Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

391–400 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#391

Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…

Usually when I see smart people talking about security, they think about what attack vector/situation you are trying to protect against. In this case, the situation you are trying to protect against is not keeping your phone locked when you are in custody or at gun point. The situation is someone unlocking your phone if someone swipes it from your pocket, you lose your phone, or simply leave it on your desk for a few moments as you go to the bathroom at the office. So, yes, a biometric scanner, even one that is easily beaten by an attacker, is good for this purpose.

Whatever the case, maybe we should step back and get some more perspective. How many of us don't put locks on our shared computers and phones because we don't want the inconvenience of ensuring everybody that should be allowed to use it can? My phone is a shared device and I removed any and all locks on it as I got very tired of "oh, let me unlock that for you." Basically, I want everybody that can reach it physically (when it isn't lost or stolen) to be able to access it and make calls, surf the web, use the map, search contacts, play games, etc. Is any phone locking mechanism going to work perfectly, probably not. Being able to set up my phone to unlock for anybody in my family and friends circle by something like fingerprints is a pretty good start.

Re: Chaos Computer Club breaks Apple TouchID

#392
post #254

Earlier quoted context omitted.

Reportedly when making purchases it "will still prompt you for your password every so often to 'renew Touch ID purchases.'" Source: http://www.cultofmac.com/246572/iphone-5s-first-impressions-... .

'every so often' seems a bit casual, for a payment [1,2] [1] From the citation: "Passcodes and passwords aren’t completely eliminated by Touch ID, then, but they almost certainly will be later on." [2] The glass screen will have your fingerprint on it, somewhere. That can be CSI'd by anyone who finds it. Anyone serious enough to do that (and its not much) can start escalating.

The payment can (mostly) only benefit the device owner though, right?

Buying apps with your device is not terribly useful unless you have take full posession of the device, in which case the owner can remote lock/wipe it with iCloud and dispute the charges with their CC company.

Re: Chaos Computer Club breaks Apple TouchID

#393
post #346

Earlier quoted context omitted.

From Apple's site [1]: > Touch ID does not store any images of your fingerprint. It stores only a mathematical representation of your fingerprint. > The Secure Enclave is walled off from the rest of A7 and as well as the rest of iOS. Therefore, your fingerprint data is never accessed by iOS or other apps, never stored on Apple servers, and never backed up to iCloud or anywhere else. Only Touch ID uses it and it can't…

Your trust in Apple is heartwarming.

Then you might as well say Apple already secretly have finger scanner since iPhone first generation and already sent that data over the wire. Or may be there are also finger scanner on your keyboard right now!!! Also that video-cam on most notebook, it's now always on and secretly send the data to NSA!!!!

Re: Chaos Computer Club breaks Apple TouchID

#394

Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…

Piss poor excuse - think of all the users using a password now downgrading their security, but Apple advertising it as "high security".

I like what you're saying, massively allow users to secure their phones without the pain of entering a password, but when it comes at a compromise of "little is better than none" is not the mentality people need for security. I'd rather see corporations rewarding and encouraging proper security strategies rather than creating some compromise for marketing.

Re: Chaos Computer Club breaks Apple TouchID

#395
post #329

Earlier quoted context omitted.

I don't know, reproducing a fingerprint is relatively easy to understand (just scan and print), while cracking a password can be more exotic to 'traditional' thieves. When today they'd just wipe the phone, tomorrow they make take the extra step of pulling out the SIM card and unlock with the fingerprint, and sell the data as well.

Your random thief is more worried about cell phone tracking than any data you have on your phone. They will wipe it as soon as possible today, and probably for the next few years; they don't give a crap about your cat photos. Even if your phone was unlocked, they probably wouldn't bother more than a cursory glance. They have more phones to steal than to bother with is on some random person's phone. When the data is i…

I see where this assumption comes from, but scraping the personal info off a phone is a thing, and "random thieves" might be the minority when it comes to stealing and reselling phones (at least in europe or asia they are rarely random. It don't know for the US).

I haven't heard of it recently, but a few years ago there was a story on phone operator temporary staff that would offer clients to move their contact info from their old phone to the new one (it's a completely legit service) and keep a backup of the old info to sell it. The price for an entry was something like 2 cents, but data would be sold by batches for about 700~800 dollars.

I didn't find any quick resources in english, just for the numbers there was this piece by trendmicro (to note, they are of course biased to make the number a littre bigger) http://blog.trendmicro.co.jp/archives/4828

Re: Chaos Computer Club breaks Apple TouchID

#396
post #87

Earlier quoted context omitted.

Then create a detailed model using said high resolution fingerprint. If someone cares enough about your phone to do that, they can probably break into it by other means anyway (jail break, brute force passcode, etc)

You leave finger prints on the phone. Just snap a photo with a decent camera - it's probably enough detail. Print it. Stick some latex or glue on it (literally available everywhere). That's it . This is not rocket science or time consuming like brute forcing. You don't even have to shoulder-surf to catch their password.

I strongly encourage you to try this and let me know how it turns out.

I'll wait.

Re: Chaos Computer Club breaks Apple TouchID

#398

Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…

Here's Apple's main marketing text on the subject: > Put your finger on the Home button, and just like that your iPhone unlocks. It’s a convenient and highly secure way to access your phone. Your fingerprint can also approve purchases from iTunes Store, the App Store, and the iBooks Store, so you don’t have to enter your password. It is definitely intended to replace passwords. Pretty good security would be to requir…

Passwords aren't exactly nuclear football grade either.

Re: Chaos Computer Club breaks Apple TouchID

#399

Earlier quoted context omitted.

When most payments are under $5 it's probably ok. It's good enough for the credit/debit card payment industry, at least. (They relaxed the rules so you don't have to sign or enter a PIN for small purchases.)

Can we agree that Apple should not be marketing this as a "highly secure way to access your phone"?

Why? It IS highly secure. Just not infallible.

Re: Chaos Computer Club breaks Apple TouchID

#400
post #370
post #169

Earlier quoted context omitted.

Touch ID is not "pretty good security" it's not even "good security" it's simply very bad security. Touch ID is better than nothing and that people use Touch ID instead of nothing is better than the current state but not by much and this definitely isn't a huge achievement. Which is really the biggest issue with Touch ID, it's advertised as such and people believe it.

Having a lock in your front door is not perfect but it is much better than not having one at all. The way that Apple haters use stunts like this to suspend normal logic and reasoning in order to express their juvenile spite is staggering. No one, ever, claimed TouchID was impregnable, but it is very good security and is better than what the vast majority of people do at present. Anyone prepared to devote the time and…

> Anyone prepared to devote the time and resources that CCC did to breaking your phone has other simpler means at their disposal

Really? Lift someone's print, leave it with superglue, scan and print it and then dump glue on the scan.

That seems to be the sum total of what needs to be done. You need only sticky tape to lift the print and the rest can be done in an hour.

It sounds quite action movie, but in reality it's pretty damn simple and if I wanted to get access to your phone I could easily prepare it in advance and carry a tiny latex strip in my wallet for just the right occasion without your knowledge at any point.

Post reply on HN