5 ms·
It should be worth noting, taking someone's fingerprint and duplicating it is surprisingly easy. In fact, a duplicate print has been used to open door locks and
by eksith 13y ago
It should be worth noting, taking someone's fingerprint and duplicating it is surprisingly easy. In fact, a duplicate print has been used to open door locks and even computer locks as the Mythbusters have shown :
https://www.youtube.com/watch?v=3Hji3kp_i9k https://www.youtube.com/watch?v=3Hji3kp_i9k
- prjw 13y agoBack in 2008, the CCC even stole and published a fingerprint of Wolfgang Schäuble, who was the Minister of the Interior in Germany at that time. http://www.h-online.com/newsticker/news/item/CCC-publishes-fingerprints-of-German-Home-Secretary-734713.html http://www.h-online.com/newsticker/news/item/CCC-publishes-f...
- gte910h 13y ago"Stole" is a pretty heightened word for something we leave on literally everything we touch
- pvidler 13y agoThis seems specific to image-based fingerprint sensors? Apple's version does not appear to work this way...
- dobbsbob 13y agoCCC in Germany did the same thing, lifted a gov minister's fingerprint from a glass and made a duplicate to defeat a door lock
- JabavuAdams 13y agoInteresting, but obviously being able to lift fingerprints remotely is worse than having to physically access the target's handled objects.
- eksith 13y agoThat's very true. IMO Apple has already thought of this and I think they're not storing the fingerprint or even a direct hash or other signature of it on the device. They may be using some sort of unique key (a salt perhaps?) that is used in conjunction with the fingerprint to generate the final password. It's also possible that it may not be a "password" in the conventional sense. Maybe the fingerprint only serves as part of the private key of a public/private key pair where only the public key is stored on the device itself and the private key must be generated each time with a scan of the finger. This is all speculation, of course.
- jack-r-abbit 13y ago> This is all speculation, of course. I suppose that is why we have people asking the questions.
- baddox 13y agoThis seems like it would be a more powerful argument if the fingerprint sensor on the iPhone was used for more things than unlocking your phone and making App Store and iTunes purchases. As it is now, Touch ID doesn't need to be technically more secure, dynamic, or anonymous than a passcode or password, it just needs to be faster and more convenient. And what does a perpetrator do once they've lifted your fingerprint and made a copy? They still have to steal your phone or gain access to it for some amount of time, which requires very personal targeting.
- r00fus 13y agoIt should be worth noting that the fingerprint sensor on the iPhone5S is far more advanced than that door. Read up on more details and critique about TouchID: http://arstechnica.com/security/2013/09/fingerprints-as-passwords-new-iphone-touch-id-gets-mixed-security-verdict/ http://arstechnica.com/security/2013/09/fingerprints-as-pass...
- eksith 13y agoThe door scanner may be easily fooled, but the computer login scanner they worked on is a bit more sophisticated. The "sub-epidermal" scan is actually what a gelatin synthetic fingerprint with a latex skin would duplicate fairly well. It's important to note the scanner isn't an imaging sensor (I.E. camera) so touch and skin conductivity are still fair game.