22 ms·
Apple’s Fingerprint ID May Mean You Can’t ‘Take the Fifth’
- deleted 13y ago[deleted]
- mpyne 13y agoIn the UK that is true, but it's more complex in the US. My understanding of a recent decision is that the government can compel delivery of a password only if they've already proven from other means some specific evidence that should be available which is protected by that password (since in that case there is already "incrimination" from means other than self-incrimination).
- cmiles74 13y agoIs it a known fact that the fingerprint authentication can't be combined with the standard PIN or complex password feature? It seems like a fingerprint scan that is followed by a password request to unlock the phone would be an easy win.
- rickyc091 13y agoI recall reading that you will get hit by the passcode lock if your fingerprint doesn't scan after X attempts.
- deleted 13y ago[deleted]
- Osmium 13y agoIn practice, it might have the opposite effect. Currently, 4-digit PINs are (presumably) brute-forceable and the alternative of entering a longer, cryptographically-secure password every time you want to use your phone is impractical, so it doesn't really matter whether you can be legally compelled to divulge your PIN or not. However, with a fingerprint ID, you can now use a cryptographically strong password to encrypt your phone (which you have to enter on device boot or after 48 hours of the device being idle [1]), while still having the convenience of actually being able to use your phone once it's on via the fingerprint scanner. So I see that as a security win. Of course, Wired's premise isn't even valid in some countries, e.g. the UK, which have powers to legally compel you to hand over your passwords regardless. For all I know this is true in the US too. [1] http://9to5mac.com/2013/09/11/apples-details-fingerprint-sensortouch-id-security-48-hour-wipe-standard/ http://9to5mac.com/2013/09/11/apples-details-fingerprint-sen...
- tocomment 13y agoAre you sure you can brute force the PIN? I thought the iPhone will enforce a waiting period after too many bad entries.
- miles 13y agoAre you sure you can brute force the PIN? Yep: Elcomsoft iOS Forensic Toolkit[1] * Instant passcode recovery for all iOS versions up to iOS 3 * Simple 4-digit iOS 4/5/6 passcodes recovered in 10-40 minutes [1] http://www.elcomsoft.com/eift.html http://www.elcomsoft.com/eift.html
- objclxt 13y ago> Yep: Elcomsoft iOS Forensic Toolkit[1] I think you missed the fairly huge disclaimer hidden away at the bottom of the page: > iPhone 4S, iPhone 5, iPad 2+, iPad Mini and iPod Touch 5th gen support is limited to jailbroken devices only (iOS 5 and 6). The chances of a target device being jailbroken are not particularly large. This should, of course, serve as a reminder that if you are running a jailbroken device you should probably have a passcode a little more complex than four digits!
- miles 13y agoThere are many other forensic acquisition products for iOS[1] as well as a number available to law enforcement only; I think it's safe to say that relying on your iPhone's PIN code for protection is probably not a good idea. [1] http://www.appleexaminer.com/iPhoneiPad/iOSAnalysisTools/iOSAnalysisTools.html http://www.appleexaminer.com/iPhoneiPad/iOSAnalysisTools/iOS... EDIT: This device was found on the AppleExaminer page: http://www.cellebrite.com/forensic-solutions/ios-forensics.html http://www.cellebrite.com/forensic-solutions/ios-forensics.h... "Using UFED Physical Analyzer, physical and file system extractions, decoding and analysis can be performed on locked iOS devices with a simple or complex passcode. Simple passcodes will be recovered during the physical extraction process and enable access to emails and keychain passwords. If a complex password is set on the device, physical extraction can be performed without access to emails and keychain. However, if the complex password is known, emails and keychain passwords will be available."
- deleted 13y ago[deleted]
- ahoge 13y agoWell, the usual smear across the screen gesture can be "cracked" by looking at the screen at an angle. Secondly, there aren't many patterns you can conveniently enter with the thumb of your dominant hand.
- cbhl 13y agoI feel like the author of this article is missing the whole point of Fingerprint ID. The feature is meant to make using an iPhone more secure for those of us who tend to leave our phones unlocked and PIN-free. If you're storing anything of value on your phone, the existing password-based and PIN-based lock mechanisms aren't going away any time soon. If nothing else, it'd break too many organizations' Active Directory configurations.
- ctdonath 13y agoNo, you're missing his point. You're in court. You refuse to admit/verify the accusation that you were in the vicinity of the deceased's home. Cell phone records, dutifully recorded and reported under warrant from NSA...er...ATT, show your phone - which you are known to carry pretty much everywhere - was in that vicinity at the crime's time. You contend that does not constitute evidence. The phone is acquired, bailiff places your finger on your Fingerprint-ID-secured phone, phone unlocks, evidence thereon shows activity during that period. So much for your 5th Amendment right against self-incrimination.
