4 ms·
Considering that people generally don't wear gloves when they use their phones this is like having a picture of your key on your door. Combine that with what we
by sehrope 13y ago
Considering that people generally don't wear gloves when they use their phones this is like having a picture of your key on your door. Combine that with what we know you can do with pictures of keys[1] and yes it's obviously not a very good idea.
[1]: https://news.ycombinator.com/item?id=6167246 https://news.ycombinator.com/item?id=6167246
- numbsafari 13y agoSo, if this can be accomplished with keys, have you removed all the locks from your house? Do you rotate your locks every 3-6 months?
- sehrope 13y agoMy front door does not have a picture of my key on it. My phone has tons of fingerprints though. It's a touch screen phone. One of those words is "touch" which clearly implies your finger coming in contact with it. Even if you wanted to use gloves you need special ones for it to work properly with the capacitive screen. Unless you are continuously wiping it (the screen, not the data) it will have you prints on it.
- numbsafari 13y agoIf you slightly smear your finger every time you remove it from the sensor you shouldn't have this problem. Additionally, if you are keeping your phone in your pocket, as I do, pull it out and take a look (like I just did) and you'll be hard pressed to see much of anything resembling a useful print. I use my phone pretty much all day long and it is devoid of useful prints. Does that mean you couldn't find my prints in other places? Sure. But I can probably find your keys in other places, too. We know that SSL is generally not implemented properly, that the CAs are probably all hacked or subverted by the NSA, that the NSA may have developed backdoors to a number of the more popular encryption suites, but I don't hear anyone running around demanding Google or Facebook disable SSL. If you are doing something that requires sufficient security that you don't want someone to access it via your fingerprint alone, add additional layers of security. If you are doing something potentially incriminating ... don't do it on your freaking phone because it's probably been exploited in a dozen other ways by various authorities who can use it to find out most of what they need without being in physical possession of the phone anyway. Most people aren't worried about the mafia or the CIA or the NSA. Most people don't even bother using a passcode, let alone a passphrase on their phones. If you can add something as easy to use as this, then it adds an additional layer of security against the casual abuse most people will find themselves subjected to (random people making calls from your phone, spouses spying on their email, etc.). If you are worried about the CIA and the NSA, using a phone at all for anything is probably not in your best interest at this point.
- EpaL 13y agoAssuming someone did steal your phone and look for prints, they would need to know which print to lift and that it's enrolled with Touch ID. After they, they only get 5 goes to be successful before the phone insists on your passcode. CCC made it look easy but I bet it didn't work for them first try or even 5th try...
- Osmium 13y ago> My front door does not have a picture of my key on it. Yeah, but as every decent locksmith will attest, very-nearly-almost-all door locks can be easily opened with the right tools. Like picking a lock is a specialist skill, so is lifting a fingerprint and making a copy of it. No security is absolute; it's all trade-offs. Making it such that it's not worth your adversary's time to bother.
- hrjet 13y agoYes, but as the same decent locksmith would attest, it would be foolish to have a picture of a key beside the lock, or anywhere in a public place. And that is what happens with a finger-print based secure system; you inadvertently place the imprint of the key on the phone's display as well as public places.
- Osmium 13y agoBut the point is that you don't need a picture of the key beside the lock for a locksmith to break into your house! And, indeed, if there was one it would probably be faster and easier for him to use a lock pick rather than taking the time to cut a new key.
- abritishguy 13y agoIt is a phone, you can bypass the passcode with a computer anyway - the passcode/touch is designed to prevent opportunistic unlocks not a determined attacker and it is much better than a passcode at doing that.
- bobbles 13y agono no no no no. This is not being done by lifting an existing print from the existing device. They're taking a photo of the authorised FINGER and using that to create their fake finger... I don't see how this could be considered a significant issue unless you are going to steal someones phone AND somehow get a still 2400 dpi photo of the surface of their finger
- ethanhunt_ 13y agoYou are incorrect. Second sentence of the article: "A fingerprint of the phone user, photographed from a glass surface, was enough to create a fake finger that could unlock an iPhone 5s secured with TouchID."
- melange 13y agoA meticulously placed fingerprint was made on a clean and polished glass surface as if it was being taken by the police. Nothing like a normal fingerprint left by accident.
- czhiddy 13y agoWhich glass surface? The oleophobic glass on the iPhone itself? If the print was copied directly from one of the phone surfaces, you'd think that the CCC would want to include that little tidbit.
- slantyyz 13y ago>> Which glass surface? The oleophobic glass on the iPhone itself? That brings up another interesting point -- I wonder how many people are going to put screen protectors on their 5S's that are not oleophobic.