About Touch ID Security
support.apple.com
support.apple.com
> Not everyone will be able to use the fingerprint scanner feature. Some people lack the impedance necessary to activate biometric devices.
> Do not service or replace the device for issues with a specific finger(s). If the customer has an issue with certain fingers, explain that in some cases Touch ID may unable to match those fingers consistently. This is usually caused by the readability of that fingerprint, and the customer can either try enrolling the finger at a later time, or use a different finger for Touch ID.
Source: http://i.imgur.com/ku1KOUK.png
That'll be a new disadvantaged minority. I think I can imagine a sci-fi short story around this now ...
This is a tad disingenuous.
Fingerprint 101:
Fingerprint databases don't search images of your fingerprints. They search mathematical representations of your fingerprints.
To uniquely identify your fingerprint an image is scanned for unique features called "minutia points"[1]. The spacing and orientation of those points is what is stored and later searched for.
Fingerprint matching isn't boolean. When you do a database search you get a list of high probability matches. There are no perfect matches, even between two different images of the exact same finger. Everything is based on probability. For law enforcement purposes, strong matches result in a technician reviewing actual images and making comparisons. For biometric security like this (which is not my area) I expect that there is a threshold percentage match that must be met.
The reason this quote concerns me is that while the actual image can't be reproduced, the image isn't the part that matters! The "mathematical representation" is what counts.
Whether or not that information is actually secure onboard the phone, I don't know.
[0] I have worked with fingerprint processing systems.
[1] http://en.wikipedia.org/wiki/Fingerprint_recognition#Minutia...
Given that, the fingerprint reader will be an improvement for most people. It keeps the same level of security and makes people feel like they're in the future when they unlock their phones.
And that's besides the fact that the government could try to eventually collect all those fingerprints in some way.
Is there any evidence so far that these readers are better armed against the most trivial of attacks?
Another problem with all kinds of biometric authentication is of course that you can't exactly change your fingerprint. So if your credentials ever become compromised you have a bit of a problem.
Put differently, would you be comfortable leaving a copy of your passwords on everything you touch? If not, why not?
I bought my first real 'desktop replacement' laptop years ago, a Thinkpad T61P. It cost a fortune but it blew every other laptop I used away, and had a fingerprint reader which I though was really cool. Then I saw the YouTube videos starting to surface with people using gummy bears to defeat them. I was disappointed, sure, but I just disabled the fingerprint scanner and enjoyed the rest of the functionality of the laptop.
I think the sensible thing to do if you buy a new iPhone is to recognise Apple got it wrong with the fingerprint reader, and enjoy all the other cool features of your new phone. It isn't an 'all or nothing' proposition.
I also think there is an opportunity for Apple to offer users the choice whether the fingerprint should be used as the username or password.
I wonder why the 4 digit password became so standardized if it is as insecure as people think it is.
To actually transfer money out of any of my accounts to an unknown account requires two-factor authentication (and transfer to unknown accounts can't be done from a phone).
I find the balance of convenience and security fairly good in this instance.
I'm not really convinced, nothing is absolutely impossible in computer science. At least, can't we bruteforce it?
I'm curious to know if they are true saying there is no way to reverse-engineer it, Any paper on the subject?
Deal?
Though I wonder how they update it with failure attempts. (When a failed scan occurs, if the subsequent scan is successful then data is used from the failed scan to update the fingerprint data.)
So by a bruteforce technique, I could be able to generate a subset of all possible fingerprint (finite?).
Tell me if I'm wrong, but maybe by "cross checking" with another data (e.g. another device with a second different conversion algorithm) I could finally find out what was your fingerprint! That's quite overkill though!
Sure, but that's not the same as reverse engineering your fingerprint from the "mathematical representation".
It isn't possible for your actual fingerprint image to be reverse-engineered from this mathematical representation.
Let's say when you scan your fingerprint Apple breaks it down into three key properties, A B and C. Each fingerprint has a different percentage for A B and C. So yours might read as
A 50% B 30% C 0%
This data is then cryptographically hashed with some unique identifier inside the phone (so the same data would store differently on every iPhone). The data is then irreversibly transformed into a different representation. You can't retrieve the unique properties of the fingerprint, nor can you retrieve the fingerprint itself.
In the linked article, Apple states that the probability of two fingerprints matching in Touch ID is 1 in 50,000. So that just means that their algorithm for breaking fingerprints down into key features discards enough information that it is possible to read two different human fingerprints as the same fingerprint.
Impractical is a word I prefer. The reason it is impractical is firstly it is lossy not lossless data storage meaning that when your fingerprint is scanned a whole ton of information is discarded immediately and then the fingerprint is normalised which discards yet more still before being stored.
So the resulting data stored literally doesn't contain the same level of information as a "real" human fingerprint, and as a result of that the data might be useful in recreating a simulated fingerprint which can beat Apple's TouchID but it would likely still be incompatible with most other fingerprint systems and databases, and the fingerprint you recreated from the data likely wouldn't look like your "real" fingerprint as several million different fingerprints can result in the same lossy compressed representation stored in the phone.
Imagine it like taking a photograph and then using a JPG compressor to decrease that photograph's size by 80% an then trying to get back the original photograph from the compressed JPG. While you can certainly get close it is implausible that you'd ever get the original image back and even if you did get it back there is no way to verify that the "original" you recreated was the same as the actual original without the actual original to compare it to.
