3 ms·
" It isn't possible for your actual fingerprint image to be reverse-engineered from this mathematical representation." I'm not really convinced, nothing is abs
by gren 13y ago
" It isn't possible for your actual fingerprint image to be reverse-engineered from this mathematical representation."
I'm not really convinced, nothing is absolutely impossible in computer science. At least, can't we bruteforce it?
I'm curious to know if they are true saying there is no way to reverse-engineer it, Any paper on the subject?
- rimantas 13y agoOK, I'll give you a bcrypt hash generated from some sentence. Will you give me back my sentence? When?
- UnoriginalGuy 13y agoNo need to be snarky to them. You could have just explained the difficulty in it rather than phasing it like they're an idiot for not understanding the perceptual problem.
- biot 13y agoWith 1 in 50,000 odds of matching fingerprints, how about I supply you with a list of 50,000 sentences. You choose one at random, generate a bcrypt hash with the default work factor of 10, and I'll give you back your sentence within the day. Deal?
- interpol_p 13y agoMy understanding of that sentence is that it is a lossy conversion. A one-way cryptographic hash. Though I wonder how they update it with failure attempts. (When a failed scan occurs, if the subsequent scan is successful then data is used from the failed scan to update the fingerprint data.)
- gren 13y agoOk, I get it! If I understand it correctly, if it's lossless, 2 different fingerprints could pass the test (collision)? So by a bruteforce technique, I could be able to generate a subset of all possible fingerprint (finite?). Tell me if I'm wrong, but maybe by "cross checking" with another data (e.g. another device with a second different conversion algorithm) I could finally find out what was your fingerprint! That's quite overkill though!
- denzil_correa 13y ago>Tell me if I'm wrong, but maybe by "cross checking" with another data (e.g. another device with a second different conversion algorithm) I could finally find out what was your fingerprint! Sure, but that's not the same as reverse engineering your fingerprint from the "mathematical representation". It isn't possible for your actual fingerprint image to be reverse-engineered from this mathematical representation.
- interpol_p 13y agoThink of it like this. We can oversimplify what Apple is doing with Touch ID. Let's say when you scan your fingerprint Apple breaks it down into three key properties, A B and C. Each fingerprint has a different percentage for A B and C. So yours might read as A 50% B 30% C 0% This data is then cryptographically hashed with some unique identifier inside the phone (so the same data would store differently on every iPhone). The data is then irreversibly transformed into a different representation. You can't retrieve the unique properties of the fingerprint, nor can you retrieve the fingerprint itself. In the linked article, Apple states that the probability of two fingerprints matching in Touch ID is 1 in 50,000. So that just means that their algorithm for breaking fingerprints down into key features discards enough information that it is possible to read two different human fingerprints as the same fingerprint.
- troels 13y agoInstead of a single hash, they could hold an array of hashes to test against. This array could then be added to as needed.
- UnoriginalGuy 13y agoI don't like the word "impossible" so let's leave that by the sidelines. Impractical is a word I prefer. The reason it is impractical is firstly it is lossy not lossless data storage meaning that when your fingerprint is scanned a whole ton of information is discarded immediately and then the fingerprint is normalised which discards yet more still before being stored. So the resulting data stored literally doesn't contain the same level of information as a "real" human fingerprint, and as a result of that the data might be useful in recreating a simulated fingerprint which can beat Apple's TouchID but it would likely still be incompatible with most other fingerprint systems and databases, and the fingerprint you recreated from the data likely wouldn't look like your "real" fingerprint as several million different fingerprints can result in the same lossy compressed representation stored in the phone. Imagine it like taking a photograph and then using a JPG compressor to decrease that photograph's size by 80% an then trying to get back the original photograph from the compressed JPG. While you can certainly get close it is implausible that you'd ever get the original image back and even if you did get it back there is no way to verify that the "original" you recreated was the same as the actual original without the actual original to compare it to.
- gren 13y agoThanks for your comment :) So eventually, if you can generate all possible set of fingerprints which match that hash and "cross check" it with another fingerprint systems, you could be able to approach the guy fingerprint? (I mean you maybe reduce the set to a reasonable size) The use case is quite overkill though! Also, generating all possible set of fingerprints is probably a lot of computation.
- UnoriginalGuy 13y agoThe other fingerprint system would need to be compatible with your data source, but if you had a compatible system and if you could generate every potential fingerprint for a given hash you could definitely use cross-checking to find any individual in your several million who also happens to be in the database. I think the biggest potential problem with that approach is both incompatibility and also false-positives. You might have "too many" matches for it to be useful for much.
- biot 13y ago> 1 in 50,000 probability means it requires trying up to 50,000 > different fingerprints until potentially finding a random match If you were hypothetically able to extract the hash from the "Secure Enclave" you could take a database of fingerprints (no doubt these exist somewhere: prison, military, customs, ...) and hash those to attempt to find a match. As Apple says, you have a 1 in 50,000 probability of randomly matching it. Once you find a hash match, you can then 3D print it and use it to unlock the device. A very impractical attack against the average Joe consumer. Someone would have to be a very high value target with sensitive information on their phone to use this, and that's assuming a direct extract via physical connection isn't the more viable option.
- interpol_p 13y ago> you can then 3D print it and use it to unlock the device You might not be able to do even this. According to the info released so far the sensor captures a sub-epidermal print. Edit: Also I am unaware of a 3D printer that is capable of printing the resolution required to represent a fingerprint.