Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Samsung always seems to me as if they race to match any iPhone feature–but never more than skin-deep.

So when the iPhone gets a fingerprint sensor that saves only a hash of the actual data in a special enclave of a custom chip, Samsung responds with an iris scanner that saves an image of the iris as a world-readable jpeg in your home directory.

Thus, their marketing material can claim feature-parity (or even exceed Apple). But it never seems like they actually care.

It's not like Apple doesn't run into similar problems (not sure if the fingerprint sensor has been defeated–it's a bad idea for 5th amendment reasons in any case). But at least they do the minimum in trying.



>It's not like Apple doesn't run into similar problems (not sure if the fingerprint sensor has been defeated–it's a bad idea for 5th amendment reasons in any case). But at least they do the minimum in trying.

In 2013 a CCC member broke TouchID access within a few hours after release of the IPhone. All needed was a photograph of the fingerprint on a glass surface. https://www.ccc.de/en/updates/2013/ccc-breaks-apple-touchid

Same method worked on the Iphone 6, as Apple hasn't changed a thing. Biometry is fundamentally broken.


>All needed was a photograph of the fingerprint on a glass surface.

And wood glue! Looks like that method proved unreliable, so they expanded it:

"To create the mold, the mask is then used to expose the fingerprint structure on photo-senistive PCB material. The PCB material is then developed, etched and cleaned. After this process, the mold is ready. A thin coat of graphite spray is applied to ensure an improved capacitive response. This also makes it easier to remove the fake fingerprint. Finally a thin film of white wood glue is smeared into the mold. After the glue cures the new fake fingerprint is ready for use."


Yes. They explained all the innovative magic of Apple's fingerprint sensor was better image resolution. So all they had to do was improving that on their end too. I imagine the body changes everywhere over time, so this resolution game has a hard limit. A fingerprint is the worst choice of biometric data, as people leave them everywhere...


So what's better, then? Tongueprint? I'm down to lick my phone to turn it on.


Tongue prints work fine on typical phone fingerprint readers, so it is an option.


I tried my noose tip and and tonge, neither worked (Huawei). Toes work (obviously).

People reported that pet's pawns work.


And you know this because you tried it? LOL :)


Actually, my father-in-law, which was pretty funny because he is typically quite reserved.


Iris scan is probably still our best bet, we just need better hardware and software.

How is the iris scanner on Microsoft phones in comparison?


People don't leave perfect moldae prints everywhere.

AFAIK CCC never had a proof of concept of a real world usage of this. They needed access the original finger.

That isn't to say it's not possible but it is a pretty major asterisk.


Didn't some group pull a politician's finger print off his dinner glass and then include it as an insert with all the issues of some magazine?

Can't find the reference right now, but somebody's gotta remember this, it was when the UK was considering using biometric data as IDs.


That was CCC in 2008. To underscore the inherent problems of biometric authentication, they pulled Wolfgang Schäuble's fingerprints of a dinner glass and published it in their magazine. That issue also included a ready-to-use replica. Schäuble was Germany's interior minister at the time and a strong proponent of biometric data in passports and increased surveillance.

https://www.ccc.de/updates/2008/schaubles-finger (in German)


They have done it with a fingerprint left on the device screen later on, if i remember correctly.


If I remember rightly that was a print applied to scanner glass, much less successful, and required absolutely perfect print transfer.

Which, imo, isn't much different conditions tbh (i.e. not representative of the real world)


Read the original ccc article or watch the video! They got the print off the phone itself. Only restriction is a high resolution scanner OR camera to capture it.


They did it also with a simple press photo of a politician.

There's no need to get a perfect copy.


> Biometry is fundamentally broken.

"fingerprints are usernames, not passwords" is the standard advice I've read.


> In 2013 a CCC member broke TouchID access within a few hours after release of the IPhone.

It's actually the same guy as with the S8, aka Starbug.


https://media.ccc.de/v/31c3_-_6450_-_de_-_saal_1_-_201412272...

