Apple’s Fingerprint ID May Mean You Can’t ‘Take the Fifth’
wired.com
wired.com
The fingerprint ID is just another option, which you don't have to use.
So titles like this are just incorrect. Fingerprint ID isn't taking away any of your rights, because you can still use the PIN just like you always have.
I mean seriously, what the heck is going on here? Why on earth are people getting worked up about this? Sure, the fingerprint ID might be less secure, and it's important to realize that, but nobody's forcing you to use it. According to everything reported so far, the new iPhone is not removing your PIN.
It's still important to let people know the potential pitfalls of such a method, even if it's one option amongst many, so they can make an informed choice between the options.
> Why on earth are people getting worked up about this?
Because it has serious implications on your security, both from other people, and from the government (or its actors), implications which are not immediately obvious.
Also, keep in mind that there are a lot of features on the iPhone (such as the key-pad ASCII password option) which even tech-savvy folk don't know about, let alone the layman. This option of using a PIN could be just as hidden unless a big deal is made out of this (educated speculation, I know).
For years Apple has been denying direct access to finger-print reader, built-in behind your device's screen, but recent revelation shows that the backdoor is being widely used by the US government.
- "I didn't know they can do that, but hey if it keeps us safe then why not?" - says Jennifer Stone, Apple products fan. - "You know after we put the boots on Syrian grounds there has been so much terror retaliation on our soil that probably at some point they would require to finger-print every American, but this way thanks to my Apple device, the government has actually saved me a trip to the local police department for a full finger-print read. Its all good, you know. yolo!".
EDIT: breaking news September 11, 2020. A North Korean terrorist organization successfully hacked into NSA mainframe and downloaded over 25 terrabytes of data related to american's social security records and credit card information. they also obtained driver's license database as well as DNA and fingerprinting records for over 300 million americans. The US government is going into full shut down; starting tomorrow everyone will start receiving new credit cards, new social security numbers as well as new drivers license. Since DNA and fingerprinting information can be reproduced and faked quite cheaply, starting tomorrow no criminal case in the US legal system will be tried based on the evidence introduced from said sources.
- When 911 happened, we had terrorist using our infrastructure, our planes, our airports and our buildings to cause terror. Who would have known that 20 years later storing detailed information on 300 million Americans under one roof in one building would be so hazardous to the National Security. - said independent security contractor.
It really makes no sense. Fingerprint sensors have been built into Android phones (Atrix 4G comes to mind) since 2011 and in Windows laptops for many, many years. The sheer amount of articles discussing the Touch ID is actually astounding when you remember that Google's Face Unlock was cracked originally by a _photo_ of the user and then cracked with _two_ photos of the person. There are real, actually implemented cracks for Android's lock screen but that's been grossly overshadowed by the conceptual idea of possibly cracking Apple's Touch ID.
Wired is simply reporting the news and making people aware of potential pitfalls with using fingerprint ID on a device like this. Smartphones and tables are very popular now so what is in vogue is reporting on them.
Thanks to revelations of NSA surveillance of the last few months, these privacy-related topics are coming up more frequently now.
And, well, there's this...
1. http://venturebeat.com/2013/09/09/nsa-calls-iphone-users-zom...
2. http://www.spiegel.de/international/world/how-the-nsa-spies-...
I have been annoyed by people complaining about Microsoft since the 90s. Close to 2 decades of criticising. Turns out they were right.
What do you think they've been vindicated about exactly?
I would suggest that Apple is heading the same way but not literally. They are certainly closed source, about as bad as it gets, they are using their financial and political muscle to bully competitors and suppliers, they are coming back to the field in terms of innovation....
Touch ID requires both a fingerprint and a PIN. If the phone hasn't been unlocked in 48 hours or has been rebooted, you have to enter the PIN. This would probably protect your 5th amendment rights in the case of going to court (since it would probably take >48 hours).
Touch ID is there to make PINs more widely adopted, by minimizing the inconvenience of entering a PIN every single time. That's a great boost for security.
Source: http://blogs.wsj.com/digits/2013/09/11/apple-new-iphone-not-...
