Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

361–370 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#361

Potential side effect of TouchID: Due to the mass marketing of this feature it becomes cool for people to learn how to copy fingerprints, causing a massive headache for forensics teams everywhere.

All the l33t kids will quit their current jobs and go to work busing tables, where they can surreptitiously lift prints from every glass or coffee-mug they carry.

Re: Chaos Computer Club breaks Apple TouchID

#362
post #238

Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…

This seems correct. Apple's moved the bar to breaking into those phones from having the phone and a 4 digit or no passcode to having: -- the phone -- a 2400 dpi resolution image of the correct fingerprint -- a 1200 dpi laser printer & transparent paper -- pink latex milk or white woodglue -- a non-trivial amount of time

I have 8 digit pass code on my phone.

Re: Chaos Computer Club breaks Apple TouchID

#364
post #98
post #35

Earlier quoted context omitted.

Regardless of whether or not fingerprint scanners are good security wise, it's a bit silly to think that phone robbing thugs are completely dim. The way it works in my first world modern country is that there are shops everywhere that unlock or reset phones as part of their services, and it isn't thugs running them. It's people with an affinity for 'tech' who just happen to deal with a shadier area. If cracking finge…

No, this is not the same as sim unlock. Circumventing touch id technology by making fake fingerprints is exactly the same case as being called to unlock a locked doors. The specialist knows when he is liable to crime and cannot make a legal bussines out of illegal access.

Honestly I think you're underestimating the gall of certain businesses. These aren't big multinational chains, they're like booths that pop up and down every year, in the less salubrious parts of town. They might not do it as openly, but there will be places thieves can go to circumvent touch ID if it's hackable...the knife wielding thug wont have to sit in his bedroom fiddling with acetate paper.

Re: Chaos Computer Club breaks Apple TouchID

#365

Earlier quoted context omitted.

Here's Apple's main marketing text on the subject: > Put your finger on the Home button, and just like that your iPhone unlocks. It’s a convenient and highly secure way to access your phone. Your fingerprint can also approve purchases from iTunes Store, the App Store, and the iBooks Store, so you don’t have to enter your password. It is definitely intended to replace passwords. Pretty good security would be to requir…

> Pretty good security would be to require both the fingerprint and a PIN You're missing the point. Right now lots of people have no password at all. Touch ID is a big improvement over having no password.

No, you are missing the point.

Having some shiny new method does not mean these people that do not currently use a pin/password will magically start using this.

Now, if Apple started forcing everyone to use one or the other (or both), that's another story.

Re: Chaos Computer Club breaks Apple TouchID

#366
post #232
post #160

Earlier quoted context omitted.

That's hyperbolic. How often can someone see your passcode over your shoulder? Or have it picked up by a security camera? Fingerprint scanning absolutely has advantages over pass codes. Security is all about trade-offs. This result was to be expected (in some form). What will be worry me is if the "secure enclave" where the fingerprint data is stored is cracked (and I wouldn't be surprised if that happens too eventua…

Your point is moot. As soon as your fp is digitally available online. E.g.,the CCC has captured and published former german minister of the interior, Wolfgang Schäuble's fingerprint in 2008 [1]. This finger of him is not secure any more and readily available via a google image search. [1] http://www.h-online.com/newsticker/news/item/CCC-publishes-f...

Agreed: that's why I said it would be especially worrying if this "secure enclave" Apple talks about is cracked and if it's then possible to reconstruct fingerprints from the data inside. But unless that happens, the iPhone itself doesn't make my fingerprints any easier to leak; someone can already get them from everything I touch!

Re: Chaos Computer Club breaks Apple TouchID

#367

Earlier quoted context omitted.

We don't really know exactly what it stores, but they claim it's a hash of the fingerprint. That is not the same as the actual fingerprint at all, and it should be unusable outside the iPhone 5S ecosystem. I would imagine this hash, is also what they send to the servers to authenticate, but time will tell.

If they send a hash to servers, that still has privacy implications. Apple could build a searchable database of those hashes, and the government could issue subpoenas to search that database for particular fingerprints. Maybe that's not such a bad thing, because it could help to solve crimes, but it's worth thinking about.

That's an awful idea. The potential for false positives is significant, since fingerprints are not 100% accurate identification method.

http://www.ncbi.nlm.nih.gov/pmc/articles/PMC3093498/ states that even professional forensics required independent verification to eliminate false positives.

The hashes, whatever they are, will not be "binary" in their nature. Matching against a range of visual characteristics requires to allow some level of fuzziness. Even assuming that near future improvements bring the false positive rate to half of that of the best forensic experts (to 0.05%), the law of large numbers guarantees that innocent people will be caught up in investigation dragnets. Just imagine the lives destroyed by these kinds of clerical errors.

The above is the same reason I'm against our national law enforcement getting access to the passport biometric databases. Even discounting the potential for abuse: once the police have a suspect with "matching" fingerprint available, they will have less incentive to find other ones.

Re: Chaos Computer Club breaks Apple TouchID

#368
post #347
post #164

Earlier quoted context omitted.

> My front door does not have a picture of my key on it. Yeah, but as every decent locksmith will attest, very-nearly-almost-all door locks can be easily opened with the right tools. Like picking a lock is a specialist skill, so is lifting a fingerprint and making a copy of it. No security is absolute; it's all trade-offs. Making it such that it's not worth your adversary's time to bother.

Yes, but as the same decent locksmith would attest, it would be foolish to have a picture of a key beside the lock, or anywhere in a public place. And that is what happens with a finger-print based secure system; you inadvertently place the imprint of the key on the phone's display as well as public places.

But the point is that you don't need a picture of the key beside the lock for a locksmith to break into your house! And, indeed, if there was one it would probably be faster and easier for him to use a lock pick rather than taking the time to cut a new key.

Re: Chaos Computer Club breaks Apple TouchID

#370
post #169

Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…

Touch ID is not "pretty good security" it's not even "good security" it's simply very bad security. Touch ID is better than nothing and that people use Touch ID instead of nothing is better than the current state but not by much and this definitely isn't a huge achievement. Which is really the biggest issue with Touch ID, it's advertised as such and people believe it.

Having a lock in your front door is not perfect but it is much better than not having one at all.

The way that Apple haters use stunts like this to suspend normal logic and reasoning in order to express their juvenile spite is staggering.

No one, ever, claimed TouchID was impregnable, but it is very good security and is better than what the vast majority of people do at present.

Anyone prepared to devote the time and resources that CCC did to breaking your phone has other simpler means at their disposal. I personally believe that no one else will replicate this achievement because it is simply a publicity stunt to get clicks and feed the hordes of anti-Apple zealots.

Post reply on HN