that was only a guess on my part).

Re: Chaos Computer Club breaks Apple TouchID

#299

Earlier quoted context omitted.

Baseless FUD is OK as long as Linux ain't the target, right?

Where the fuck did that come from? It is neither baseless or FUD. That fingerprint will be sent over the wire at some point and the NSA will gladly pick it up. How you think otherwise is beyond me. What operating system I prefer really has nothing to do with it, even if it is linux. Posted from my iPhone, android, third mac mini, 2nd mac air, or first thinkpad who the fuck knows (or cares? oh you obviously)

Firstly nobody cares what hardware you have. It doesn't make what you say any more or less accurate.

Which in this case doesn't matter because you're talking complete nonsense. Apple does not send your fingerprint over the wire.

Re: Chaos Computer Club breaks Apple TouchID

#300

Earlier quoted context omitted.

So rather than addressing the point, you attack him on something completely different. Presumably because there are actually no examples where he's been wrong about TouchID.

No, I couldn't be bothered because the man writes guff. http://daringfireball.net/2013/09/the_iphone_5s_and_5c > "You know how iOS touch latency and scrolling performance have always been far ahead of its competition? The way you could just tell that internally, Apple had uncompromising standards for how responsive these things needed to be? That’s what Touch ID is like — it’s to all previous fingerprint scanners I’v…

You haven't actually made any points at all. You've just called him names and added some dismissive words after a few quotes from him. You don't have to convince anyone that you dislike Gruber. That much is obvious.
Post reply on HN