Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

431–440 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#431
I want to see this exact attack repeated based entirely on the fingerprints left on the device itself. It's an all glass surface and we leave fingerprints everywhere, including on the device itself. It you are literally leaving the key all over the screen itself, this is pretty damning. I wouldn't be surprised if an entire photograph of all the partials all over the screen could be used to reconstruct one full fingerprint of the desired digit.

Now that this type of security is on the iPhone, it is likely to become widespread, which will only further increase the value of improving attacks on this particular security measure.

Re: Chaos Computer Club breaks Apple TouchID

#432

Earlier quoted context omitted.

"They didn't say it was designed to the standards needed to protect DOD secrets." I'm sorry, but this is so much backpedaling. Do i really need to start pulling out comments from the last discussion where people were quoting Apple's press conference about how revolutionary and secure this was?

People will here what they want (you included), i'm not entirely sure what you're getting at though.

Hear what they want?

Apple made a huge deal about how secure it was an how much of an improvement and how very sophisticated it was. It turns out, it wasn't really.

Now people are saying "well, they never really said it was all that good, or meant to keep you secure", blah blah blah.

Let's start with the basic press release:

"and introducing Touch ID™, an innovative way to simply and securely unlock your phone with just the touch of a finger."

" “iPhone 5s sets a new standard for smartphones, packed into its beautiful and refined design are breakthrough features that really matter to people, like Touch ID, a simple and secure way to unlock your phone with just a touch of your finger.""

From http://www.apple.com/pr/library/2013/09/10Apple-Announces-iP...

"“There’s so much personal stuff on these devices; our email, our photos, our contacts. We have to protect them. The most common way is to set up a passcode. A simple 4-digit passcode, or a more complex one if you want. Unfortunately, some people find it’s too cumbersome and dont set it up. In our research as much as half of people don’t ever set it up.”"

"We’ve set up a new technology that makes this super easy to do. We call it: Touch ID."

"“Your fingerprint is one of the best passwords in the world.”"

This was said by Apple at the iphone 5s press conference.

This says it is meant to replace the passcodes, and it was "one of the best passwords in the world", and supposed to be able to protect personal data.

Here's a cite: http://techcrunch.com/2013/09/10/live-blog-from-apples-iphon...

You can verify from other transcripts as well. I avoided the slides they had explaining how very sophisticated the sensor technology was.

So what i'm getting at is that most of the comments in this thread smack of "Apple never really meant it to do X, or Apple didn't say it would be all that secure". They did, on both counts. They said it would replace passwords, and they said it was quite secure.

The claims otherwise are ridiculous.

Re: Chaos Computer Club breaks Apple TouchID

#434
post #306
post #238

Earlier quoted context omitted.

This seems correct. Apple's moved the bar to breaking into those phones from having the phone and a 4 digit or no passcode to having: -- the phone -- a 2400 dpi resolution image of the correct fingerprint -- a 1200 dpi laser printer & transparent paper -- pink latex milk or white woodglue -- a non-trivial amount of time

The problem here is your implying getting past the 4 digit code is substantially easier then cloning a finger print. The code is in someone's head, or you have to deconvolute it from screen smudges. Your fingerprints are literally everywhere you go.

Do you think the finger prints you leave everywhere are a substitute for the 2400 dpi photograph?

I bet you if CCC wanted to make a much stronger case, they would have taken that image from a fingerprint on a glass - but that didn't work. They photographed the finger and not a stray print for a reason.

Re: Chaos Computer Club breaks Apple TouchID

#435

Earlier quoted context omitted.

Here's Apple's main marketing text on the subject: > Put your finger on the Home button, and just like that your iPhone unlocks. It’s a convenient and highly secure way to access your phone. Your fingerprint can also approve purchases from iTunes Store, the App Store, and the iBooks Store, so you don’t have to enter your password. It is definitely intended to replace passwords. Pretty good security would be to requir…

I think it's more than adequate security for App Store purchases. My debit card, for example, has "paywave" short range payment support. So anybody who has my card can go around making small purchases, no PIN, no signature needed. I'm fine with this because the convenience far outweighs the security concern. With the iPhone an attacker who replicates your fingerprint can make purchases to your iTunes account using yo…

> Creating a fake print that can fool the scanner is so much harder than stealing someone's debit/credit card.

No, it's not. Starbug used simple means starting from a photo of a fingerprint. The fact that fingerprints are blasted all over the place makes this very easy. You could probably even build a cheap machine that automates this process.

