Live data from Hacker News

Chaos Computer Club breaks Apple TouchID

ccc.de

441–450 of 458 posts

Re: Chaos Computer Club breaks Apple TouchID

#441
post #401
post #370

Earlier quoted context omitted.

Having a lock in your front door is not perfect but it is much better than not having one at all. The way that Apple haters use stunts like this to suspend normal logic and reasoning in order to express their juvenile spite is staggering. No one, ever, claimed TouchID was impregnable, but it is very good security and is better than what the vast majority of people do at present. Anyone prepared to devote the time and…

Is not about Apple haters is that the security code is actually more secure than TouchID. If having TouchID will increase the amount of people that doesn't lock thir phone I'm up for it. But is not this amazing super-secure technology that will revolutionize the world.

Really? You think a four digit security code that users have to enter repeatedly is more secure than obtaining a 2400 dpi clean image of a specific fingerprint and a nontrivial lab procedure? It might require some patience but if you have an excuse for being around the target, it doesn't require great skill to see the digits as they are entered. In either case the adversary has to deal with Activation Lock which has been introduced with iOS7.

I've read there is already something like 35% adoption of iOS7 so we may see soon how effective Activation Lock is at deterring theft.

Re: Chaos Computer Club breaks Apple TouchID

#442

Earlier quoted context omitted.

Did you read the article? To crack the sensor, the would-be malevolent party needs a _2400 DPI photo of the fingerprint._ TouchID is highly secure if the only way to break into it is to have an ultra high-def image of the exact finger the device is looking for. I guess 50 character-long passcodes aren't secure because you could just tell a thief the code?

Yes, I read the article. We must have wildly different definitions of "highly". I'm pretty confident I could reproduce this result in one afternoon. Compare that to other things we might consider highly secure, like strong encryption or Fort Knox. What word do you use for security measures that take non-trivial resources to circumvent?

And the social aspect? Is it common for you to obtain the image of the correct finger and then the phone from a stranger?

How do you approach that part of the problem?

Re: Chaos Computer Club breaks Apple TouchID

#443
post #373

Despite all the claims of how insecure this is, I've just checked a bunch of my stuff. I cannot find a single clear print. There are a few smudged prints on my laptop and coffee cup. My phone is just smudges all over. So what is a realistic way to clandestinely grab a print?

The CCC previously published a German minister's fingerprint. They acquired it by lifting a water glass he had used at a public event. http://www.edri.org/edrigram/number6.7/fingerprint-schauble

This doesn't really translate to an everyday attack vector.

They had to have served the minister a drink that would not cause precipitation to form on the surface of the glass and specifically target him. Then you need to actually process the print.

A better measure would be how easy it is to lift a usable print from a crime scene. But even this has problems. You need to target a person to know whose prints you have.

If you just randomly pick pocket a phone. How do you get the print? How do you identify which finger was used? You need to get lucky or get 10 good prints.

I agree with others. The real question here is, "Is this better than no password?" I think the answer is, yes.

Re: Chaos Computer Club breaks Apple TouchID

#444

Earlier quoted context omitted.

Yes, I read the article. We must have wildly different definitions of "highly". I'm pretty confident I could reproduce this result in one afternoon. Compare that to other things we might consider highly secure, like strong encryption or Fort Knox. What word do you use for security measures that take non-trivial resources to circumvent?

And the social aspect? Is it common for you to obtain the image of the correct finger and then the phone from a stranger? How do you approach that part of the problem?

It's not common for me to do that, but it's also not common for me to try breaking into iPhones.

But if I were trying to break into an iPhone, perhaps the finger prints are on the phone. Or some other item I also got as part of the same theft. Or I found the phone in the owner's house when I robbed it and have my pick of surfaces. Or I have the owner's prints in a database because they went were convicted of a crime(I admit I have no idea what resolution those are taken at). I don't think there's a shortage possibilities. You leave prints on almost everything you touch.

To be extra clear, I'm not saying the finger print reader isn't good enough for most iPhone users; I'm not arguing the nth-grandparent's point about that. My point is that it's not highly secure, and Apple shouldn't be marketing it that way. Similarly, the lock on my front door is plenty good for my house, but no one would ever describe my house as highly secure.