So eventually, if you can generate all possible set of fingerprints which match that hash and "cross check" it with another fingerprint systems, you could be able to approach the guy fingerprint? (I mean you maybe reduce the set to a reasonable size)
The use case is quite overkill though! Also, generating all possible set of fingerprints is probably a lot of computation.
I think the biggest potential problem with that approach is both incompatibility and also false-positives. You might have "too many" matches for it to be useful for much.
> 1 in 50,000 probability means it requires trying up to 50,000
> different fingerprints until potentially finding a random match
If you were hypothetically able to extract the hash from the "Secure Enclave" you could take a database of fingerprints (no doubt these exist somewhere: prison, military, customs, ...) and hash those to attempt to find a match. As Apple says, you have a 1 in 50,000 probability of randomly matching it. Once you find a hash match, you can then 3D print it and use it to unlock the device.A very impractical attack against the average Joe consumer. Someone would have to be a very high value target with sensitive information on their phone to use this, and that's assuming a direct extract via physical connection isn't the more viable option.
You might not be able to do even this. According to the info released so far the sensor captures a sub-epidermal print.
Edit: Also I am unaware of a 3D printer that is capable of printing the resolution required to represent a fingerprint.
As long as the password needs to be bruteforce with more than 50K attempts (really, any reasonable one), your weakest link is the touch sensor, which is still 5 times better than a 4-digit passcode used by only 50% of users.
Frankly, if a government agent wants your fingerprints, there are much easier ways to do it than trying to get a backdoor placed in a TPM chip. Even _if_ it's something they can do, they sure as heck aren't going to use it routinely -- it would be visible in network traffic, would be sitting there in the source code for anybody to come and discover it with a decompiler, and would destroy Apple's reputation if it ever got out (and you can bet their lawyers would push back when their reputation's on the line).
Everybody questioning about wether they can or can't rebuild your finger print from the mathematical model. While this is relevant, it's just one of the many implications that implementing finger-print technology in mass-production products has.
Apple here is saying that the "mathematical representation" of your finger-print IS stored. Where? Nobody knows. Locally? Cloud?
Very likely they will abuse this, as they are abusing social data in general.
I'll just leave it here: "So, we have your day-to-day activities and a solid face recognition mathemtical model thanks to facebook, all your phone data thanks to Apple and Google, now we will have your finger print as well"
As far as i'm concerned, at the moment NSA reversing from the mathematical model to the actual finger-print image is quite irrelevant and the general sitution is becoming disturbing.
Apple explicitly says that fingerprint data is not backed up to iCloud.
The data is only stored in what they are calling "Secure Enclave" on the A7. From my understanding this is an area of the SoC that is out of reach to all processes and most of iOS itself.
From the article:
"The Secure Enclave is walled off from the rest of A7 and as well as the rest of iOS."
I think all OS processes that wish to interact with the secure enclave must do so through a secure monitor. The idea is that the secure processes are completely isolated from anything untrusted.
Apple is not interested in your fingerprint data, they are interested in your trust and convenience. Those two things are far more likely to get you to buy things.
They don't want your fingerprint data. They want your money. They are more likely to get your money if you trust them. You are more likely to trust them if they don't lie about how they store your fingerprint data.
It's pretty straight forward and perfectly in line with their past behaviour.
Some are claiming that Apple's "Secure Enclave" is their branding of ARM's TrustZone. [1]
[1] http://www.arm.com/products/processors/technologies/trustzon...
"...so it is rare that...two separate fingerprints are alike enough to register as a match for Touch ID. The probability of this happening is 1 in 50,000 for one enrolled finger. This is much better than the 1 in 10,000 odds of guessing a typical 4-digit passcode...the 1 in 50,000 probability means it requires trying up to 50,000 different fingerprints until potentially finding a random match. But Touch ID only allows five unsuccessful fingerprint match attempts before you must enter your passcode..."
So Touch ID odds are 50,000 while passcode is only 10,000. But since you only have five attempts for Touch ID to switch back to passcode, The Touch ID security only adds 5 odds to the previous passcode system and we end up with 10,005 odds of some successfully breaking into your phone.
A whole system to gain 5 odds of breaking into the phone. Brilliant.
That should help increase those odds again.
Also, the slick, futuristic appeal of fingerprint access goes a long way to achieve Apple's branding goals, which surely is just as important to selling iPhones as actual security.
How does this work exactly, if the fingerprint-pass is only stored locally on your device? Is the fingerprint acting only as a "master password", which means you still have to set-up your password for iTunes first?, and then it just re-uses that iTunes password after you used the fingerprint-master password?
Because otherwise I'd have to assume Apple stores your fingerprint on their servers, in order to match your account with your fingerprint-as-password.
That's the right answer I believe.
This is most definitely not the case. The GPS is not running 24/7, nor do apps have access to historical GPS data. The location API is still entirely opt-in at the time the app runs.
The data you can query from the M7 is not very sensitive, and is geared towards fitness apps.[1]
For example, you can query the number of steps taken in a given date range (for up to seven days). You can also query the motion type.
This is no way relates to GPS or your actual, physical location in the world.
[1] http://www.doubleencore.com/2013/09/core-motion-activity-tra...
Surprise.