By using this site, you agree to our Privacy Policy and our Terms of Use. Close

The famous German hacker group "ccc" (Chaos Computer Club) has proven the fingerprint sensor to be not secure.

 

"Hackers of the biometrics team of the Chaos Computer Club (CCC) has been able to circumvent the biometric security features of the Apple TouchID with the simplest means. This was enough for the hackers a fingerprint, which they abfotgoraphierten of a glass surface to produce an artificial finger. Thus they were able to unlock an iPhone 5s, which was protected with TouchID. Thus, the hackers demonstrated once again that biometric data to prevent unauthorized access are completely unsuitable. 

The new iPhone 5s is equipped with a fingerprint sensor that Apple has touted as much more secure than previous sensors. Even in technological trade press is discussed on the profit for the safety for days.


"In fact, the sensor of Apple only has a higher resolution than previous sensors. We had only the Ganularität our Art increase a little finger, "said the hacker with the pseudonym starbug, which has optimized through experiments, the method of outwitting the sensor. "For years we have repeatedly warned against the use of fingerprints for access control. We leave fingerprints everywhere, and it is a breeze to create fake fingers from it. "[1]


The procedure to overcome is documented in this video: Hacking iPhone 5s TouchID .


The method is equivalent to the following steps and uses materials that are present in almost every household: first the fingerprint of a user is photographed with a resolution of 2400 dpi. The photo is then adjusted on the computer, inverted and printed by laser printer on a transparency film. A resolution of 1200 dpi at maximum pressure level should not be exceeded. Skin-colored latex milk or white wood glue is then applied to the image. By the pressure lines creates a fingerprint image in the deposited material. After drying, the counterfeit finger can be removed. This is moistened slightly by breathe on him. Then you can unlock the iPhone with it.


"We hope that this eliminates the remaining illusions that humans in biometric security systems have. It's just a stupid idea to use something as an everyday security token, which leaves you every day of endless many places, "said Frank Rieger, speaker of the CCC. "The public should no longer be led around by the biometrics industry with false statements on the nose. Biometrics is suitable to monitor and control people not to back to everyday devices against unauthorized access. "Fingerprints in identification documents have been introduced in many countries for several years, although considered to be of no safety.

iPhone users should avoid, to secure sensitive data with your fingerprint. It's not just that the fingerprint can be so easily faked. Also one can easily be forced to unlock his phone when you get arrested. To force a person to abandon a secure password, however, is a lot more than just keep the phone from his hands in handcuffs difficult.


We would like to thank especially when Heise security team, which could provide a short-term iPhone 5s for analysis. More information about the hack will be posted there.

Links:

 [1] fingerprint at the supermarket checkout just as insecure as biometrics in the passport (2007)"

 

 

http://www.google.com/translate?hl=en&ie=UTF8&sl=de&tl=en&u=http%3A%2F%2Fwww.ccc.de%2Fde%2Fupdates%2F2013%2Fccc-breaks-apple-touchid

 

http://www.youtube.com/watch?v=HM8b8d8kSNQ