Happy Christmas from Team MNC

We hope Santa brought you exactly what you wanted. If not, check out these amazing tech deals a little elf brought us 🙂

We hope Santa brought you exactly what you wanted. If not, check out these amazing tech deals a little elf brought us 🙂

German hacking collective, the Chaos Computer Club, have announced that they have successfully broken the security on Apple’s highly-fêted Touch ID fingerprint sensor. They used simple, everyday means to demonstrate a straightforward way to circumvent the fingerprint-reading technology on a Heise Security iPhone 5S.
The group of hackers claim that this conclusively demonstrates that fingerprint biometrics are unsuitable as an access control method (as they have been claiming for some time). The news further calls into question Apple’s use of Touch ID and the various claims they are making about how secure it is. The implementation of a fingerprint sensor on the new iPhone 5S has been touted as an advanced technology with both privacy and security benefits. Fingerprints biometrics are also used on some passports.
However, despite the fact that the home button sensor is only 170 microns thick and has a scanning resolution of 500 ppi, it appears to be fairly trivial to bypass with normal household materials. Previous attempts to incorporate fingerprint sensors as access devices have been found to be easily broken. For all the typical bigging up Apple has been engaging in, there’s nothing revolutionary about the Touch ID sensor. The only real meaningful difference between it and earlier incarnations is that it has a higher resolution.
And so, the Chaos Computer Club attempted to put to rest all the bogus speculation surrounding the fingerprint sensor. They have experience in bypassing other finger and sensors, they decided that the first step to try would be to simply produce a fake fingerprint with as high a high resolution as possible.
For their proof of concept hack, they simply photographed the fingerprint at 2400 dpi, digitally cleaned up the image, and then laser printed it at half that resolution onto a transparent sheet using as thick toner as the printer was able to produce. Then, by applying a layer of standard PVA wood glue and then peeling off, the thick toner leaves a tiny invent similar to a fingerprint. If you just peel off the set glue from the plastic sheet, you then have your very own fake fingerprint. The little bit of damp breath applied, it’s now effortless to break into any Apple device supposedly-secured by touch ID.
This is just a quick hack that took a couple of days to produce working results. Later on, the Chaos Computer Club refined and affected their method. Instead of photographing the fingerprints, they use the scanner instead. And they found that using photosensitive PCB produced a cleaner mould than a simple computer printout. They also determined that the end product be improved upon by using a thin coat of graphite grey instead as it is easier to peel off the fake fingerprint before applying the PVA glue. Frank Rieger, spokesperson of the CCC said the following:
We hope that this finally puts to rest the illusions people have about fingerprint biometrics. It is plain stupid to use something that you can’t change and that you leave everywhere every day as a security token. The public should no longer be fooled by the biometrics industry with false security claims. Biometrics is fundamentally a technology designed for oppression and control, not for securing everyday device access.
We can only concur with this sentiment. After all, it is well known that governments and state security agencies scan your fingerprints at way high resolutions that is required to perform this hack will stop not only that, but your fingerprint is permanent and cannot ever be changed. It’s already been claimed by many that the whole Touch ID system is little more than a meaningless gimmick, but this surely puts to rest the notion that it provides meaningful security for your devices.
What you make of this hack? Did you think the security would be broken this quickly? Do you have an Apple device with Touch ID and do you make use of this feature? And what you think would be the best way to secure our mobile devices?

While we’re hoping for a white Christmas here at Mobile Network Comparison, over in the antipodes a woman enjoying a trip to Melbourne was glad that the weather’s currently rather balmy.
Senior Constable Julie-Anne Newman from the local Victoria police department reported last week that a tourist fell off St Kilda pier as she was too engrossed in browsing Facebook on her smartphone to notice the end of the promenade.
Just before midnight local time, the woman fell into the water and, unable to swim, frantically splashed about. Her efforts didn’t do her much good as she failed to climb back out again and soon found herself about twenty metres out into Port Phillip Bay.
Bystanders and onlookers were not forthcoming in their attempts to help her. It took police in the vicinity to help locate the woman and orchestrate the rescue by specialist police boats.
On this blog we’ve already covered the reasons why it can be a bad idea to walk and text at the same time. But maybe we should be explicit is saying that it’s a good idea to keep your eyes off your phone and on where you’re going if you’re on a pier in the middle of the sea without any safety barriers. Especially if you can’t swim!
Thankfully, although the woman was taken to hospital for treatment, we came to no harm. Nor did her mobile phone as she desperately held onto it the whole time she was trying to avoid drowning.
Personally, we don’t think she even wanted to join Facebook in the first place. We have a suspicion that it was pier pressure!
Recent Comments