Live data from Hacker News

Apple’s Fingerprint ID May Mean You Can’t ‘Take the Fifth’

wired.com

31–40 of 141 posts

Re: Apple’s Fingerprint ID May Mean You Can’t ‘Take the Fifth’

#32
post #4

In practice, it might have the opposite effect. Currently, 4-digit PINs are (presumably) brute-forceable and the alternative of entering a longer, cryptographically-secure password every time you want to use your phone is impractical, so it doesn't really matter whether you can be legally compelled to divulge your PIN or not. However, with a fingerprint ID, you can now use a cryptographically strong password to encry…

Are you sure you can brute force the PIN? I thought the iPhone will enforce a waiting period after too many bad entries.

Are you sure you can brute force the PIN?

Yep:

Elcomsoft iOS Forensic Toolkit[1]

* Instant passcode recovery for all iOS versions up to iOS 3

* Simple 4-digit iOS 4/5/6 passcodes recovered in 10-40 minutes

[1] http://www.elcomsoft.com/eift.html

Re: Apple’s Fingerprint ID May Mean You Can’t ‘Take the Fifth’

#33
post #18
post #4

In practice, it might have the opposite effect. Currently, 4-digit PINs are (presumably) brute-forceable and the alternative of entering a longer, cryptographically-secure password every time you want to use your phone is impractical, so it doesn't really matter whether you can be legally compelled to divulge your PIN or not. However, with a fingerprint ID, you can now use a cryptographically strong password to encry…

I worry that they could physically force people to put their fingers on the phone, though, which would be much easier than forcing them (physically) to input the passcode.

I'm quite sure they could get prints off the phone or something else you've touched and make an artificial gelatin "finger" with the print. Depending on the scanner,this can work and is a well known way to fool some consumer-grade fingerprint scanners.

Re: Apple’s Fingerprint ID May Mean You Can’t ‘Take the Fifth’

#34
post #4

In practice, it might have the opposite effect. Currently, 4-digit PINs are (presumably) brute-forceable and the alternative of entering a longer, cryptographically-secure password every time you want to use your phone is impractical, so it doesn't really matter whether you can be legally compelled to divulge your PIN or not. However, with a fingerprint ID, you can now use a cryptographically strong password to encry…

Are you sure you can brute force the PIN? I thought the iPhone will enforce a waiting period after too many bad entries.

I believe the idea is that if the encryption key is protected with only 4-digits, you could brute-force it offline (if you cracked open the phone and de-soldered stuff). If the encryption key is protected with a secure passphrase (as, for example, PGP private keys typically are) then that attack becomes a lot less feasible.

Re: Apple’s Fingerprint ID May Mean You Can’t ‘Take the Fifth’

#35
post #4

In practice, it might have the opposite effect. Currently, 4-digit PINs are (presumably) brute-forceable and the alternative of entering a longer, cryptographically-secure password every time you want to use your phone is impractical, so it doesn't really matter whether you can be legally compelled to divulge your PIN or not. However, with a fingerprint ID, you can now use a cryptographically strong password to encry…

> 4-digit PINs are (presumably) brute-forceable

True, but iOS does have an option to wipe the phone after 10 unsuccessful PIN attempts. Given that iCloud backup is pretty simple to setup, there's no reason not to configure this option, IMO.

Re: Apple’s Fingerprint ID May Mean You Can’t ‘Take the Fifth’

#36
A little off-topic, but can someone tell me why fingerprint-access is even a needed feature? With PIN access, you get good enough security when you also enable the lock-after-10-mistypes. And 4-digits is only about a few seconds slower than fingerprint access...and since you already have instant access to incoming calls and to the camera, in what situations do we need insta-touch access to our phones?

Phones are getting stolen and compromised because people are too lazy to do the PIN thing, I suppose...but it never seemed like it was in Apple's best interest to make phones brickable.

Re: Apple’s Fingerprint ID May Mean You Can’t ‘Take the Fifth’

#37
The way everyone's talking, you'd think Apple was taking away the four-digit PIN! But they're not...

The fingerprint ID is just another option, which you don't have to use.

So titles like this are just incorrect. Fingerprint ID isn't taking away any of your rights, because you can still use the PIN just like you always have.

I mean seriously, what the heck is going on here? Why on earth are people getting worked up about this? Sure, the fingerprint ID might be less secure, and it's important to realize that, but nobody's forcing you to use it. According to everything reported so far, the new iPhone is not removing your PIN.

Re: Apple’s Fingerprint ID May Mean You Can’t ‘Take the Fifth’

#38

A finger can easily be forcefully used or even removed for use later. A password however is still harder to get out of a brain and can be just as strong if it is long/complex enogh.

I don't think getting a password out of a living brain is harder than removing a finger. Most brains would give you their password if you threaten to remove a finger, even more if you give a demo first and threaten to remove a second one.

In the case where the brain is dead, removing the finger is way easier.

I am not sure how that balances out, but I am sure two-factor authentication (fingerprint plus password) beats either.

Re: Apple’s Fingerprint ID May Mean You Can’t ‘Take the Fifth’

#39
post #7

I feel like the author of this article is missing the whole point of Fingerprint ID. The feature is meant to make using an iPhone more secure for those of us who tend to leave our phones unlocked and PIN-free. If you're storing anything of value on your phone, the existing password-based and PIN-based lock mechanisms aren't going away any time soon. If nothing else, it'd break too many organizations' Active Directory…

No, you're missing his point. You're in court. You refuse to admit/verify the accusation that you were in the vicinity of the deceased's home. Cell phone records, dutifully recorded and reported under warrant from NSA...er...ATT, show your phone - which you are known to carry pretty much everywhere - was in that vicinity at the crime's time. You contend that does not constitute evidence. The phone is acquired, bailif…

Along the lines of what haberman says:

Most users don't care that their phone could be used against them in a court case. Maybe they should, but they don't, and pretending Fingerprint ID should be a form of two-factor authentication for your phones is silly. If users cared, they could use a passcode and the fifth amendment to protect them. It is far more likely for the average user to lose their phone by dropping it somewhere outside.

At this time, we can't even get most users to use one-factor authentication. Hell, the mass media perpetuates feel-good stories where kids use an unlocked lost phone to return it to their owners[0], so even with this technology you'll have a hell of a time convincing people to lock their phone with even a 4-digit PIN.

Stallman et al. have been telling us "your closed-source phone is spying on you" for years now, and it's clear that the education hurdle is far bigger than "fingerprints are self-incriminating". Just look the first half of the byline for [1] -- "The boy addicted to porn; the girl who let herself be sexually assaulted to get her BlackBerry back".

[0] http://www.huffingtonpost.com/2013/08/21/kids-find-phone_n_3... (original at http://www.kym4.com/4/post/2013/08/awesome-lost-found.html)

[1] http://www.theguardian.com/film/2013/sep/08/beeban-kidron-in... (posted as https://news.ycombinator.com/item?id=6373073)

Re: Apple’s Fingerprint ID May Mean You Can’t ‘Take the Fifth’

#40

Earlier quoted context omitted.

No, you're missing his point. You're in court. You refuse to admit/verify the accusation that you were in the vicinity of the deceased's home. Cell phone records, dutifully recorded and reported under warrant from NSA...er...ATT, show your phone - which you are known to carry pretty much everywhere - was in that vicinity at the crime's time. You contend that does not constitute evidence. The phone is acquired, bailif…

If the phone wasn't password-protected (or fingerprint-protected) at all, the story would be the same except you could skip the "bailiff places your finger..." step.

You would be missing the key "the phone is, beyond doubt, yours" step.
Post reply on HN