Live data from Hacker News

Xerox scanners randomly alter numbers in scanned documents (2013)

dkriesel.com

51–60 of 63 posts

Re: Xerox scanners randomly alter numbers in scanned documents (2013)

#51

Earlier quoted context omitted.

But Xerox has admitted that the character substitution was enabled on all compression levels even though they claimed it was only active on one specific level. So theoretically, everyone who archived during that time using Xerox WorkCentres has to question their documents.

Which might be exactly, why nobody wants to talk about this. (This may be especially nasty where archives had been digitized and then the analog originals were disposed of. What can you even do about this?) PS: In order to have learned anything from this, there should be a rule for the digitization of archives containing core documents to use (at least) two unrelated scanning technologies, with unrelated processors a…

> A sole, single scan should attribute to nothing.

That's not much less than a sole, single repository of paper documents that may not be climate controlled or fire protected (or the fire protection may be sprinklers which will ruin most of the documents anyway).

Document digitalization is a cost saving program, but it doesn't save money if you need to have two vendors, validate the vendors are actually separate and remain actually separate, have a comparison process and an exception process. If the requirements are too high, paper remains and nobody uses the documents because the retrieval costs in labor and time are too high.

Re: Xerox scanners randomly alter numbers in scanned documents (2013)

#52
post #46

Earlier quoted context omitted.

When Apple introduced a fingerprint unlock in the home button, it wanted to keep the fingerprint scans secure. The security chip that stores the fingerprint scans needs to verify that the home button's fingerprint scanner is trustworthy, to prevent man in the middle attacks. However, when an unauthorized or unofficial button is used as a replacement for repair, the phone will permanently brick itself. No warning is g…

As a user, that’s what I’d want it to do. If someone is trying to bypass the fingerprint sensor by replacing it because they know that’s where the authorization is stored, that’s exactly what I’d want the phone to do.

You want your whole phone bricked by an update when it worked before, even though they can just disable the fingerprint scanner instead?

Re: Xerox scanners randomly alter numbers in scanned documents (2013)

#53

Earlier quoted context omitted.

As a user, that’s what I’d want it to do. If someone is trying to bypass the fingerprint sensor by replacing it because they know that’s where the authorization is stored, that’s exactly what I’d want the phone to do.

You want your whole phone bricked by an update when it worked before, even though they can just disable the fingerprint scanner instead?

Not just bricked but permanently and securely wiped, would be my preference.

Re: Xerox scanners randomly alter numbers in scanned documents (2013)

#54

Earlier quoted context omitted.

As a user, that’s what I’d want it to do. If someone is trying to bypass the fingerprint sensor by replacing it because they know that’s where the authorization is stored, that’s exactly what I’d want the phone to do.

You want your whole phone bricked by an update when it worked before, even though they can just disable the fingerprint scanner instead?

You are assuming it is fine to swap authentification hardware for incompatible parts? I guess this is from the spirit of "right t repair". While I get the idea in princple, I still think going dark is the best option you have if essential hardware was apparently tampered with. Find a back-alley smartphone shop which at least swaps your FP reader with compatible hardware. But if someone gained access to my phone, and put a piece of hardware in which is not recognized by the OS, I want it to stop right there. That doesn't feel like bricking, more like a security feature.

Re: Xerox scanners randomly alter numbers in scanned documents (2013)

#55
post #54

Earlier quoted context omitted.

You want your whole phone bricked by an update when it worked before, even though they can just disable the fingerprint scanner instead?

You are assuming it is fine to swap authentification hardware for incompatible parts? I guess this is from the spirit of "right t repair". While I get the idea in princple, I still think going dark is the best option you have if essential hardware was apparently tampered with. Find a back-alley smartphone shop which at least swaps your FP reader with compatible hardware. But if someone gained access to my phone, and…

This attack scenario doesn't make any sense. If your phone is out of your sight and unsecured for long enough to take it apart and replace the fingerprint sensor, it's unsecured and out of sight long enough to be entirely replaced by a clone that will steal all your credentials and send everything to whatever bad guy you are imagining

Re: Xerox scanners randomly alter numbers in scanned documents (2013)

#56
post #46

Earlier quoted context omitted.

When Apple introduced a fingerprint unlock in the home button, it wanted to keep the fingerprint scans secure. The security chip that stores the fingerprint scans needs to verify that the home button's fingerprint scanner is trustworthy, to prevent man in the middle attacks. However, when an unauthorized or unofficial button is used as a replacement for repair, the phone will permanently brick itself. No warning is g…

As a user, that’s what I’d want it to do. If someone is trying to bypass the fingerprint sensor by replacing it because they know that’s where the authorization is stored, that’s exactly what I’d want the phone to do.

Nice how some people try to justify Apple here.

I think the problem lies in this point:

>No warning is given ... Just straight to a permanent bricking.

There should have been a warning, at least, but there was none.

Re: Xerox scanners randomly alter numbers in scanned documents (2013)

#57

Earlier quoted context omitted.

As a user, that’s what I’d want it to do. If someone is trying to bypass the fingerprint sensor by replacing it because they know that’s where the authorization is stored, that’s exactly what I’d want the phone to do.

You want your whole phone bricked by an update when it worked before, even though they can just disable the fingerprint scanner instead?

Ah, I see the use case now-where you get it replaced by a 3rd party or buy a stolen phone, do you want it bricked by a software update? I don't know. I don't know that I care much about that use case TBH.

What I don't want is this: someone steals my phone and then replaces the fingerprint sensor and has access to everything, including the ability to reset and resell the phone.

Re: Xerox scanners randomly alter numbers in scanned documents (2013)

#58

Earlier quoted context omitted.

You want your whole phone bricked by an update when it worked before, even though they can just disable the fingerprint scanner instead?

Ah, I see the use case now-where you get it replaced by a 3rd party or buy a stolen phone, do you want it bricked by a software update? I don't know. I don't know that I care much about that use case TBH. What I don't want is this: someone steals my phone and then replaces the fingerprint sensor and has access to everything, including the ability to reset and resell the phone.

That’s not possible anyway because the phone can detect and reject the replacement sensor. If it couldn’t then how would it know to brick itself? Instead it should just fall back to PIN authentication, which is actually more secure and how it worked before the update

Re: Xerox scanners randomly alter numbers in scanned documents (2013)

#59
post #53

Earlier quoted context omitted.

You want your whole phone bricked by an update when it worked before, even though they can just disable the fingerprint scanner instead?

Not just bricked but permanently and securely wiped, would be my preference.

You want your own phone that you paid money for wiped and bricked remotely at random without your permission while you’re using it for no security advantage whatsoever (since it can just fall back to PIN authentication which is actually more secure than a fingerprint) until you give Apple money to “repair” it?

Re: Xerox scanners randomly alter numbers in scanned documents (2013)

#60
post #54

Earlier quoted context omitted.

You are assuming it is fine to swap authentification hardware for incompatible parts? I guess this is from the spirit of "right t repair". While I get the idea in princple, I still think going dark is the best option you have if essential hardware was apparently tampered with. Find a back-alley smartphone shop which at least swaps your FP reader with compatible hardware. But if someone gained access to my phone, and…

This attack scenario doesn't make any sense. If your phone is out of your sight and unsecured for long enough to take it apart and replace the fingerprint sensor, it's unsecured and out of sight long enough to be entirely replaced by a clone that will steal all your credentials and send everything to whatever bad guy you are imagining

And it won’t work anyway because the phone will detect and reject the sensor and just fall back to PIN authentication which is how it worked before the update
Post reply on HN