It would be nice if you could adjust the 48 hour timeout.
That's never how it works. Today it's "just another option", a few years down the line it's mandatory.
And "not having to use" does not equal "people will not use it unless they are fully aware of possible consequences" anyway.
That's just FUD. And saying baseless things like "that's never how it works", that's just fearmongering, not contributing to the conversation. It doesn't even make sense.
There are millions (hundreds of thousands? you get my point) of fingerprint readers out there. Suddenly Apple builds one in, an additional feature, and people start inventing conspiracy theories. People are completely confusing real issues (recent NSA disclosures) with totally imaginary ones. It's getting tiring.
But did you know how many fingerprints are currently being gathered and kept by US government?
Here's a 2008 article. (http://www.reuters.com/article/2008/03/25/us-security-finger...)
They take a lot of fingerprints, but don't seem to catch many people.
> The U.S. government has been collecting digital fingerprints and photographs of nearly all non-citizens aged 14 and up entering the country since 2004, officials said, in a Homeland Security program called US-VISIT, at a cost of $1.7 billion.
> [...] On an average day, almost 14,400 international visitors undergo the fingerprinting process at Kennedy, officials said.
> More than 2,000 criminal and visa fraud cases have been detected by the screening process, introduced in response to security concerns following the attacks of September 11, 2001, U.S. officials said. Roughly they've scanned fingerprints for 36,792,000 visitors (who may be repeat visitors), and caught more than 2,000 people. (Between 2001/9/11 and 2008/9/11.)
Repeat visitors are fingerprinted on each visit.
I agree it is not directly connected to Apple, or the US, but there is a progressive and gradual creep into the acceptance and use of biometric data.
Links:
- U.S. inquires about India’s UID project (http://secureidnews.com/news-item/u-s-inquires-about-indias-...)
The Evolution of India’s UID Program Lessons Learned and Implications for Other Developing Countries (http://www.cgdev.org/files/1426371_file_Zelazny_India_Case_S..., Section 3: Implications for other countries)
- Biometric Sensors in new iPhone Can be a Game Changer in India (http://www.nextbigwhat.com/biometric-sensors-new-iphone-in-i...) [Clueless piece, but highlights potential connections b/w iPhone biometrics and other ID projects]
- Opposition to the world’s biggest biometric identity scheme is growing (http://www.economist.com/node/21542814)
It makes perfect sense -- you just need to follow the historical precedents, instead of looking for some inevitable logical reason why that would happen.
Technologies introduced with the potential to control and restrict people (or users) have always expanded their scope and reach.
CCTV was something banks used. Now it's all around modern cities. GPS tracking was once something exotic. Then millions could be tracked through their mobile phone. Then you even get people voluntarily participating in "location aware" services, transmitting their location 24/7. Walled garden software was few and far between all through 1980-2010. Now it's the sole standard on iOS, de facto on Android, and has crept in desktop OS too. There are tons of similar examples.
>There are millions (hundreds of thousands? you get my point) of fingerprint readers out there.
There were also "tens of thousands" of tablets before the iPad. Still noone cared about them. Mass sales are an enabler. It's another thing for "hundrends of thousands" (far fewer, I'd say) fingerprint readers to be out there in places and devices noone sees excepts when he travels or if he works in some special places that use them for security, and another thing to have fingerprint readers on 1 out of 3 or 4 americans (the iPhone market share IIRC).
>Suddenly Apple builds one in, an additional feature, and people start inventing conspiracy theories.
I don't care much about conspiracy theories (and I dislike the use of the term to ridicule legitimate concerns, as if we were talking about fake moon landings or UFOs). This comment thread was about some not far-fetched potential implications.
Yes, that's why you can't get on the internet except through AOL any more.
Walled garden software was few and far between all through 1980-2010.
What nonsense.
I don't see any justification for your sarcasm.
It might not be called AOL today, but between FB and Google you have a even more widespread and far reaching modern equivalent. Add Youtube, Android, Google Fiber and Glass to the mix and the control and information gathered is even more than what was there to AOL's wildest dreams.
