Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: Swordmaker
I have read some of the literature concerning scanning of the inner dermal layer to make cloning more difficult. It appears, however, that the iPhone 6 fingerprint authenticator can still be hacked using a cloned fingerprint, as demonstrated here. "Touch ID was ‘hacked’ less than a month after introduction, thanks to a latex finger and fingerprint." (Banking Technology, December 14 2014)

What do you say to those that say that dual- or multi-factor authentication is still necessary?

17 posted on 12/29/2014 10:13:19 PM PST by Praxeologue
[ Post Reply | Private Reply | To 1 | View Replies ]


To: Kennard
What do you say to those that say that dual- or multi-factor authentication is still necessary?

For the same reason the guy who succeeded in your link does. . . it is very complex to get a fake fingerprint that has sufficient underlying detail to work. . . and it still has to be on a living finger. It WILL NOT WORK with just a photo. He states it is a very complex procedure for it to work. . . he says:

The attack requires skill, patience, and a really good copy of someone’s fingerprint — any old smudge won’t work. Furthermore, the process to turn that print into a useable copy is sufficiently complex that it’s highly unlikely to be a threat for anything other than a targeted attack by a sophisticated individual.

Why I hacked TouchID (again) and still think it’s awesome

I posted about this hack back when it came out. . . and it was completely discussed on the forums. The amount of equipment necessary to get a good fake fingerprint, essentially requiring using a superglue vapor transfer technique to lift a fingerprint that will get the underlying ridge detail, makes this a non-starter hacking method. The equipment to do that costs in the multiple thousands of dollars.

Being able to steal someone's phone and then access their TouchID is NOT going to happen by using an easy to acquire fingerprint copy.

18 posted on 12/29/2014 11:01:32 PM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users contnue...)
[ Post Reply | Private Reply | To 17 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson