Now, you don't usually type the username when you run sudo, do you? That's because most of the time, the username can be gleaned from context. For example, "Which user is this process running under?".
So, if TouchID's purpose was just to supply identification and not any verification that the identification is legit, that would be pretty pointless.
I know that in practice apple does use it to auth.
I am probably in a minority.
That seems like the best of both worlds there.
"He used $10 of ingredients you could buy, and whipped up his gummy fingers in the equivalent of a home kitchen. And he defeated eleven different commercial fingerprint readers, with both optical and capacitive sensors, and some with "live finger detection" features."
That article's a little old now and the tech may well have improved since but I wouldn't put too much faith in fingerprint readers. (Also: other attack vectors exist).
If they'll move to the new optical sensors the the refracted IR ones can sense the flow of blood in the veins of your finger.
So I agree with zwp (not sure why he was downvoted):
I wouldn't put too much faith in fingerprint readers.
There are plenty of people still using 4 digit passcode (especially simple ones like 0000 or 1234) which is easy to 'steal' by watching somebody unlock their phone before pickpocketing them.
Now some of the above issues aren't specifically in play with this particular app: It's locally owned/controlled hardware only. Also, as you say most of us aren't international spies (though I do find that getting a bit close to 'I have nothing to hide').
There is a missing link in the trust chain though, which is attestation of that secure enclave (how do we know it is a legitimate and uncompromised one?) However, privacy preserving attestation mechanisms such as DAA [1] require somewhat expensive crypto.
[1] https://en.wikipedia.org/wiki/Direct_Anonymous_Attestation
If you are afraid that some one will cut off your finger to unlock your computer don't use the touchID, that said if some one is willing to do that to unlock it i wouldn't want to imagine what they'll do to you to get the password.
;)
I don't buy this story or their "sources" at all. A zoomed in photo is enough to create a accurate 3d model? Really?
I might be naive at times, but this time I'm calling BS.
And I'd have to agree, fingerprints are a terrible substitute for a passphrase.
[1] http://blog.dustinkirkland.com/2013/10/fingerprints-are-user...
The bigger issue I see is that 'rrmm' is an identity I assumed. I have many different identities. I only have one set of finger prints. (Fingerprinting to unlock a local store of keys would fix some of this problem, but I am fond of plausible deniablity in identification).
If a biometric sensor can be tricked by a body part that is no longer attached to the body, that's a serious issue. But AFAIK at least modern sensors try to verify if it's still alive and then there's also the biological effect that a body part quickly changes its properties if it is no longer supported by the body.
The biggest danger in that is probably criminals who don't know that it is likely that a detached body parts stops functioning.