It's mentioned in the video as well: http://www.apple.com/iphone-5s/videos/#video-touch
It's mentioned in the video as well: http://www.apple.com/iphone-5s/videos/#video-touch
That's what I means by "we have to consider the iPhones backdoored". Once you can't trust the device any more, all bets are off and thus we can't be sure that what Apple says they do with that fingerprint is what they actually are doing.
(edit: regarding jailbreaking, I seriously doubt that a sufficiently well-hidden backdoor would be found by a jailbreaker. Or have we found the backdoors in OSX or Windows yet? Since the latest leak, we know they are there)
They might want to do approximate matching, though. That could make it hard or impossible to do without the decryption key.
edit: Also, there is a difference between a subtle crypto vulnerability and sending data to a server that, according to the announcement, is designed to be protected in its own enclave and never sent anywhere. The latter would be far more obvious in the code and easier to spot.
But we can't see the code. And it's far from certain you'd be able to pick it up through watching data packages.
good spy novel stuff... steal the prints of some foreign bigwig, or say Julian Assange, plant a copy in some compromising crime scene...
If you're going to do anything, including working on the computer you're typing your comments on, you have to trust a lot of parties. Some of that trust involves knowing who made the code, and some of it may involve the knowledge that the NSA will not be using their best, most secret backdoors against a whole lot of people.
If they send out 8 bytes of your fingerprint data hidden in every picture you take (so your fingerprint can be regenerated by looking at your first 500 pictures) I doubt anyone will ever find it.
Makes perfect sense.
How many webapps have encypted and stored their users password "only on their own servers", to later have them leaked via combination of exploit in 3rd party software that allowed the download of their DB and a little brute force?
Only difference on an iPhone is that there are literally 100s of thousand of apps that can possibly be exploited
Additionally -- if things are like they used to be when I was in the biometrics world in the mid-90s -- the fingerprint template will be small and work like a one way hash; if you have the template you cannot reconstruct the fingerprint from it. It wouldn't really be very useful to the NSA or anyone else.