4 ms·
Having a lock in your front door is not perfect but it is much better than not having one at all. The way that Apple haters use stunts like this to suspend nor
by epo 13y ago
Having a lock in your front door is not perfect but it is much better than not having one at all.
The way that Apple haters use stunts like this to suspend normal logic and reasoning in order to express their juvenile spite is staggering.
No one, ever, claimed TouchID was impregnable, but it is very good security and is better than what the vast majority of people do at present.
Anyone prepared to devote the time and resources that CCC did to breaking your phone has other simpler means at their disposal. I personally believe that no one else will replicate this achievement because it is simply a publicity stunt to get clicks and feed the hordes of anti-Apple zealots.
- hahainternet 13y ago> Anyone prepared to devote the time and resources that CCC did to breaking your phone has other simpler means at their disposal Really? Lift someone's print, leave it with superglue, scan and print it and then dump glue on the scan. That seems to be the sum total of what needs to be done. You need only sticky tape to lift the print and the rest can be done in an hour. It sounds quite action movie, but in reality it's pretty damn simple and if I wanted to get access to your phone I could easily prepare it in advance and carry a tiny latex strip in my wallet for just the right occasion without your knowledge at any point.
- deveac 13y agoIt sounds quite action movie, but in reality it's pretty damn simple Also in reality it will foil over 99% of potential unauthorized activation attempts as most people aren't going to craft fingerprints to get into someone's device. If reality is the bar you're using, TouchID still wins.
- deveac 13y ago>but in reality it's pretty damn simple Also, it's not remotely "pretty damn simple": https://blog.lookout.com/blog/2013/09/23/why-i-hacked-apples-touchid-and-still-think-it-is-awesome/ https://blog.lookout.com/blog/2013/09/23/why-i-hacked-apples... "Creating the fake fingerprint is arguably the hardest part and by no means “easy.” It is a lengthy process that takes several hours and uses over a thousand dollars worth of equipment..."
- Kesty 13y agoIs not about Apple haters is that the security code is actually more secure than TouchID. If having TouchID will increase the amount of people that doesn't lock thir phone I'm up for it. But is not this amazing super-secure technology that will revolutionize the world.
- sdbryan 13y agoReally? You think a four digit security code that users have to enter repeatedly is more secure than obtaining a 2400 dpi clean image of a specific fingerprint and a nontrivial lab procedure? It might require some patience but if you have an excuse for being around the target, it doesn't require great skill to see the digits as they are entered. In either case the adversary has to deal with Activation Lock which has been introduced with iOS7. I've read there is already something like 35% adoption of iOS7 so we may see soon how effective Activation Lock is at deterring theft.
- san86 13y agoThe problem is not so much what CCC has done, but CCC has started. In the days/month ahead.. there is now a possibility of building a more practical attack. Remember the firefox plugin which allowed users to steal FB user sessions in a cafe with Free WiFi (or any WiFi hotspot)? That wasn't a new attack.. just made an existing attack easier (and hence caught a LOT of attention). The threat is similar. Now there is an exploit.. now the collective security researcher (and hacktivist) will work to make the hack easier by building a tool.. THERE lies the real danger. I still commend Apple for trying. The real issue will be if I can steal the "Hash" of the fingerprint and reverse it to know who it is... so far TouchId has done well. The way that happens, Apple users will need to rethink using TouchID