And between Google Search and Gmail, it's even less easy to switch to than from AOL. AOL was all disanvatages, whereas Google Search is best of class, as is Gmail. People are even afraid to leave FB (you see it all the time, even on HN threads) because of peer pressure and the effect on their social life. Leaving AOL never had that.
>What nonsense.
iTunes Store, Mac App Store, Windows Phone Store, Google Play Store, console software, etc etc. So called "post-PC" devices like the iPad have adopted the walled garden approach, that's not something to be argued, it's a fact.
Do you have any counter-examples, or just wanted to insult my response with the content-less reply of "nonsense"?
iTunes Store, Mac App Store, Windows Phone Store, Google Play Store, console software, etc etc. So called "post-PC" devices like the iPad have adopted the walled garden approach, that's not something to be argued, it's a fact. Do you have any counter-examples, or just wanted to insult my response with the content-less reply of "nonsense"?
Yeas, but your claim was that this is a new thing. Go back and look at home computers in the 1980s or networking hardware in the 90s. Walled gardens have been around for ages: it was the basis of the AT&T monopoly that existed until the 70s (see http://en.wikipedia.org/wiki/Walled_garden_(technology)) and used to be the norm in the motion picture industry at one time before antitrust actions forced the studios to divest their theater holdings.
Really, it's up to you to back up your own claims, not up to me to falsify them. You have a bad habit of drawing your conclusion first and then looking for evidence to support it. I personally find it helpful to begin by assuming I'm wrong and trying to falsify my hypothesis.
And what better way to prove it than to cherry-pick examples.
Examples are always cherry picked. The other option is called "exhaustive enumeration", and I don't think it's possible.
Let's just say that 50 years ago,
1) nobody could track your exact position 24/7, 2) there was not fingerprint matching, 3) you could still dissapear in a remote place with much fewer chances of people finding you 4) your friends didn't post pictures of you for all the world to see 5) people were not required to carry some sort of ID cards 6) your purchases could not be tracked in real time (cach or cachiers check's, no credit cards) 7) all your (snail then) correspondence was not automatically and efficiently read 8) CCTV wasn't prevalent 9) radio couln't track what you were listening to (as Pandora etc) 10) nobody kept track of what movies you watched (like Netflix, Youtube, etc) 11) They could track cars by reading their plates of some camera.
etc etc. And tons of other stuff besides.
It's nice living in a dream bubble, but all these do exist, and are a real tendency in a higher technological society. After all bureacracy and control with expand given the chance (and with the lack of any counter tendency), and technology is a huge enabler for it to expand.
It's as if someone invented a key you could turn to remember whatever you forgot. Great invention, but the article is saying: be aware, turning the key is not self-incrimination, and so now you have no 5th amendment.
It's not about boring people living boring lives. They can go on doing whatever and not care. This is about people whose rights get violated, people that do things, from investigative journalism, to politics, to corporate whistleblowers, etc.
And it's not just about some boring, cozy little suburbian part of the world (as if Nowheresville, Iowa and Sunville, California is all there exists), it's also about people living in oppressive regimes, fucked up governments etc.
Those people push society forward. If it were only for people whose "lives are not profound", then we would still have slavery, no women's vote, no gay rights, and 15 hour workdays (including for children).
There is no slippery slope here. You think Android manufacturers blindly follow where Apple leads? At the very worst Apple will sign iOS's death warrant at that point.
I don't believe people, and much more, hackers, would deny that PC and technology gets more restrictive, and companies like to push that as much as they can.
Here's a few examples:
1) You could change the memory of a Mac laptop (but not with current versions where it's purposefully glud to the board).
2) You could expand a Mac Pro, change GPU, even CPU, etc (but not with the new version).
3) You could change the battery of older iPods, not with newer models, iPhones or iPads.
In general, todays more prevalent forms, from laptops to tablets are not user servicable like desktops (and even laptops) used to be.
4) You used to run anything on OS X without any restrictions. Now OS X added code signing and a mode that only let's you run signed-apps (and another mode that only let's you run only App Store apps).
