By using this site, you agree to our Privacy Policy and our Terms of Use. Close

Forums - Gaming - Iphone 5s Security (TouchID) broken

The famous German hacker group "ccc" (Chaos Computer Club) has proven the fingerprint sensor to be not secure.

 

"Hackers of the biometrics team of the Chaos Computer Club (CCC) has been able to circumvent the biometric security features of the Apple TouchID with the simplest means. This was enough for the hackers a fingerprint, which they abfotgoraphierten of a glass surface to produce an artificial finger. Thus they were able to unlock an iPhone 5s, which was protected with TouchID. Thus, the hackers demonstrated once again that biometric data to prevent unauthorized access are completely unsuitable. 

The new iPhone 5s is equipped with a fingerprint sensor that Apple has touted as much more secure than previous sensors. Even in technological trade press is discussed on the profit for the safety for days.


"In fact, the sensor of Apple only has a higher resolution than previous sensors. We had only the Ganularität our Art increase a little finger, "said the hacker with the pseudonym starbug, which has optimized through experiments, the method of outwitting the sensor. "For years we have repeatedly warned against the use of fingerprints for access control. We leave fingerprints everywhere, and it is a breeze to create fake fingers from it. "[1]


The procedure to overcome is documented in this video: Hacking iPhone 5s TouchID .


The method is equivalent to the following steps and uses materials that are present in almost every household: first the fingerprint of a user is photographed with a resolution of 2400 dpi. The photo is then adjusted on the computer, inverted and printed by laser printer on a transparency film. A resolution of 1200 dpi at maximum pressure level should not be exceeded. Skin-colored latex milk or white wood glue is then applied to the image. By the pressure lines creates a fingerprint image in the deposited material. After drying, the counterfeit finger can be removed. This is moistened slightly by breathe on him. Then you can unlock the iPhone with it.


"We hope that this eliminates the remaining illusions that humans in biometric security systems have. It's just a stupid idea to use something as an everyday security token, which leaves you every day of endless many places, "said Frank Rieger, speaker of the CCC. "The public should no longer be led around by the biometrics industry with false statements on the nose. Biometrics is suitable to monitor and control people not to back to everyday devices against unauthorized access. "Fingerprints in identification documents have been introduced in many countries for several years, although considered to be of no safety.

iPhone users should avoid, to secure sensitive data with your fingerprint. It's not just that the fingerprint can be so easily faked. Also one can easily be forced to unlock his phone when you get arrested. To force a person to abandon a secure password, however, is a lot more than just keep the phone from his hands in handcuffs difficult.


We would like to thank especially when Heise security team, which could provide a short-term iPhone 5s for analysis. More information about the hack will be posted there.

Links:

 [1] fingerprint at the supermarket checkout just as insecure as biometrics in the passport (2007)"

 

 

http://www.google.com/translate?hl=en&ie=UTF8&sl=de&tl=en&u=http%3A%2F%2Fwww.ccc.de%2Fde%2Fupdates%2F2013%2Fccc-breaks-apple-touchid

 

http://www.youtube.com/watch?v=HM8b8d8kSNQ 






Around the Network

interesting read, I enjoyed it. Makes sense why biometric scanners aren't more popular.



 Been away for a bit, but sneaking back in.

Gaming on: PS4, PC, 3DS. Got a Switch! Mainly to play Smash

Yes.. every one of us can pull a fingerprint from a glass and then produce an artifcial version of it in our kitchen... they should have went with an eye scanner..



 

Face the future.. Gamecenter ID: nikkom_nl (oh no he didn't!!) 

They should have went with a breath scanner instead. I am pretty sure that everyone's breath smells different.



Apple just had to watch the episode where the Mythbusters crack a door scanner with a piece of paper wiht a finger print on it, 6 years ago. This is why I never trusted fingerpirnt things again.



Around the Network

Oh no!

Quick, everybody go back to a 4-digit PIN that can be cracked by, uh, anybody looking over your shoulder actually.

I'd read some chatter from the biometric crowd that this tech was supposed to use RF capacitance to map the "electronic signature" of the flesh beneath the fingerprint. I wonder what went wrong there. The video I saw showed the same guy using a different finger plus the overlay they cooked up to unlock, so I'm wondering the RF capacitance is more a feature of your blood than the structure of your finger.

In other words, the meat of his finger provided the "electronic signature" while the overlay provided the physical key. That would mean this team only has half of an attack figured out.

Either that or Apple was straight-up lying about the sub-dermal scanning.



"The worst part about these reviews is they are [subjective]--and their scores often depend on how drunk you got the media at a Street Fighter event."  — Mona Hamilton, Capcom Senior VP of Marketing
*Image indefinitely borrowed from BrainBoxLtd without his consent.

famousringo said:
Oh no!

Either that or Apple was straight-up lying about the sub-dermal scanning.


Of course they lied. This is a cheap chip for a few cents, what did people expect?



walsufnir said:
famousringo said:
Oh no!

Either that or Apple was straight-up lying about the sub-dermal scanning.


Of course they lied. This is a cheap chip for a few cents, what did people expect?


Well, another alternative is that the company with a reputation worth billions of dollars is telling the truth, and the random internet dudes with nothing to lose are lying for the attention. I think I'll wait for these guys who are putting money where their mouth is to verify it, and personally, I want to see them use a different guy's finger:

http://istouchidhackedyet.com

BTW, the IP behind that "cheap chip" is worth $356 million. More, if you consider the whole integrated hardware/software stack behind it.



"The worst part about these reviews is they are [subjective]--and their scores often depend on how drunk you got the media at a Street Fighter event."  — Mona Hamilton, Capcom Senior VP of Marketing
*Image indefinitely borrowed from BrainBoxLtd without his consent.

To be fair it is not much more secure than the other method.

What I would like to see is tests proving whether or not the fingerprints are stored somewhere else.



That's why I always use randomly generated pass codes that are changed out on a regular basis. The current active codes are kept in a safe until new ones are written by hand. The old are shredded and then burnt.