Live data from Hacker News

Apple’s Fingerprint ID May Mean You Can’t ‘Take the Fifth’

wired.com

91–100 of 141 posts

Re: Apple’s Fingerprint ID May Mean You Can’t ‘Take the Fifth’

#91
post #86
post #4

In practice, it might have the opposite effect. Currently, 4-digit PINs are (presumably) brute-forceable and the alternative of entering a longer, cryptographically-secure password every time you want to use your phone is impractical, so it doesn't really matter whether you can be legally compelled to divulge your PIN or not. However, with a fingerprint ID, you can now use a cryptographically strong password to encry…

Um, why do you think you can't brute force a fingerprint? The phone is covered with them, just copy one and use it.

That is not a brute force attack. That is the user covering the phone with the password.

Re: Apple’s Fingerprint ID May Mean You Can’t ‘Take the Fifth’

#93

Earlier quoted context omitted.

Honestly, I think it's because attacking Apple seems to be in vogue nowadays. Thus, if you have an article attacking Apple, you can guarantee higher click-thru rates. It really makes no sense. Fingerprint sensors have been built into Android phones (Atrix 4G comes to mind) since 2011 and in Windows laptops for many, many years. The sheer amount of articles discussing the Touch ID is actually astounding when you remem…

Attacking apple is still dwarfed by drivel praising apple. It also goes with the territory for any successful entity. I have been annoyed by people complaining about Microsoft since the 90s. Close to 2 decades of criticising. Turns out they were right.

>Turns out they were right.

What do you think they've been vindicated about exactly?

Re: Apple’s Fingerprint ID May Mean You Can’t ‘Take the Fifth’

#94
post #4

In practice, it might have the opposite effect. Currently, 4-digit PINs are (presumably) brute-forceable and the alternative of entering a longer, cryptographically-secure password every time you want to use your phone is impractical, so it doesn't really matter whether you can be legally compelled to divulge your PIN or not. However, with a fingerprint ID, you can now use a cryptographically strong password to encry…

That does you no good if you get nabbed with your phone in the decrypted but locked by fingerprint state. (which would be the common state since the password is a pain in the ass to enter if it's strong, so you do it on boot or something). So provided whoever has your phone can force you to put your thumb on your phone, forge your print, or cut off your thumb, they get your data.

Or fingerprint you at the detention center after you're arrested filming some cops beating a protester. Probably can just print it out to film and press it into the reader and open it. The CCC lifted the fingerprint of German Secretary of the Interior Wolfgang Schäuble from a glass he used at a panel discussion to prove how worthless fingerprints are for authentication.

Re: Apple’s Fingerprint ID May Mean You Can’t ‘Take the Fifth’

#95

Earlier quoted context omitted.

> 4-digit PINs are (presumably) brute-forceable True, but iOS does have an option to wipe the phone after 10 unsuccessful PIN attempts. Given that iCloud backup is pretty simple to setup, there's no reason not to configure this option, IMO.

Yeah, but the court can still get a warrant for the iCloud data, which I am almost certain isn't store in encrypted form or at least in an encrypted form for which Apple does not have the keys. You really need to use iTunes and an app like PhoneView for backing up all your data locally and storing that data in encrypted form outside the jurisdiction of your country.

Except police malware such as FinFisher/FinSpy specifically uses Itunes updates to break into iOS

Re: Apple’s Fingerprint ID May Mean You Can’t ‘Take the Fifth’

#96
post #4

In practice, it might have the opposite effect. Currently, 4-digit PINs are (presumably) brute-forceable and the alternative of entering a longer, cryptographically-secure password every time you want to use your phone is impractical, so it doesn't really matter whether you can be legally compelled to divulge your PIN or not. However, with a fingerprint ID, you can now use a cryptographically strong password to encry…

A fingerprint is an identification, not a passphrase. On top of that a fingerprint is very easy to obtain (especially on an iPhone where it might even by ready available on the button that reads it). A PIN on the other hand is a passphrase. The fact that a fingerprint is very unique doesn't mean that it isn't easy to discover and replicate or that it's difficult to use a copy of it.

