Politician's fingerprint 'cloned from photos' by hacker
bbc.com
bbc.com
It's like Apple and other biometric device purveyors are telling us all to just log in with our username and a blank password. At the moment we're all scrawling our passwords on every surface of every room we enter.
"As an example, he demonstrated how he could use his fake fingerprint to unlock his iPhone — that features a ‘Touch ID’ fingerprint sensor integrated into its home button."
http://www.iphonehacks.com/2014/12/hackers-reproduce-fingerp...
It isn't entirely clear which fake fingerprint was used. I guess we should probably watch the CCC talk.
Obviously his own fingerprint. He doesn't have access to the German Defense Minister iPhone to test the real one (assuming the Defense Minister uses an iPhone and has Touch ID configured).
https://www.youtube.com/watch?v=3Hji3kp_i9k
Of course, things may have gotten better or worse since then.
So the idea of Apple isn't THAT bad.
On the other hand, how often do people use this?
I, for one, don't lock my phone at all. And most people I know don't change their PIN/gesture ever.
In many cases fingerprints are perfectly fine to use. However, they do have glaring problems as well. So they are anything but perfect, I’m just not sure what difference that makes to how they are used in practice right now.
While I applaud the research, Krissler needs to prove that he can unlock a device reliably using a system like TouchID (as a reference platform) using this intensive photograph-only modeling approach before I become worried - his previous efforts last year don't count as "previous proof" - if it were reliable, there would be a comprehensive breakdown/proof.
Fingerprint technology has improved greatly - e.g. TouchID requires something warm like flesh behind the scan, and does image the 3D contours as applied to the press - which deform the scan from it's natural state.
Remember: Fingerprint locks are convenient, but they discard your ability to "forget" or refuse to unlock a device. They remove consent.
[ source - https://twitter.com/SwiftOnSecurity / https://imgur.com/a/1PDRJ / ]
Can anyone intent on downvoting explain what is factually wrong or misleading about the quote in the picture? Just because it's on a picture doesn't make it less valid.
If the article was about a case where a person was mandated to unlock their phone because it is only protected by a fingerprint scan, (and of course a person cannot "forget" their fingerprint like they can a password), then your quote would have been on topic.
Yeah, the quote is about fingerprints, but it's really orthogonal to the topic of the article, which is that fingerprints can be "cracked" just like passwords. That's not what the quote you posted is about. The quote is about the fifth amendment (of the US constitution): https://www.eff.org/issues/know-your-rights#17
Granted, there also useful limiting casual access. Think kid/roomate using someone elses work laptop vs. a dedicated hacking attempt.
People are convicted of crimes on the strength of their fingerprint.
Apple is using fingerprint evidence to allow or deny access to a phone.
Judiciary around the world is using fingerprint evidence to lock people up, deny them basic rights, and sometimes to kill them.