Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

341–350 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#341
post #237

Dont panic! this loophole is easy to fix if AAPL gives free mittens(cuter than gloves) to its users with clear instructions to take them off only when unlocking the phone.

Yes; the hackers are just holding it the wrong way! It's really secure if it's held the right way.

Re: Chaos Computer Club breaks Apple TouchID

#342
post #269

Earlier quoted context omitted.

> The goal is to get more consumers to move from zero security to pretty good security. One might argue that Touch ID is too strong to be used where there was no security before. In an arms race with thefts and hackers, leaping too far forwards might not be the best option in the long term.

Thefts are not limited by passwords, the thief will just reset the phone.

Actually, with iOS7s new activation lock feature, thefts are limited by passwords.

Re: Chaos Computer Club breaks Apple TouchID

#343

Earlier quoted context omitted.

I don't really think it is relevant. The iTunes authorisation for example wouldn't be sent the fingerprint information, it would be sent the response 'yes the person passed the test'. The fingerprint information stored in the 'secure enclave' of the A7 is a combination of the data related to the fingerprint combined with unique information for that specific device. So even if the data could be extracted, using it for…

>I don't really think it is relevant. The iTunes authorisation for example wouldn't be sent the fingerprint information, it would be sent the response 'yes the person passed the test'. No, it wouldn't send that response at all. That's called a client-side security control, and I'm sure you can think of why that's out of the question in any system.

I don't want to jump in on the "how secure is my phone discussion", I just wanted to point out that with all the revelations and concerns regarding privacy, a single company having fingerprints for some significant portion of North America is nothing to be taken lightly.

That said, I sincerely doubt this is the case. I imagine the phone acts as a proxy for the authentication, validating the fingerprint then sending some other form of authorization to Apple or using the fingerprint as input to a cryptographic algorothm.

Re: Chaos Computer Club breaks Apple TouchID

#344
post #123
post #94

Earlier quoted context omitted.

It looks like either of the following: - the capacitance of the ridges and crests of one's fingerprint dominates any differences in subcutaneous capacitance (possibly because they are closer to the scanner, or because there simply is too little variance in capacitance between flesh and hair veins) - subcutaneous structures resembles fingerprints too much (seems quite possible, as there must be a reason that it is har…

The subcutaneous structures are, from what I've read, basically the same as the surface ridges and crests.

Looking at the chaos computer club video, that becomes plausible/likely (the iPhone UI shows a picture of the fingerprint as a guideline for the quality of the phone's knowledge of the fingerprint, and afaik the sensor does not have a camera, so that is not just an aid for the user.)

Yes, it could also be Johnny Appleseed's fingerprint, used as an image users are familiar with, but http://en.wikipedia.org/wiki/Friction_ridge seems to confirm it, too ("The pattern of ridges they produce in hands and feet". I'm not sure whether they refers to the epidermal cells or to the blood vessels (less likely), but that doesn't matter)

Re: Chaos Computer Club breaks Apple TouchID

#345

Earlier quoted context omitted.

Apple claims that "The technology within Touch ID is some of the most advanced hardware and software we've put in any device." [1]. This attack showed that increasing sensor resolution only requires increasing the resolution on the fake print to match. This attack is an interesting data point in the debate over using biometrics in access control systems. Apple was hyped to have introduced something new and exciting i…

> This attack showed that increasing sensor resolution only requires increasing the resolution on the fake print to match. Just to clarify, it wasn't just the increased resolution that was required here, but "latex milk", I assume to simulate a living finger, as well. It's not as simple as print-of-print = unlock.

It's "latex milk" today, tomorrow it might be just "regular milk" that's needed! The point is that the fingerprint security was bypassed so soon after release, and posted on the internet. Sure, it takes a lot of effort with the first generation of this hack.

No matter how cool the fingerprint tech is on iPhones, you wouldn't go as far as using it for your master access to your password manager app or bank account app.

For the purpose of replacing the lock screen pin, or as others have said, no pin at all, I think it's fine.

Re: Chaos Computer Club breaks Apple TouchID

#346

Earlier quoted context omitted.