5) Older (windows) tablets run everything. Then the iPad come that only runs iTunes Store iOS apps (without a jailbreak). Every company started adding stores (Play store, Windows store) to their offerings.
6) You could change GUI themes in Mac OS (Kaleidoscope, etc). Not with OS X.
7) Windows just needed a serial code from the box you bought. Then internet activation became mandatory. In general, software using the internet for purchase validation was few and optional. Now most software has some form of mandatory "activation" step.
8) You could buy Creative Suite in a box and use it forever. Now subscription is mandatory.
You can find tons more examples. Either stuff gets incrementally locked down or something cames along and replaces the previous form with a more restricted newer one.
You might want to reduce your sarcasm and read on this:
Bullshit.
So which one is causing these threads?
Maybe not, but the mechanism still exists to capture your finger print — even if it's "turned off".
You may as well set up a location-aware tweet to broadcast "I'm here" every time you hit that home button.
It's an Apple release. The tech press is _required_ to act like any Apple release contains at least one thing that is the second coming of Mecha-Hitler; it's the law.
Personally, I'd trust a 4-digit pin with a lockout timer to stand up better than fingerprint authentication. It looks cool in the movies, but it's never been a very bright idea.
Of course, most won't care if it's insecure, and being able to set different functions to automatically execute based on scanning different fingers (an ability laptop scanners have had for years) is certainly a selling point.
But I mean, a fingerprint is a physical thing which can be cloned, just like a key. And you also leave prints everywhere you go. It's not a silver bullet in authentication. All else being equal, passwords are safer against a determined attack, if we can assume correct usage.
In particular, tools automating (b) already exist: http://gizmodo.com/5896992/the-xry-cracking-tool-is-unimpres...
However, with a fingerprint ID, you can now use a cryptographically strong password to encrypt your phone (which you have to enter on device boot or after 48 hours of the device being idle [1]), while still having the convenience of actually being able to use your phone once it's on via the fingerprint scanner. So I see that as a security win.
Of course, Wired's premise isn't even valid in some countries, e.g. the UK, which have powers to legally compel you to hand over your passwords regardless. For all I know this is true in the US too.
[1] http://9to5mac.com/2013/09/11/apples-details-fingerprint-sen...
1. If the prosecutor can prove that incriminating evidence is encrypted, you can be compelled.
2. If you ever divulged your passphrase to the government or provided the plaintext, you can be compelled.
3. If you have not divulged the passphrase and the government has no proof that incriminating evidence is encrypted, you cannot be compelled.
If I remember correctly, the prosecutor cannot both compel you to give up a passphrase and use your knowledge of the passphrase as evidence against you (e.g. to prove that you controlled the computer in question).
Yep:
Elcomsoft iOS Forensic Toolkit[1]
* Instant passcode recovery for all iOS versions up to iOS 3
* Simple 4-digit iOS 4/5/6 passcodes recovered in 10-40 minutes
I think you missed the fairly huge disclaimer hidden away at the bottom of the page:
> iPhone 4S, iPhone 5, iPad 2+, iPad Mini and iPod Touch 5th gen support is limited to jailbroken devices only (iOS 5 and 6).
The chances of a target device being jailbroken are not particularly large. This should, of course, serve as a reminder that if you are running a jailbroken device you should probably have a passcode a little more complex than four digits!
[1] http://www.appleexaminer.com/iPhoneiPad/iOSAnalysisTools/iOS...
EDIT: This device was found on the AppleExaminer page:
http://www.cellebrite.com/forensic-solutions/ios-forensics.h...
"Using UFED Physical Analyzer, physical and file system extractions, decoding and analysis can be performed on locked iOS devices with a simple or complex passcode. Simple passcodes will be recovered during the physical extraction process and enable access to emails and keychain passwords. If a complex password is set on the device, physical extraction can be performed without access to emails and keychain. However, if the complex password is known, emails and keychain passwords will be available."
My son has verified this personally...