Re: Apple’s Fingerprint ID May Mean You Can’t ‘Take the Fifth’

#97
post #56

> Take this hypothetical example coined by the Supreme Court: If the police demand that you give them the key to a lockbox that happens to contain incriminating evidence, turning over the key wouldn’t be testimonial if it’s just a physical act that doesn’t reveal anything you know. However, if the police try to force you to divulge the combination to a wall safe, your response would reveal the contents of your mind —…

They should have written that, then. Instead they wrote "to be a witness against himself".

Considering that the legal entire legal system practically runs on fine definitions such as these (witness against oneself != implicate oneself), and also considering that it's a judge's job to attempt to successfully translate a centuries old document based on jurisprudence, case law, etc, your opinion on intention is worth precisely jack and squat.

(As is mine and pretty much everyone else's here...)

Re: Apple’s Fingerprint ID May Mean You Can’t ‘Take the Fifth’

#98
post #34

Earlier quoted context omitted.

Are you sure you can brute force the PIN? I thought the iPhone will enforce a waiting period after too many bad entries.

I believe the idea is that if the encryption key is protected with only 4-digits, you could brute-force it offline (if you cracked open the phone and de-soldered stuff). If the encryption key is protected with a secure passphrase (as, for example, PGP private keys typically are) then that attack becomes a lot less feasible.

Yeah, the online attack defence like a short password is sufficient to defeat most attacks so long as root is not enabled, and Google/Apple don't comply to remotely unlock the device or reset the password (or you have all google framework apk's ripped out, or not built). The phone should reboot or wipe itself, or timeout or do something besides allowing unlimited attempts.

The offline attack you need a password suitable for protecting against police GPU cloud running john the ripper. Android you can set this up (2 different passwords), but should then make a script that deletes adb and su, add it to rc.local and reboot. Also helps to sabotage the recovery partition so it deletes user data should anybody try to flash something to system image

There's also mobiflauge, which is experimental deniable encryption and has 2 passwords, one to open a decoy install and one for your secret files full of stolen government intel you took pictures of to fool casual searches, and not ripped apart JTAG forensics.

Re: Apple’s Fingerprint ID May Mean You Can’t ‘Take the Fifth’

#99

Earlier quoted context omitted.

Honestly, I think it's because attacking Apple seems to be in vogue nowadays. Thus, if you have an article attacking Apple, you can guarantee higher click-thru rates. It really makes no sense. Fingerprint sensors have been built into Android phones (Atrix 4G comes to mind) since 2011 and in Windows laptops for many, many years. The sheer amount of articles discussing the Touch ID is actually astounding when you remem…

Attacking apple is still dwarfed by drivel praising apple. It also goes with the territory for any successful entity. I have been annoyed by people complaining about Microsoft since the 90s. Close to 2 decades of criticising. Turns out they were right.

The endless criticism of Microsoft over the last 20 years was generally that they're not open source and had anti-competitive practices (ex, the browser wars.) How exactly has Microsoft's comeuppance had anything to do with these aspects? Their fall has been due to their shitty design sense and their inability to see the PC era ending.

Re: Apple’s Fingerprint ID May Mean You Can’t ‘Take the Fifth’

#100
post #57

The way everyone's talking, you'd think Apple was taking away the four-digit PIN! But they're not... The fingerprint ID is just another option , which you don't have to use . So titles like this are just incorrect. Fingerprint ID isn't taking away any of your rights, because you can still use the PIN just like you always have . I mean seriously, what the heck is going on here? Why on earth are people getting worked u…

> The way everyone's talking, you'd think Apple was taking away the four-digit PIN! But they're not... The fingerprint ID is just another option, which you don't have to use. That's never how it works. Today it's "just another option", a few years down the line it's mandatory. And "not having to use" does not equal "people will not use it unless they are fully aware of possible consequences" anyway.

Oh, that's "never how it works?" You must be full of concrete examples that I will patiently await you posting here.
Post reply on HN