Why I Hacked Apple’s TouchID and Still Think it is Awesome
blog.lookout.com
blog.lookout.com
This is my main takeaway. I suspect the vast majority of iPhone users either do not secure their phone at all, or use a 4-digit PIN, and therefore are not protected against targeted attacks anyway. Touch ID can improve security for these users.
My main reason for protecting my phone is to prevent a scenario where it gets stolen, and the thief can access my data with reasonable effort. My secondary reason is to protect against snoopy acquaintances. A 4-digit PIN marginally achieves these goals: a typical thief is locked out, but a more sophisticated one can easily brute-force my code using commercially available tools.
What if I use Touch ID instead? It is very likely that a thief will not know who I am, and therefore will not be able to go around lifting my fingerprints. They might, however, try to lift prints off my phone. The way to protect against this is to only unlock the phone using my thumbs, because (per TFA) there are typically no good thumb prints on the phone itself. If I do this, then I will in fact be more protected than I would be using a 4-digit PIN.
A couple of caveats. After 5 rejected attempts the iPhone will fall back to asking for a PIN. It is therefore advisable to set a strong (longer than 4 digits) PIN here. Second, this of course may change if the 'secure enclave' that stores the fingerprint hashes gets hacked.
TL;DR: If you only use your thumbs to unlock your iPhone, Touch ID currently provides better security against typical threats than a 4-digit PIN.
In this way Touch ID is a far far superior defense against snoopy acquaintances unless you happen to be unconscious around them.
UPDATE For more detail about how this is done, have a look at the current releases of jailbreaking tools. The general method is to perform a temporary jailbreak which allows the ability to SSH into the device and dump all the data.
Got a credible source for this?
What the poster doesn't mention that this only works on devices with iBoot bootloader exploits, which is currently the A4/iPhone 4 and lower. The 4S, 5, 5S, 5C etc are all safe from this.
Good luck guessing the length and the passphrase I use to lock my phone now when the keyboard comes up.
Only pre-A5 CPUs are vulnerable to the boot-ROM exploit which allows a custom ramdisk to be uploaded.
The exploit is called "limera1n" or the "A4 boot-ROM exploit" if you're interested in learning more.
True security comes from multiple layers of security, where the question changes randomly but you still know what the end result will be, much like a bank does when signing in.
When things become easier, it only remains easy to get in to it. The reason it isn't so easy right now is because it hasn't had to be so widely available. When TouchID becomes more popular, you will read more stories on how people have found easier ways of cracking it.
It's all about convenience. If you want security then it's TouchID from 5 fingers + 8 digit pin + your first dogs girlfriend's name.
As I understand correctly, the purpose of a hashing function is to create totally different output even on a very minor change in the input data, which wouldn't work that great with fingerprints... or are they just using a clever hashing function which tries to somehow normalise the data before hashing them?
In short, they store a number of unique sub-regions of each 'enrollment' (a reading resulting in pixel data). These sub-regions – called 'spots' – can then be hashed and matched against future enrollments to provide a correlation score.
this might provide some information: 'Symmetric hash functions for secure fingerprint biometric systems' (http://www.researchgate.net/publication/222570842_Symmetric_...). also this: https://www.schneier.com/blog/archives/2013/09/iphone_finger... (for some general overview)
Hmm, other people seem to have demonstrated an 'attack' that uses ordinary photography to capture the print, and a much simpler process to reproduce it than the one described in OP too.
Here's an article about that: http://www.forbes.com/sites/andygreenberg/2013/09/22/german-... (An article about those germans was posted on HN a few days ago is how i know about it, not sure if it was this same article)
OP may be right that TouchID is an appropriate level of security for many users/usecases. All security is tradeoffs, none is unattackable.
But OP seems to be over-estimating the amount of work it takes to reproduce the fingerprint, according to the Germans.
Additionally, if phones locked only with TouchID become common, I would expect criminal networks to develop and share standardized processes and devices to do it, lowering the barrier further.
It was clearly a bunch of work, but measured in hours.
Imagine a scenario in which you find an iPhone (or "borrow" it) - how do you unlock it without knowing the owner and having access to their fingerprints? You don't, not with this "hack".
A cool demonstration of the fingerprint lifting technique though.
http://www.youtube.com/watch?v=HM8b8d8kSNQ
Several very clear fingerprints are visible on the glass.
If it were this easy, why do the hacks use carefully made fingerprints from clean polished glass?
What matters is not whether one pristine fingerprint can fool TouchID (note that we don't know how many failed attempts were made), but what percentage of fingerprints found in the wild can fool it.
It explicitly states "prints lifted like from a beer mug" and so far, all I have seen were prints lifted in a laboratory setting. Nothing real world about it.
I like my Galaxy S4, but I wouldn't mind easier phone unlocking. Even better than fingerprinting, I wish I could draw an unlock pattern in the shape of whatever I wanted, a higher resolution pattern with visible brushstroke. Subtle unlock patterns would then be possible. You'd need a good algorithm to allow some difference in the reproduced pattern, while remaining high resolution enough to provide thousands more combinations than 4 digit pins.
Paint to unlock - that's what I need, if anyone wants to make that as an app for Android, I'd buy it for a dollar!
If the issue is smudgy prints, I wonder if some image processing could improve results.
The fingerprint scanner only protects from #1, and is worse for 2 & 3 (the police just put my finger on the phone, and my girlfriend just waits until I'm asleep to put my phone on my finger... My overall security has gone down considerably for a modest gain in convenience
While I would prefer two-factor authentication with TouchID, I still feel like this implementation protects the user from the lowest common denominator (i.e. petty theft).
If I zoom in or out it looks normal, so probably something wrong with hinting in the font (or a bug in firefox?) FWIW it looks normal in Chromium.
http://i.imgur.com/wlfEBHC.png
So even if there is a bug, it's apparently been fixed :)
I have used 'Help->Submit feedback' to report it, is this the preferred way to report website issues, or are bugzilla entries better? https://input.mozilla.org/en-US/dashboard/response/3983188
I notice also that the back of the 'b' is broken and the dot is missing from the 'i' in your screenshot.
Just like the pattern lock (or face unlock and its variations) on Android phones, the idea is to encourage users to have at least some protection.
As an Android phone user, I hope to see this being adopted by the Android manufacturers (and I hope the Apple camp would shut up about people copying their idea).
Loads of companies used fingerprint readers and it it was a conversation for a few days at most. This has had an article on hn every day for at least a week.
I use fewer and fewer of their products, but to me it's shocking how much of Apple's success is still attributed to brand and marketing - I don't know how you could argue that anyone else is the gold standard for hardware/software integration in consumer devices. If anything, their marketing glosses over the exacting level of fit and finish that obviously go into these things.
> If you use your thumb to unlock it, the way Apple designed it, then you are looking for the finger which is least likely to leave a decent print on the iPhone.