5 ms·
> If you use your thumb to unlock it, the way Apple designed it, then you are looking for the finger which is least likely to leave a decent print on the iPhone
by guygurari 13y ago
> If you use your thumb to unlock it, the way Apple designed it, then you are looking for the finger which is least likely to leave a decent print on the iPhone.
This is my main takeaway. I suspect the vast majority of iPhone users either do not secure their phone at all, or use a 4-digit PIN, and therefore are not protected against targeted attacks anyway. Touch ID can improve security for these users.
My main reason for protecting my phone is to prevent a scenario where it gets stolen, and the thief can access my data with reasonable effort. My secondary reason is to protect against snoopy acquaintances. A 4-digit PIN marginally achieves these goals: a typical thief is locked out, but a more sophisticated one can easily brute-force my code using commercially available tools.
What if I use Touch ID instead? It is very likely that a thief will not know who I am, and therefore will not be able to go around lifting my fingerprints. They might, however, try to lift prints off my phone. The way to protect against this is to only unlock the phone using my thumbs, because (per TFA) there are typically no good thumb prints on the phone itself. If I do this, then I will in fact be more protected than I would be using a 4-digit PIN.
A couple of caveats. After 5 rejected attempts the iPhone will fall back to asking for a PIN. It is therefore advisable to set a strong (longer than 4 digits) PIN here. Second, this of course may change if the 'secure enclave' that stores the fingerprint hashes gets hacked.
TL;DR: If you only use your thumbs to unlock your iPhone, Touch ID currently provides better security against typical threats than a 4-digit PIN.
- casca 13y agoPlease know that the 4-digit pin is easily removed by someone with non-specialist tools that are widely available. Touch ID is too new to assess whether this is also the case for the new Iphone, but it's quite possible that there is a sufficiently clear fingerprint on the screen of your device already for reuse. UPDATE For more detail about how this is done, have a look at the current releases of jailbreaking tools. The general method is to perform a temporary jailbreak which allows the ability to SSH into the device and dump all the data.
- lawnchair_larry 13y agoThe 4 digit PIN is not at all easily removed. This meme needs to die.
- dan1234 13y ago> Please know that the 4-digit pin is easily removed by someone with non-specialist tools that are widely available. Got a credible source for this?
- hrrsn 13y agoI've used msftguy's SSH ramdisk tool plus the iphone-dataprotection tools on Google Code. Takes about 20 minutes maximum to bruteforce the 4 digit PIN. What the poster doesn't mention that this only works on devices with iBoot bootloader exploits, which is currently the A4/iPhone 4 and lower. The 4S, 5, 5S, 5C etc are all safe from this.
- mitchty 13y agoAdditionally, its rather easy to switch your lock password to be regular text. Good luck guessing the length and the passphrase I use to lock my phone now when the keyboard comes up.
- hrrsn 13y agoThis isn't true for devices with the A5, A6 or A5 processor. The iPad 2, 3, 4, mini, 4S, 5, 5C and 5S are safe.
- danieldk 13y agoCould you explain why? Or at least provide some pointers?
- bri3d 13y agoIn order to start bruteforcing the PIN using the current method, you need to get code running on the device before iOS has finished booting, which means a custom ramdisk. Only pre-A5 CPUs are vulnerable to the boot-ROM exploit which allows a custom ramdisk to be uploaded. The exploit is called "limera1n" or the "A4 boot-ROM exploit" if you're interested in learning more.
- hrrsn 13y agoThis is all correct. While there have been A5/A6 jailbreaks, none have been at a low enough level (not a bootloader exploit) to provide the facility to load a ramdisk so none of the above tool methods are compatible.
- psutor 13y agoIt is also extremely easy for your acquaintances (or even patient thieves) to learn your PIN, unless you unlock in a weird, secretive way that is sure to cause teasing or funny looks. In this way Touch ID is a far far superior defense against snoopy acquaintances unless you happen to be unconscious around them.
- alex_doom 13y agoIt's really a SO lock out. Now your girlfriend/boyfriend is going to have a harder time snooping on your phone. :D
- eeeeeeeeeeeee 13y agoYou can also disable the simple pin (4-digit) and switch to a real passphrase as the alternative authentication mechanism. So if the touch ID fails for whatever reason, you need to enter that complex passphrase (which should be a rare occurrence). I think that's more secure than a 4 digit pin also, which a friend or attacker could witness you entering from a distance.