- haberman 13y agoIf the phone wasn't password-protected (or fingerprint-protected) at all, the story would be the same except you could skip the "bailiff places your finger..." step.
- jlgreco 13y agoYou would be missing the key "the phone is, beyond doubt, yours" step.
- tedunangst 13y ago"I just bought it yesterday."
- gknoy 13y ago
- darkchasma 13y agoAnd now wired is added to my list of fear mongering link baited blogospam.
- swamp40 13y agoYes, pure FUD.
- Dylan16807 13y agoLink baited blogospam? I knew exactly what would be in the article, and I think the title was reasonable for the contents.
- tedunangst 13y agoWouldn't citing a case where somebody was forced to unlock their laptop using a fingerprint provide a more compelling example of precedent?
- umsm 13y agoWouldn't you be able to CHOOSE what you apply a fingerprint lock to? Ideally you would only allow it for payments and not other things.
- ctdonath 13y agoI'm looking forward to CHOOSING to locking the whole device, so that I can actually have a lock "code" (whatever form) that isn't subject to a 3-year-old poking at it so much the device locks itself up for an hour or more thinking it's under attack.
- thehme 13y agoI certainly expect to be able to choose which option I want to use, specially if Apple wants to keep my business. I have no problem remembering long complex passwords and have adapted to the phone authentication method as well. For our own sake, it would be best if we continue to use things ONLY we remember, to authenticate ourselves, otherwise we may be in trouble. For instance, I recently heard of an older couple who allowed the husband's brother to visit them to talk about a new business he was in. Essentially he wanted to visit the couple with his "mentor" because he needed to "practice". At the end of their visit the couple had been persuaded to: join the "business" as members, for a monthly fee, which was going to be charged to their credit card. THIS WAS OBVIOUSLY A PYRAMID SCHEME! Anyways, after the visit, the terrified the woman immediately called the bank and had them cancel the card, so everything ended up being okay. Imagine if they had handed over their fingerprints! You won't be able to call the bank to tell them to send you a new fingerprint.
- sschueller 13y agoA finger can easily be forcefully used or even removed for use later. A password however is still harder to get out of a brain and can be just as strong if it is long/complex enogh.
- aroch 13y agoIF they really want your password, a 4digit pin isn't too hard to beat out of someone. Also, bruteforcing would be trivial.
- Someone 13y agoI don't think getting a password out of a living brain is harder than removing a finger. Most brains would give you their password if you threaten to remove a finger, even more if you give a demo first and threaten to remove a second one. In the case where the brain is dead, removing the finger is way easier. I am not sure how that balances out, but I am sure two-factor authentication (fingerprint plus password) beats either.
- alexfringes 13y ago"24" News.
- whatthesmack 13y agoI've never regarded fingerprint-only as an option, because of the reasons the author mentioned in the article. It's more like having a badge or a keyfob...it could be difficult to get, but by no means impossible. Something you have: fingerprint Something you know: PIN Combine the two and you can be fairly sure only the owner has access to whatever's being protected.
- frank_boyd 13y ago> Some even argue that Apple’s move is a death knell for authenticators based on what a user knows (like passwords and PIN numbers). To reclaim your freedom, just switch to open-source solutions.
- tocomment 13y agoI wonder if the fingerprint will ever be used to prove that you were at the location your phone recorded you at?
- danso 13y agoA little off-topic, but can someone tell me why fingerprint-access is even a needed feature? With PIN access, you get good enough security when you also enable the lock-after-10-mistypes. And 4-digits is only about a few seconds slower than fingerprint access...and since you already have instant access to incoming calls and to the camera, in what situations do we need insta-touch access to our phones? Phones are getting stolen and compromised because people are too lazy to do the PIN thing, I suppose...but it never seemed like it was in Apple's best interest to make phones brickable.
- chrislomax 13y agoIf I were to take a massive guess on this (and this is a massive guess). I would say that for the lifetime of the phone being unlocked with your fingerprint you could do things like pay for items etc. They may be lining up for banks or other authorities to start allowing finger print recognition in their systems and apps to make bank transfers or pay for items in general and that your finger print would be the authorisation. It may be one level more secure when they implement NFC. I don't know though, I doubt they have done it simply because people want to unlock their phones 1 second faster.
