4 ms·
> It's one thing to leave fingerprints all around your environment, but there is now the potential to steal your biometrics over the internet. Correct me if I'
by speedyapoc 13y ago
> It's one thing to leave fingerprints all around your environment, but there is now the potential to steal your biometrics over the internet.
Correct me if I'm wrong, but the biometric data never leaves the device.
- erichocean 13y agoIt's also not stored on the device. Hashes, not fingerprints, are stored. You need the fingerprints themselves to fake out the hardware.
- marshray 13y agoRare is the phone without the owner's fingerprints stored all over it.
- erichocean 13y agoSure, but his post was about stealing data "over the Internet". That's not possible. All bets are off with physical access to the hardware, of course.
- Bud 13y agoNot true at all. There are quite a large number of cases out there that would be hard to lift fingerprints from. If the owner has this sort of case, and if the owner has cleaned the screen recently or just had the phone pocketed, thus wiping the screen off rather well...I think there are a large number of phones from which you would get no prints.
- melange 13y agoNobody has been able to use those low quality fingerprints to defeat TouchID.
- marshray 13y agoI wouldn't count on that. See https://twitter.com/dotMudge/status/381900643415240704 https://twitter.com/dotMudge/status/381900643415240704
- melange 13y agoThat picture shows a carefully polished phone into which someone has meticulously placed 5 careful fingerprints - as if they were being taken at a police station, nothing like the fingerprints you get in normal use.
- makomk 13y agoWell, they have to store fuzzy hashes rather than cryptographically secure ones since they're going to get a different section of the finger and slightly different features within that finger each time. There's a good chance that whatever form of fuzzy hashing they're using is reversible in the sense that, given a hash, you can create a fingerprint that isn't necessarily exactly the same as the original but will match that hash. For example, the obvious approach is to store fingerprint features, which will be then matched by any print that has the same features in the same positions. If you do a good enough job of generating the new print you might even be able to fool police investigations, since they compare prints the same way.
- bcoates 13y agoLooks like fingerprints have 30-40ish bits of entropy depending on how forgiving the device is, so unless they're doing some key stretching it should be practical to produce an image of a similar fingerprint by brute-forcing the hash with every biologically likely fingerprint. http://lukenotricks.blogspot.com/2009/04/on-entropy-of-fingerprints.html http://lukenotricks.blogspot.com/2009/04/on-entropy-of-finge...
- fancy_pantser 13y agoI think it's a hot topic in security circles right now that a worm or virus could infect these mobile devices and "phone home" with the data, resulting in a media nightmare.