iPhone 5s's touch ID may already be hacked

amirm

Banned
Apr 2, 2010
15,813
38
0
Seattle, WA
This didn't take long: http://news.cnet.com/8301-13579_3-5...o-have-defeated-apples-touch-id-print-sensor/

A day after the iPhone 5S hit the streets, a group of hackers in Germany say they have successfully bypassed the biometric security on the Apple's Touch ID fingerprint sensor by using "easy everyday means."

The Chaos Computer Club announced late Saturday that it defeated the security device by photographing an iPhone user's fingerprint from a glass surface and using that captured image to verify the user's login credentials. The sensor, which resides under the home button, replaces the four-digit passcode to unlock the handset and authorize iTunes Store purchases.

"This demonstrates -- again -- that fingerprint biometrics is unsuitable as access control method and should be avoided," the group wrote in a blog post detailing its bypass:

'First, the fingerprint of the enrolled user is photographed with 2400 dpi resolution. The resulting image is then cleaned up, inverted and laser printed with 1200 dpi onto transparent sheet with a thick toner setting. Finally, pink latex milk or white woodglue is smeared into the pattern created by the toner onto the transparent sheet. After it cures, the thin latex sheet is lifted from the sheet, breathed on to make it a tiny bit moist and then placed onto the sensor to unlock the phone. This process has been used with minor refinements and variations against the vast majority of fingerprint sensors on the market.'

"We hope that this finally puts to rest the illusions people have about fingerprint biometrics," CCC spokesperson Frank Rieger said in a statement. "It is plain stupid to use something that you can´t change and that you leave everywhere every day as a security token."

CNET has contacted Apple for comment and will update this report when we learn more.

It wasn't immediately clear if the group would lay claim to a bounty of more than $16,000 that is being offered to the first person who could hack the fingerprint sensor. IsTouchIDhackedyet.com -- the brainchild of independent security researcher Nick DePetrillo -- said on its Web site that it was waiting for the group to upload video of the process before declaring CCC the winner.

In addition to cash, the winner has been promised a free application from CipherLaw to patent the hack; several bottles of alcohol including Laphroaig, Maker's Mark, Argentine wine, Patron Silver, and Bulleit bourbon; a "dirty sex book," and an iPhone 5C.

The group's demonstration video:


 

About us

  • What’s Best Forum is THE forum for high end audio, product reviews, advice and sharing experiences on the best of everything else. This is THE place where audiophiles and audio companies discuss vintage, contemporary and new audio products, music servers, music streamers, computer audio, digital-to-analog converters, turntables, phono stages, cartridges, reel-to-reel tape machines, speakers, headphones and tube and solid-state amplification. Founded in 2010 What’s Best Forum invites intelligent and courteous people of all interests and backgrounds to describe and discuss the best of everything. From beginners to life-long hobbyists to industry professionals, we enjoy learning about new things and meeting new people, and participating in spirited debates.

Quick Navigation

User Menu

Steve Williams
Site Founder | Site Owner | Administrator
Ron Resnick
Site Co-Owner | Administrator
Julian (The Fixer)
Website Build | Marketing Managersing