I know that in practice apple does use it to auth.
I know that in practice apple does use it to auth.
If you are afraid that some one will cut off your finger to unlock your computer don't use the touchID, that said if some one is willing to do that to unlock it i wouldn't want to imagine what they'll do to you to get the password.
;)
I don't buy this story or their "sources" at all. A zoomed in photo is enough to create a accurate 3d model? Really?
I might be naive at times, but this time I'm calling BS.
"He used $10 of ingredients you could buy, and whipped up his gummy fingers in the equivalent of a home kitchen. And he defeated eleven different commercial fingerprint readers, with both optical and capacitive sensors, and some with "live finger detection" features."
That article's a little old now and the tech may well have improved since but I wouldn't put too much faith in fingerprint readers. (Also: other attack vectors exist).
If they'll move to the new optical sensors the the refracted IR ones can sense the flow of blood in the veins of your finger.
So I agree with zwp (not sure why he was downvoted):
I wouldn't put too much faith in fingerprint readers.
There are plenty of people still using 4 digit passcode (especially simple ones like 0000 or 1234) which is easy to 'steal' by watching somebody unlock their phone before pickpocketing them.
Now some of the above issues aren't specifically in play with this particular app: It's locally owned/controlled hardware only. Also, as you say most of us aren't international spies (though I do find that getting a bit close to 'I have nothing to hide').
There is a missing link in the trust chain though, which is attestation of that secure enclave (how do we know it is a legitimate and uncompromised one?) However, privacy preserving attestation mechanisms such as DAA [1] require somewhat expensive crypto.
[1] https://en.wikipedia.org/wiki/Direct_Anonymous_Attestation
I am probably in a minority.
That seems like the best of both worlds there.