- djdj123 13y agoEr, iphones and other fancy smartphones are being stolen because they fetch hundreds of dollars from black-market wholesalers and unwitting craigslist buyers. Not because people don't use a PIN. Of course, using a PIN is a good idea in the event that the person who eventually gets possession is an identity thief.
- rblatz 13y agoIt improves the security of my phone in the real world cases that I'm likely to encounter. Like friends, coworkers, family members, and significant others. It's trivial for them to observe my pin, but lifting a print and creating a fake finger ala Mythbusters or compelling me by force is beyond their resources. So it's a trade off, giving up security against a determined threat for a gain in security against casual threats.
- a_c_s 13y ago
- crazygringo 13y agoThe way everyone's talking, you'd think Apple was taking away the four-digit PIN! But they're not... The fingerprint ID is just another option, which you don't have to use. So titles like this are just incorrect. Fingerprint ID isn't taking away any of your rights, because you can still use the PIN just like you always have. I mean seriously, what the heck is going on here? Why on earth are people getting worked up about this? Sure, the fingerprint ID might be less secure, and it's important to realize that, but nobody's forcing you to use it. According to everything reported so far, the new iPhone is not removing your PIN.
- falcolas 13y ago> The fingerprint ID is just another option, which you don't have to use. It's still important to let people know the potential pitfalls of such a method, even if it's one option amongst many, so they can make an informed choice between the options. > Why on earth are people getting worked up about this? Because it has serious implications on your security, both from other people, and from the government (or its actors), implications which are not immediately obvious.
- deleted 13y ago[deleted]
- coldtea 13y ago>The way everyone's talking, you'd think Apple was taking away the four-digit PIN! But they're not... The fingerprint ID is just another option, which you don't have to use. That's never how it works. Today it's "just another option", a few years down the line it's mandatory. And "not having to use" does not equal "people will not use it unless they are fully aware of possible consequences" anyway.
- crazygringo 13y ago> a few years down the line it's mandatory That's just FUD. And saying baseless things like "that's never how it works", that's just fearmongering, not contributing to the conversation. It doesn't even make sense. There are millions (hundreds of thousands? you get my point) of fingerprint readers out there. Suddenly Apple builds one in, an additional feature, and people start inventing conspiracy theories. People are completely confusing real issues (recent NSA disclosures) with totally imaginary ones. It's getting tiring.
- malandrew 13y agoAt least with fingerprints, you can effectively destroy the "password" irreversibly before being compelled, since you can always cut off the tip of your finger and destroy it. Sounds messed up, but it's certainly a possibility. Since the finger is not the evidence itself, I don't think this would constitute destruction of evidence, and so long as it is done before the court asks you to unlock the device, it should not result in contempt of court. However, this is all uncharted territory and IANAL.
- VladRussian2 13y ago>Since the finger is not the evidence itself only until it is an attached part of your body :) I can see how destroying the tip of your finger and cutting after that is ok, while in reverse would be a destruction of evidence.
- rayiner 13y agoThis article actually gets the law right, as it stands today. I'm not sure if it's super relevant information, but it's correct. The 5th amendment says: "No person... shall be compelled in any criminal case to be a witness against himself..." Witness is a legal term of art, which refers to someone who gives oral testimony recounting their own experiences. Handing over a key or touching a button is not testamentary and therefore not protected.
- chrismcb 13y agoActually they got the law exactly wrong. "If the police demand that you give them the key to a lockbox that happens to contain incriminating evidence" you don't have to turn the key over without a warrant. The police have to have good knowledge that the incriminating evidence in the lockbox. And passwords are just a key. This has already gone through the courts, the courts can impel you to turn over your password, if they have evidence to suggest your computer has incriminating evidence. This won't be any different, they can't take your fingerprint or dna without probable cause. I don't see how it is any different.
- rayiner 13y agoWhen the 5th amendment applies, it protects you even when the police have a warrant. Courts have not reached agreement about whether turning over a password is like turning over a key or scanning your thumbprint. See: http://www.techdirt.com/articles/20130425/08171522834/judge-says-giving-up-your-password-may-be-5th-amendment-violation.shtml http://www.techdirt.com/articles/20130425/08171522834/judge-...
- Symmetry 13y agoProbably cause isn't hard to manufacture, though. I believe there was a court decision recently that said that a state's drug sniffing dogs still provided valid probably cause even though they would bark whenever their owner wanted them to bark.