Re: Chaos Computer Club breaks Apple TouchID

#445

Earlier quoted context omitted.

From Apple's site [1]: > Touch ID does not store any images of your fingerprint. It stores only a mathematical representation of your fingerprint. > The Secure Enclave is walled off from the rest of A7 and as well as the rest of iOS. Therefore, your fingerprint data is never accessed by iOS or other apps, never stored on Apple servers, and never backed up to iCloud or anywhere else. Only Touch ID uses it and it can't…

a "mathematical representation of" is exactly what a "digital image" is.

They're clearly referring to storing some kind of "hash"/mathematical representation of your fingerprint vs a plain photo/"digital image".

Re: Chaos Computer Club breaks Apple TouchID

#446

Just to keep things in perspective, the goal of Touch ID is not to be unhackable. The goal is to get more consumers to move from zero security to pretty good security. A very large number of people don't put any kind of passcode of any kind on their phone, simply because it's inconvenient. Touch ID is designed for them. It's not designed to secure nuclear footballs. Touch ID is going to massively reduce the number of…

If users not using any PIN is moving to TouchID then it is good. If users using PIN moves to TouchID then it is not as sunny.

Re: Chaos Computer Club breaks Apple TouchID

#447
(Huge discussion here - lets add to it. ;-)

There are several things here that people in discussion seems to miss och confuse. I've been working with biometrics and can at least try to clear things up.

For authentication (and identification) of a user we have three types of information: Things you have (a hard token generator), things you know (password) and things you are (shape of face, gait, voice, pattern in the iris, arteries in the back of the eye, hand, DNA. And fingerprints). Measuring what you are info and using it is called biometrics.

For good security we normally want to have a combination of at least two of the types. OpenID using for example a Yubikey is a good example.

The good thing with biometrics is that the user always carry the info needed with him/her. There are a few drawbacks though:

(1) The information is not very stable. It changes during the lifetime of the user. Sometimes it can be pretty rapid.

(2) The information is not very unique. Some types of biometrics is better than others. There is also differences in informational quality between individuals and ethnic groups. Depending on type of biometrics we get anything from a few bits to a few ten of bits. This means that it is not better than a good password that is 8 characters or more, but as good as or a bit better than a normal PIN code.

(3) The information is not under the users control and can't readily be replace. This is one thing many here and elsewhere seem to have missed in the CCC announcement. The point is that you as a user can't decide at any given time that you don't trust you token anymore, invalidate it and get a new token. That is why biometrics is foremost a tool _for others_ to identify you (passports, forensics).

The reason fingerprint based biometrics is so popular (compared to other types of biometrics) is that it is possible to build compact, cheap sensors that are pretty easy to use and are simple to integrate into digital systems.

All types of biometrics are fuzzy. We normally talk about False Acceptance Rate (FAR), that is how often do we accept a biometric ID as valid when in fact it is not. And correspondingly we have False Rejection Rate, where a valid ID is rejected. Good biometric systems have FAR, FRR under 10%. But for a busy airport there is still quite a few mistakes during a day.

The way a fingerprint based biometric system normally works is that you have a sensor that creates an image (256 levels of gray scale or similarly). The image is then processed (differential filters etc) followed by feature extraction. The features are called minuae:

https://en.wikipedia.org/wiki/Minutiae

Typically sworls, where lines end, merges splits. Normally we find 8-10-15 or a few more good minutae in the image. Based on the location of the minutae we create a graph.

The graph is then stored (if registering a user - called enrollment) or compared to stored graphs. And here comes the fuzziness. The graph will not be similar so we simply can't do a SHA-1 digest and match. The graph will be rotated, scaled, stretched, have fewer or more points. Basically fuzzy congruence matching with threshold.

The feature extraction can be done directly in the sensor. But in the case of TouchID I don't think so. Apple bought Authentec and their area sensors (that can capture a whole image directly. Sweep sensors detect movement of a finger over the sensor, estimate speed and stitch image slices together) simply delivered a raw image. This means that the filtering, feature extraction and matching is done inside A7.

