Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

421–430 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#421
post #407

Earlier quoted context omitted.

I think it would be pretty easy to get many people's phone password -- just by being in the right place when they unlock it, and watching closely. Most people I know don't cover up their phone at all when they enter it, even in public. So you don't need to get "in someone's head". You just need a good view of them using it. Granted, getting an iTunes Store password by just watching would be a lot harder. But compared…

Conversely you can just change a phone password. Hell you could rotate it daily if you wanted (surprised that's not a feature yet). But you can't change your fingerprints.

or you could just rotate your fingers/toes/nipples?

Re: Chaos Computer Club breaks Apple TouchID

#422

Earlier quoted context omitted.

I don't want to jump in on the "how secure is my phone discussion", I just wanted to point out that with all the revelations and concerns regarding privacy, a single company having fingerprints for some significant portion of North America is nothing to be taken lightly. That said, I sincerely doubt this is the case. I imagine the phone acts as a proxy for the authentication, validating the fingerprint then sending s…

We don't really know exactly what it stores, but they claim it's a hash of the fingerprint. That is not the same as the actual fingerprint at all, and it should be unusable outside the iPhone 5S ecosystem. I would imagine this hash, is also what they send to the servers to authenticate, but time will tell.

I remember reading (but can't find the source, I think it was Anand) that they store a hash of the fingerprint data and a unique identifier of the phone.

Re: Chaos Computer Club breaks Apple TouchID

#423

Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…

"Touch ID is going to massively reduce the number of totally unsecured iPhones that require zero effort to access. That's the goal."

...while lowering the security of a massive number of iPhones previously secured by PINs.

Re: Chaos Computer Club breaks Apple TouchID

#424

Earlier quoted context omitted.

Can we agree that Apple should not be marketing this as a "highly secure way to access your phone"?

Did you read the article? To crack the sensor, the would-be malevolent party needs a _2400 DPI photo of the fingerprint._ TouchID is highly secure if the only way to break into it is to have an ultra high-def image of the exact finger the device is looking for. I guess 50 character-long passcodes aren't secure because you could just tell a thief the code?

2400 dpi is nothing out of ordinary for a half decent scanner or a digital camera at 1:1 reproduction.

Re: Chaos Computer Club breaks Apple TouchID

#425

Earlier quoted context omitted.

Can we agree that Apple should not be marketing this as a "highly secure way to access your phone"?

Did you read the article? To crack the sensor, the would-be malevolent party needs a _2400 DPI photo of the fingerprint._ TouchID is highly secure if the only way to break into it is to have an ultra high-def image of the exact finger the device is looking for. I guess 50 character-long passcodes aren't secure because you could just tell a thief the code?

2400 DPI is not that hard to achieve. Any DSLR can do it with a macro lens attachment and a flash. Many scanners can do it as well.

Re: Chaos Computer Club breaks Apple TouchID

#426

Earlier quoted context omitted.

> Pretty good security would be to require both the fingerprint and a PIN You're missing the point. Right now lots of people have no password at all. Touch ID is a big improvement over having no password.

No, you are missing the point. Having some shiny new method does not mean these people that do not currently use a pin/password will magically start using this. Now, if Apple started forcing everyone to use one or the other (or both), that's another story.

>Having some shiny new method does not mean these people that do not currently use a pin/password will magically start using this.

It actually does mean exactly that in the aggregate. There are huge number of people that don't use pass codes not because they don't care, but because they are inconvenient. This technology is for them, and it will have nothing to do with "magic" when they adopt this fundamental improvement (that happens to be also a heavily marketed main differentiation from the previous model).

As for the people that never used a pass code because they weren't aware/didn't care... probably less adoption, but just because the feature is so heavily marketed, many of them will also use it.

But yeah. Significant numbers of people who didn't secure their devices with pass codes will now do so. No magic required.

Re: Chaos Computer Club breaks Apple TouchID

#427
post #370

Earlier quoted context omitted.

Having a lock in your front door is not perfect but it is much better than not having one at all. The way that Apple haters use stunts like this to suspend normal logic and reasoning in order to express their juvenile spite is staggering. No one, ever, claimed TouchID was impregnable, but it is very good security and is better than what the vast majority of people do at present. Anyone prepared to devote the time and…

> Anyone prepared to devote the time and resources that CCC did to breaking your phone has other simpler means at their disposal Really? Lift someone's print, leave it with superglue, scan and print it and then dump glue on the scan. That seems to be the sum total of what needs to be done. You need only sticky tape to lift the print and the rest can be done in an hour. It sounds quite action movie, but in reality it'…

It sounds quite action movie, but in reality it's pretty damn simple

Also in reality it will foil over 99% of potential unauthorized activation attempts as most people aren't going to craft fingerprints to get into someone's device.

If reality is the bar you're using, TouchID still wins.

Re: Chaos Computer Club breaks Apple TouchID

#428

Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…

Piss poor excuse - think of all the users using a password now downgrading their security, but Apple advertising it as "high security". I like what you're saying, massively allow users to secure their phones without the pain of entering a password, but when it comes at a compromise of "little is better than none" is not the mentality people need for security. I'd rather see corporations rewarding and encouraging prop…

>Piss poor excuse - think of all the users using a password now downgrading their security, but Apple advertising it as "high security".

If you're talking aggregate security, TouchID will still increase security (even with current PIN users moving to a FP Scan) as currently about 50% don't use any sort of pass code now.

If you're talking about the ability for current PIN users to maintain their level of security if they wish, -they can still use a PIN.

Bottom line is that there will be fewer successful unauthorized login attempts in the wild.

Re: Chaos Computer Club breaks Apple TouchID

#429

Earlier quoted context omitted.

The primary use case here is keeping kids from buying apps or in-app purchases when their parents lend them the phone to play games. A casual solution is perfectly acceptable. If someone is going to go through the trouble of stealing my phone and cloning my fingerprint I'm guessing they would want more than purchasing music or apps under my iTunes account.

And if you know your phone is stolen you can disable it anyways.

You can't renew your fingerprint, though.

Re: Chaos Computer Club breaks Apple TouchID

#430
post #395

Earlier quoted context omitted.

Your random thief is more worried about cell phone tracking than any data you have on your phone. They will wipe it as soon as possible today, and probably for the next few years; they don't give a crap about your cat photos. Even if your phone was unlocked, they probably wouldn't bother more than a cursory glance. They have more phones to steal than to bother with is on some random person's phone. When the data is i…

I see where this assumption comes from, but scraping the personal info off a phone is a thing, and "random thieves" might be the minority when it comes to stealing and reselling phones (at least in europe or asia they are rarely random. It don't know for the US). I haven't heard of it recently, but a few years ago there was a story on phone operator temporary staff that would offer clients to move their contact info…

I live in Beijing, the first thing the thief will do here is take the sim out and wipe the phone. They will also hawk the phone as soon as possible to maximize turnover, so it's usually possible to buy your stolons phone back within the hour.
Post reply on HN