Where the fuck did that come from? It is neither baseless or FUD. That fingerprint will be sent over the wire at some point and the NSA will gladly pick it up. How you think otherwise is beyond me. What operating system I prefer really has nothing to do with it, even if it is linux. Posted from my iPhone, android, third mac mini, 2nd mac air, or first thinkpad who the fuck knows (or cares? oh you obviously)

From Apple's site [1]: > Touch ID does not store any images of your fingerprint. It stores only a mathematical representation of your fingerprint. > The Secure Enclave is walled off from the rest of A7 and as well as the rest of iOS. Therefore, your fingerprint data is never accessed by iOS or other apps, never stored on Apple servers, and never backed up to iCloud or anywhere else. Only Touch ID uses it and it can't…

Your trust in Apple is heartwarming.

Re: Chaos Computer Club breaks Apple TouchID

#347
post #164

Earlier quoted context omitted.

My front door does not have a picture of my key on it. My phone has tons of fingerprints though. It's a touch screen phone. One of those words is "touch" which clearly implies your finger coming in contact with it. Even if you wanted to use gloves you need special ones for it to work properly with the capacitive screen. Unless you are continuously wiping it (the screen, not the data) it will have you prints on it.

> My front door does not have a picture of my key on it. Yeah, but as every decent locksmith will attest, very-nearly-almost-all door locks can be easily opened with the right tools. Like picking a lock is a specialist skill, so is lifting a fingerprint and making a copy of it. No security is absolute; it's all trade-offs. Making it such that it's not worth your adversary's time to bother.

Yes, but as the same decent locksmith would attest, it would be foolish to have a picture of a key beside the lock, or anywhere in a public place.

And that is what happens with a finger-print based secure system; you inadvertently place the imprint of the key on the phone's display as well as public places.

Re: Chaos Computer Club breaks Apple TouchID

#348

Earlier quoted context omitted.

>I don't really think it is relevant. The iTunes authorisation for example wouldn't be sent the fingerprint information, it would be sent the response 'yes the person passed the test'. No, it wouldn't send that response at all. That's called a client-side security control, and I'm sure you can think of why that's out of the question in any system.

I don't want to jump in on the "how secure is my phone discussion", I just wanted to point out that with all the revelations and concerns regarding privacy, a single company having fingerprints for some significant portion of North America is nothing to be taken lightly. That said, I sincerely doubt this is the case. I imagine the phone acts as a proxy for the authentication, validating the fingerprint then sending s…

We don't really know exactly what it stores, but they claim it's a hash of the fingerprint. That is not the same as the actual fingerprint at all, and it should be unusable outside the iPhone 5S ecosystem. I would imagine this hash, is also what they send to the servers to authenticate, but time will tell.

Re: Chaos Computer Club breaks Apple TouchID

#349
post #254

Earlier quoted context omitted.

'every so often' seems a bit casual, for a payment [1,2] [1] From the citation: "Passcodes and passwords aren’t completely eliminated by Touch ID, then, but they almost certainly will be later on." [2] The glass screen will have your fingerprint on it, somewhere. That can be CSI'd by anyone who finds it. Anyone serious enough to do that (and its not much) can start escalating.

When most payments are under $5 it's probably ok. It's good enough for the credit/debit card payment industry, at least. (They relaxed the rules so you don't have to sign or enter a PIN for small purchases.)

Can we agree that Apple should not be marketing this as a "highly secure way to access your phone"?

Re: Chaos Computer Club breaks Apple TouchID

#350

Earlier quoted context omitted.

So rather than addressing the point, you attack him on something completely different. Presumably because there are actually no examples where he's been wrong about TouchID.

No, I couldn't be bothered because the man writes guff. http://daringfireball.net/2013/09/the_iphone_5s_and_5c > "You know how iOS touch latency and scrolling performance have always been far ahead of its competition? The way you could just tell that internally, Apple had uncompromising standards for how responsive these things needed to be? That’s what Touch ID is like — it’s to all previous fingerprint scanners I’v…

> Convenient that he forgets the uncompromising standards of Apple Maps.

In the next paragraph, he writes that Apple sucks at online services, and that TouchID is great precisely because it's a completely offline feature. You haven't even read the article. I wish HN would blacklist any mention of Gruber's name.

Post reply on HN