The offline attack you need a password suitable for protecting against police GPU cloud running john the ripper. Android you can set this up (2 different passwords), but should then make a script that deletes adb and su, add it to rc.local and reboot. Also helps to sabotage the recovery partition so it deletes user data should anybody try to flash something to system image
There's also mobiflauge, which is experimental deniable encryption and has 2 passwords, one to open a decoy install and one for your secret files full of stolen government intel you took pictures of to fool casual searches, and not ripped apart JTAG forensics.
True, but iOS does have an option to wipe the phone after 10 unsuccessful PIN attempts. Given that iCloud backup is pretty simple to setup, there's no reason not to configure this option, IMO.
You really need to use iTunes and an app like PhoneView for backing up all your data locally and storing that data in encrypted form outside the jurisdiction of your country.
http://images.apple.com/iphone/business/docs/iOS_Security_Oc...
The phone is covered with them, just copy one and use it.
> When a person has a valid privilege against self-incrimination, nobody — not even a judge — can force the witness to give that information to the government.
The Fifth Amendment explicitly outlines that you cannot successfully "plead the fifth" in response to a grand jury compelling you to testify.
Perhaps you are confusing the first and the second clause of fifth amendment?
Basically this issue is totally sidelined by this feature.
Phones are getting stolen and compromised because people are too lazy to do the PIN thing, I suppose...but it never seemed like it was in Apple's best interest to make phones brickable.
They may be lining up for banks or other authorities to start allowing finger print recognition in their systems and apps to make bank transfers or pay for items in general and that your finger print would be the authorisation.
It may be one level more secure when they implement NFC.
I don't know though, I doubt they have done it simply because people want to unlock their phones 1 second faster.
So it's a trade off, giving up security against a determined threat for a gain in security against casual threats.
Since a fingerprint scan is faster, it is security I would probably use. (And the hyperventilation about hypothetical 5th amendment issues doesn't bother me one iota.)
The feature is meant to make using an iPhone more secure for those of us who tend to leave our phones unlocked and PIN-free.
If you're storing anything of value on your phone, the existing password-based and PIN-based lock mechanisms aren't going away any time soon. If nothing else, it'd break too many organizations' Active Directory configurations.
You're in court. You refuse to admit/verify the accusation that you were in the vicinity of the deceased's home. Cell phone records, dutifully recorded and reported under warrant from NSA...er...ATT, show your phone - which you are known to carry pretty much everywhere - was in that vicinity at the crime's time. You contend that does not constitute evidence. The phone is acquired, bailiff places your finger on your Fingerprint-ID-secured phone, phone unlocks, evidence thereon shows activity during that period. So much for your 5th Amendment right against self-incrimination.
Most users don't care that their phone could be used against them in a court case. Maybe they should, but they don't, and pretending Fingerprint ID should be a form of two-factor authentication for your phones is silly. If users cared, they could use a passcode and the fifth amendment to protect them. It is far more likely for the average user to lose their phone by dropping it somewhere outside.
At this time, we can't even get most users to use one-factor authentication. Hell, the mass media perpetuates feel-good stories where kids use an unlocked lost phone to return it to their owners[0], so even with this technology you'll have a hell of a time convincing people to lock their phone with even a 4-digit PIN.
Stallman et al. have been telling us "your closed-source phone is spying on you" for years now, and it's clear that the education hurdle is far bigger than "fingerprints are self-incriminating". Just look the first half of the byline for [1] -- "The boy addicted to porn; the girl who let herself be sexually assaulted to get her BlackBerry back".
[0] http://www.huffingtonpost.com/2013/08/21/kids-find-phone_n_3... (original at http://www.kym4.com/4/post/2013/08/awesome-lost-found.html)
[1] http://www.theguardian.com/film/2013/sep/08/beeban-kidron-in... (posted as https://news.ycombinator.com/item?id=6373073)
The phone company can testify that the phone corresponds to a given cell number. Other people can testify that they spoke to the defendant on that number. No one piece of evidence exists in a vacuum; all the pieces of evidence combine to paint a picture.
Sure you could try to lie by making up stories about how the phone wasn't really yours, but it's hard to get all the other evidence to line up with a lie. This is a GOOD thing; the protection against self-incrimination isn't intended to help people get away with murder, it's intended to protect the accused from being compelled to help the government prosecute them.