- ihsw 13y agoNot quite. > When a person has a valid privilege against self-incrimination, nobody — not even a judge — can force the witness to give that information to the government. The Fifth Amendment explicitly outlines that you cannot successfully "plead the fifth" in response to a grand jury compelling you to testify.
- jrs235 13y agoWouldn't it make the most sense then from a security and privacy perspective to require a fingerprint AND a "pin" or password from one's personal memory [stored in their head]? Why not just do that?
- coldtea 13y ago>Take this hypothetical example coined by the Supreme Court: If the police demand that you give them the key to a lockbox that happens to contain incriminating evidence, turning over the key wouldn’t be testimonial if it’s just a physical act that doesn’t reveal anything you know. However, if the police try to force you to divulge the combination to a wall safe, your response would reveal the contents of your mind — and so would implicate the Fifth Amendment. (If you’ve written down the combination on a piece of paper and the police demand that you give it to them, that may be a different story.) BS interpretations like these make the legal system a big bad joke. The original intention clearly had nothing to do with whether it was something out of your mind or not, and all to do with not being forced to implicate yourself.
- Karunamon 13y agoThey should have written that, then. Instead they wrote "to be a witness against himself". Considering that the legal entire legal system practically runs on fine definitions such as these (witness against oneself != implicate oneself), and also considering that it's a judge's job to attempt to successfully translate a centuries old document based on jurisprudence, case law, etc, your opinion on intention is worth precisely jack and squat. (As is mine and pretty much everyone else's here...)
- ryanobjc 13y agoInteresting feature of the fingerprint lock... if you havent unlocked your phone in 48 hours, the fingerprint lock won't work anymore and you will need to use the PIN you had to set up. Basically this issue is totally sidelined by this feature.
- beloch 13y agoIt will be interesting to see how difficult or how easy it is to fool Apple's fingerprint scanner. I suspect the security will not be high given the constraints of putting it in a button on a mobile phone and the preference for letting marginal scans authenticate the user so as not to frustrate or inconvenience them. Personally, I'd trust a 4-digit pin with a lockout timer to stand up better than fingerprint authentication. It looks cool in the movies, but it's never been a very bright idea. Of course, most won't care if it's insecure, and being able to set different functions to automatically execute based on scanning different fingers (an ability laptop scanners have had for years) is certainly a selling point.
- nodata 13y agoSince the phone is covered in the password anyway, it would be interesting to see if it stands up to a gummi bear attack: http://www.theregister.co.uk/2002/05/16/gummi_bears_defeat_fingerprint_sensors/ http://www.theregister.co.uk/2002/05/16/gummi_bears_defeat_f...
- marvin 13y agoHave we seen this fingerprint reader yet? IBM/Lenovo ThinkPads use a reader that's just a tiny strip, so you actually have to swipe your finger instead of just planting it on the reader. This at the very least defends against simple attacks. But I mean, a fingerprint is a physical thing which can be cloned, just like a key. And you also leave prints everywhere you go. It's not a silver bullet in authentication. All else being equal, passwords are safer against a determined attack, if we can assume correct usage.
- ffrryuu 13y agoThat and the NSA chip, you'd be crazy to buy one.
- ianstallings 13y agoYou know what I think? I think wired just wanted to say the word iphone in an article today.
- troystribling 13y ago"But if we move toward authentication systems based solely on physical tokens or biometrics — things we have or things we are, rather than things we remember" If the argument is valid it seems that it could also be applied to public key encryption.
- rralian 13y agoSeems like simply combining the fingerprint with some sort of quick gesture could get around this. They couldn't force you to try all possible gestures any more than they could force you to try all possible combinations of a lock (example taken from the article).
- jamesrom 13y agoThe average person (who according to apple does not use a passcode) will be more secure overall if they use Touch ID.
- stavrianos 13y agoMy understanding was that the right against self-incrimination was largely meant as a patch, to prevent suspects being tortured into confessing by devaluing their confessions. If that's the point, I don't see any reason for a court not to compel a harmless, painless fingerprint swipe.
- stedaniels 13y agoAre we going to see an influx of pointer fingers getting mysteriously burnt when their owners have been arrested? I see it's certainly easier to force someone's finger onto their home button than beat the pin code out of them.
- A1kmm 13y agoPhone locks are not designed to keep a well resourced attackers out, they are to keep nosy people from casually accessing your data. Competent authorities will not access your phone through the phone interface, they will just image the data on it. Unless you encrypt data on your device with a strong key, they will get all your data anyway.
- CurtMonash 13y agoWow! What a great idea! We need to make up a name for it! How about "two-factor authentication"? Think that would ever catch on???