Earlier quoted context omitted.
> I think they're missing the point. The passcode on an iPhone defends against other people in your environment - family members, coworkers, roommates - getting your information opportunistically. It doesn't defend against hackers, the government, or even slightly savvy thieves. The Google Chrome Security team begs to differ [1]. According to them giving someone the illusion of security is bad. [1] https://news.ycomb…
Which is an incredibly absurd position, in any context. Security is not binary.
Chaos Computer Club breaks Apple TouchID
91–100 of 458 posts
Re: Chaos Computer Club breaks Apple TouchID
#92Earlier quoted context omitted.
Giving Apple a break? Just another layer of security? That's not how Apple describes it: http://support.apple.com/kb/HT5949?viewlocale=en_US And selling a stolen iPhone on eBay does not need a password or a fingerprint, a jailbreak is enough …
Jailbreak is enough... When it exists. And for now it doesn't.
Re: Chaos Computer Club breaks Apple TouchID
#93Honestly, TouchID is better than what we have today; a 4 digit useless passcode. If somebody has to take a photo of my fingerprint off a glass surface to gain access to my phone, so be it.
Re: Chaos Computer Club breaks Apple TouchID
#94I thought, based on anandtech review, that this scanner is not optical but electrical, hence "sub epidermal scanning", so why does a printed finger work?
- the capacitance of the ridges and crests of one's fingerprint dominates any differences in subcutaneous capacitance (possibly because they are closer to the scanner, or because there simply is too little variance in capacitance between flesh and hair veins)
- subcutaneous structures resembles fingerprints too much (seems quite possible, as there must be a reason that it is hard to permanently change one's fingerprints by using sand paper)
Aside: a Google found this procedure: http://www.zoklet.net/bbs/archive/index.php/t-202956.html I don't have the faintest idea whether that is real, but regardless, I don't recommend it.
Re: Chaos Computer Club breaks Apple TouchID
#95Re: Chaos Computer Club breaks Apple TouchID
#96Earlier quoted context omitted.
Frontline had an excellent piece on the (lack of) reliability behind most of crime forensics. Fingerprints in particular are mentioned as being very unreliable and unscientific. The only scientifically rigorous piece of "CSI" is DNA matching. http://www.pbs.org/wgbh/pages/frontline/real-csi/
And now even DNA is being called into question. http://mobile.nytimes.com/2013/09/17/science/dna-double-take...
Re: Chaos Computer Club breaks Apple TouchID
#97Earlier quoted context omitted.
Agreed. But they always blow it out of proportion. As if the existing fingerprint systems are extremely insecure and theirs is not. The truth is they are all the same- insecure.
Theirs is better than the standard old fingerprint scanners and far better than using 'nothing' which is what they are replacing. They have blown nothing out of proportion.
Re: Chaos Computer Club breaks Apple TouchID
#98If we've learned anything over the past few months, it is that security is an illusion when it comes to Google, Apple and Facebook. The fingerprint scanner is not intended to protect your personal data from being accessed by nefarious cyber-spooks or crackers. The $5 dollar wrench technique is fairly effective in bypassing such security anyway. The fingerprint scanner is there so that when your phone is nicked by a m…
Regardless of whether or not fingerprint scanners are good security wise, it's a bit silly to think that phone robbing thugs are completely dim. The way it works in my first world modern country is that there are shops everywhere that unlock or reset phones as part of their services, and it isn't thugs running them. It's people with an affinity for 'tech' who just happen to deal with a shadier area. If cracking finge…
Re: Chaos Computer Club breaks Apple TouchID
#99I think they're missing the point. The passcode on an iPhone defends against other people in your environment - family members, coworkers, roommates - getting your information opportunistically. It doesn't defend against hackers, the government, or even slightly savvy thieves. Also, if a fingerprint sensor is significantly easier to use, and in practice will deter a class of privacy violations, it could increase over…
> I think they're missing the point. The passcode on an iPhone defends against other people in your environment - family members, coworkers, roommates - getting your information opportunistically. It doesn't defend against hackers, the government, or even slightly savvy thieves. The Google Chrome Security team begs to differ [1]. According to them giving someone the illusion of security is bad. [1] https://news.ycomb…
Name one security technology that is 100% foolproof. They don't exist. So the point isn't to rely on one thing, but to rely on many things that, used in concert, increase the risk, complexity and cost associated with subverting the entire system--not its individual components.
Re: Chaos Computer Club breaks Apple TouchID
#100Earlier quoted context omitted.
Even DNA can provide false negatives in the case of human chimeras.
Or just someone skilled enough to place fake dna in his body such that the person taking the sample is fooled into taking it from the fake dna. Yes, this really happened - at least once that we know of: https://en.wikipedia.org/wiki/John_Schneeberger
During his 1999 trial, Schneeberger revealed the method he used to foil the DNA tests. He implanted a 15 cm Penrose drain filled with another man's blood and anticoagulants in his arm. During tests, he tricked the laboratory technician into taking the blood sample from the place the tube was planted.