Re: Chaos Computer Club breaks Apple TouchID

#436

Earlier quoted context omitted.

Can we agree that Apple should not be marketing this as a "highly secure way to access your phone"?

Did you read the article? To crack the sensor, the would-be malevolent party needs a _2400 DPI photo of the fingerprint._ TouchID is highly secure if the only way to break into it is to have an ultra high-def image of the exact finger the device is looking for. I guess 50 character-long passcodes aren't secure because you could just tell a thief the code?

Yes, I read the article.

We must have wildly different definitions of "highly". I'm pretty confident I could reproduce this result in one afternoon. Compare that to other things we might consider highly secure, like strong encryption or Fort Knox. What word do you use for security measures that take non-trivial resources to circumvent?

Re: Chaos Computer Club breaks Apple TouchID

#437

Earlier quoted context omitted.

I think it's more than adequate security for App Store purchases. My debit card, for example, has "paywave" short range payment support. So anybody who has my card can go around making small purchases, no PIN, no signature needed. I'm fine with this because the convenience far outweighs the security concern. With the iPhone an attacker who replicates your fingerprint can make purchases to your iTunes account using yo…

> Creating a fake print that can fool the scanner is so much harder than stealing someone's debit/credit card. No, it's not. Starbug used simple means starting from a photo of a fingerprint. The fact that fingerprints are blasted all over the place makes this very easy. You could probably even build a cheap machine that automates this process.

I'd argue stealing a credit card is a much simpler one step process: Step 1. steal card. Done. Pretty easy too, lots of people leave their wallet or purse unattended in all sorts of scenarios, typically with their phone sitting underneath it. The home kitchen or the desk at work are typically places.

Creating fake print: Step 1. Either find a perfect print, or a number of imperfect prints. Step 2. photograph. Step 3. enhance. Step 4. print. Step 5. Use print on suitably encoded device (which probably means steeling their phone too).

Edit: Given the front of a phone is glass, there's probably going to be a print on the screen, though I wonder if any prints take from a phone screen would be clean? I don't know.

Re: Chaos Computer Club breaks Apple TouchID

#438

Earlier quoted context omitted.

Where the fuck did that come from? It is neither baseless or FUD. That fingerprint will be sent over the wire at some point and the NSA will gladly pick it up. How you think otherwise is beyond me. What operating system I prefer really has nothing to do with it, even if it is linux. Posted from my iPhone, android, third mac mini, 2nd mac air, or first thinkpad who the fuck knows (or cares? oh you obviously)

From Apple's site [1]: > Touch ID does not store any images of your fingerprint. It stores only a mathematical representation of your fingerprint. > The Secure Enclave is walled off from the rest of A7 and as well as the rest of iOS. Therefore, your fingerprint data is never accessed by iOS or other apps, never stored on Apple servers, and never backed up to iCloud or anywhere else. Only Touch ID uses it and it can't…

a "mathematical representation of" is exactly what a "digital image" is.

Re: Chaos Computer Club breaks Apple TouchID

#439

Earlier quoted context omitted.

Look at your finger. Actual ridges are not that dense. A sampling frequency of 20 points per mm is high enough to visualise a fingerprint in sufficient detail for identification purposes https://en.wikipedia.org/wiki/Fingerprint#Research Random #s: 20dpmm = 5,080dpi? Sounds like 2400dpi sensing is certainly insufficient for research-grade identification... and therefore maybe easy to fool? :)

DPI refers to the number of samples in a straight line one inch long, not to the number of samples in a 1 inch square.

Aha! Thanks, that makes more sense. So 1 inch = 25.4mm. 20 dots per mm is sufficient. So 20x25.4 = 508dpi. That's more believable as a rough minimum.

Re: Chaos Computer Club breaks Apple TouchID

#440

Earlier quoted context omitted.

The primary use case here is keeping kids from buying apps or in-app purchases when their parents lend them the phone to play games. A casual solution is perfectly acceptable. If someone is going to go through the trouble of stealing my phone and cloning my fingerprint I'm guessing they would want more than purchasing music or apps under my iTunes account.

Locks just keep an honest man honest. If someone wants what you have bad enough, there really isn't anything you can do to stop them.

If my kid is talented enough to create a silicone-gel replica of my fingerprint in order to buy in-game merch, she's earned it.
Post reply on HN