Apple has touted the security of the processing. Basically it is ARM Trust Zone used in several other devices.

http://www.arm.com/products/processors/technologies/trustzon...

TZ is good, but there has been attacks published. And there is nothing that says that Apple has not added a read port from the untrusted enclave into the memory of the trusted enclave. For efficient debug reasons for example.

So. Biometrics is fuzzy and will give false acceptance (as the main problem. rejextion is less of a problem). There is quite probably an image available in the A7 and we really don't know if it and/or the graph database is in fact accessible.

When it comes to the CCC attack - we simply don't know if they tried lower resolution before ending up with 2400 dpi. I wouldn't be surprised if it works (at least sometimes - fuzziness again) with lower resolution. Also attack always gets better. I'm prepared to bet a good IPA that someone within 2 years will show how he/she can unlock a 5S just by smartly pressing on the home button while breathing to activate residue as fingerprint. It has been done with area sensors such as Authentecs before.

TouchID is good if it makes users without PIN to use it. But if it gets users with PINs stop using PINs, it is not as good. What would be great if we could combine TouchID with PIN or password. All the time.

I hope all this explains a few things. And remember, once again, the main problem with biometrics is that it can't be changed at will by the user. Good for others, less so for the user.

Re: Chaos Computer Club breaks Apple TouchID

#448
post #257

Earlier quoted context omitted.

But you have to consider potential damage from the successful attack. It doesn't matter if 99% of low damage attacks are unsuccessful but 1% high damage attacks will go through. The solution is fine by itself but millions of people will use it and not understand the real level of protection.

The potential damage is zero. You (and everyone else in this thread) are forgetting that you can't steal an iPhone for more than 30 seconds anymore without Activation Lock locking you and everyone else out, forever, period, paragraph. Activation Lock + Touch ID = all the security that almost anyone needs on a phone and much higher security than any of us have been used to up to now.

I think this is key here. Before, you could try and lock or wipe your phone when it was stolen. But in order for it to work the thief must have let it powered on. If he was smart and shut it off, took it home and booted into DFU mode to restore a the thing back to factory settings, you were out of luck.

But with the new Activation Lock, it supposedly doesn't matter if it is shut down, the minute someone tries to flash the phone. Be it normally via iTunes or via DFU mode and iTunes there should appear a message that the phone has been wiped and must be unlocked with the iCloud password of the account that did the wiping. So no chance to flash the phone back to factory settings.

Re: Chaos Computer Club breaks Apple TouchID

#449
post #367

Earlier quoted context omitted.

If they send a hash to servers, that still has privacy implications. Apple could build a searchable database of those hashes, and the government could issue subpoenas to search that database for particular fingerprints. Maybe that's not such a bad thing, because it could help to solve crimes, but it's worth thinking about.

That's an awful idea. The potential for false positives is significant, since fingerprints are not 100% accurate identification method. http://www.ncbi.nlm.nih.gov/pmc/articles/PMC3093498/ states that even professional forensics required independent verification to eliminate false positives. The hashes, whatever they are, will not be "binary" in their nature. Matching against a range of visual characteristics require…

It's a shame really, because all evidence is fuzzy on some level. DNA could be planted, videos can be a of a lookalike, or being at a particular location at a particular time could be a coincidence. I don't know exactly how law enforcement works, but they really should be looking for connections and try to explain why a suspect is not the right guy, instead of the other way around. Maybe that is just wishful thinking.

Re: Chaos Computer Club breaks Apple TouchID

#450
post #126

Earlier quoted context omitted.

Frontline had an excellent piece on the (lack of) reliability behind most of crime forensics. Fingerprints in particular are mentioned as being very unreliable and unscientific. The only scientifically rigorous piece of "CSI" is DNA matching. http://www.pbs.org/wgbh/pages/frontline/real-csi/

Isn't it rather easy to obtain somebody's DNA, and also clone it? Seems even easier than obtaining somebody's fingerprints.

It's easy to obtain. You'd need lab gear to make more - the gear is pretty common in wet labs: a PCR machine, desk centrifuge and suitable supplies.

It's much less common than a consumer-grade scanner and some wood glue.

Post reply on HN