I'm not contending the "wasn't really yours" point. Phones get stolen, misplaced, left behind, etc. with enough frequency that "it's your phone and it registered/triangulated with this position" may be strong circumstantial evidence but still isn't proof. That it was used in a manner requiring your finger (still attached to your body) does.
Don't get me wrong, I'm with you on protecting the accused from compulsion to self-incrimination. Just observing that the fingerprint sensor, coupled with the enormous data being collected on/about the device, isn't helping 5th Amendment rights.
For the average non-criminal, the likelihood of ever being both falsely accused and falsely convicted based on evidence from an iPhone is almost infinitesimally small. Considering that if you didn't do the crime, if anything the phone should exonerate you.
The fairly rare cases of something 'bad' happening and getting falsely accused shouldn't be the basis of making tech decisions. A similar logic would compel us to never ride in a car, since the threat profile of an auto fatality is much higher than that of being forced to incriminate yourself with an iPhone. Decisions should be based on a risk management profile. If you tend to hang out with criminals, then your risk management profile would be different than someone who works at home and only goes to the gym once in awhile. And if you are a criminal, you'd be foolish to use any identifiable electronics devices at all. Your retired aunt Sarah who hangs out at the hair salon and church food pantry would hardly need to be as paranoid as a guy who's good friend is an ecstasy dealer. There's no reason worry about that exceptionally rare situation where you suddenly find yourself in the middle of a real-life Law and Order episode. There are plenty if other, more realistic things to worry about in terms of digital security than being forced to fingerprint in a courtroom.
Touch ID is optional, if a user feels particularly concerned, about legal implications of this, it is perfectly valid to revert to a passcode. I am glad that this article/discussion exists though, it is good to know what risks may exists using new security systems.
[Edited to add: just read somewhere else that after 48 hours of inactivity or a reboot, user must re-enter passcode before fingerprint will unlock the device. This would seem to protect from the case stated in the article.]
BS interpretations like these make the legal system a big bad joke.
The original intention clearly had nothing to do with whether it was something out of your mind or not, and all to do with not being forced to implicate yourself.
Considering that the legal entire legal system practically runs on fine definitions such as these (witness against oneself != implicate oneself), and also considering that it's a judge's job to attempt to successfully translate a centuries old document based on jurisprudence, case law, etc, your opinion on intention is worth precisely jack and squat.
(As is mine and pretty much everyone else's here...)
To reclaim your freedom, just switch to open-source solutions.
Sounds messed up, but it's certainly a possibility. Since the finger is not the evidence itself, I don't think this would constitute destruction of evidence, and so long as it is done before the court asks you to unlock the device, it should not result in contempt of court. However, this is all uncharted territory and IANAL.
only until it is an attached part of your body :) I can see how destroying the tip of your finger and cutting after that is ok, while in reverse would be a destruction of evidence.
In the case where the brain is dead, removing the finger is way easier.
I am not sure how that balances out, but I am sure two-factor authentication (fingerprint plus password) beats either.
Something you have: fingerprint Something you know: PIN
Combine the two and you can be fairly sure only the owner has access to whatever's being protected.
Competent authorities will not access your phone through the phone interface, they will just image the data on it. Unless you encrypt data on your device with a strong key, they will get all your data anyway.
If the argument is valid it seems that it could also be applied to public key encryption.
Why not just do that?
For instance, I recently heard of an older couple who allowed the husband's brother to visit them to talk about a new business he was in. Essentially he wanted to visit the couple with his "mentor" because he needed to "practice". At the end of their visit the couple had been persuaded to: join the "business" as members, for a monthly fee, which was going to be charged to their credit card. THIS WAS OBVIOUSLY A PYRAMID SCHEME! Anyways, after the visit, the terrified the woman immediately called the bank and had them cancel the card, so everything ended up being okay. Imagine if they had handed over their fingerprints! You won't be able to call the bank to tell them to send you a new fingerprint.
How about "two-factor authentication"? Think that would ever catch on???
Deleted comment