They also managed to get the fingerprint of a politician via a high resolution picture taken at a speech. (Also a phone PIN via eye reflection captured by the front camera.)


> It's actually the same guy as with the S8, aka Starbug.

Yes, hopefully he will give another talk at 34C3. Very entertaining guy too!


No need to wait for 34c3, he's giving a 30 minute talk at Gulaschprogrammiernacht in Karlsruhe on Thursday: https://entropia.de/GPN17:hacking_galaxy_S8_iris_recognition


AS i have come to understand it, biometrics is a good identifier (telling who you are) but a lousy authenticator (telling that you are allowed).

The use of biometrics on mobile devices somewhat mix this, with the assumption that if some user was authenticated within a certain time frame (via a pin or some other knowledge bound check), a simple id is enough to extend that authentication.


> authenticator

Authorization is the counterpart to Authentication: authentication proves who you are (with passwords/tokens/biometrics aka something you know/have/are), authorization controls what you can do (with permissions/ACLs/roles/etc.)

To put it another way, the bouncer at a club checks your photo ID to see that you match it (authentication via something you are), then uses it to see if you can enter (authorization by checking your birthdate against a cut-off/name against a guestlist).


Samsung always seems to me as if they race to match any iPhone feature–but never more than skin-deep

Firstly, any biometric technique can be beaten. Against a known, committed foe, it is almost impossible to defend with surety. And for that matter, who can't obtain the pin code of any other user given a short amount of time and focused attention? The notion that "if someone takes an IR high resolution, close photo of your iris they can defeat your security" is asinine given that the same people could obtain your pin in a million and one ways.

These mechanisms are to induce users to use some security, and the primary defense is against lost or stolen phones, making it convenient enough that it isn't disabled.

Secondly, how did this somehow turn into yet another Royal Apple spiel? Aside from the easy beatability of the Apple fingerprint sensor, why wouldn't you compare the fingerprint sensor on a Samsung?


> ...if someone takes an IR high resolution, close photo of your iris they can defeat your security...

There are commercial security products that regularly perform "IR high resolution" iris scans from several meters away and require no cooperation from the target. Stanley CSS sold one that sat on top of a doorway over five years ago, their product literature says that you need to look at it - but having demoed it myself, I can say that is not true.


Have any real security researchers have tried to analyze and break this one?

Until CCC approves your CSS I will consider it insecure.


You've misunderstood my point, which is that distant iris data collection from non-cooperative subjects is so easy now that vendors are selling solutions pretty cheaply. So using it for security, without additional checks in place, is like walking around with your pin written on your forehead.



Samsung always half-asses their new features. They are so desperate to be first to market or to make a splash they rarely take the time to make it work well. It's my biggest frustration with Samsung, they have the resources and market position to take the long view and give their teams more time to polish, but never do.


And this is why it makes it so difficult to choose high end phones. I have been shouting about how my Pixel phone is magnitudes better of a device than any other phone I've ever used, including the S8.

On paper it looks awful, but everything this phone does works 100% of the time quickly and without stuttering or failing.


I'm on my second Samsung. First was a very annoying pre-capacitive touch that never worked well. This current one is an old Galaxy S5. It is better, but it likes to restart periodically (fortunately Android handles that well). Battery life is crap and it gets sluggish easily.

Before I had a Motorola. It was much better. I will not buy another Samsung.


I like my Galaxy S6. Bike shed!


I'd say the Pixel is the best Android phone for sure.

But that should be expected, as it's from Google


I wouldn't say expected, they have made some poor performing phones in the past (for various definitions of "made").

But my point was more that on paper it doesn't look like much. It doesn't have waterproofing, it's not "best in class" in anything except the camera, it runs software which has less "on paper" features than other brands, it doesn't have an SD card or removable battery, etc...

But when you actually go to use it, it's a night and day difference between it and other devices.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: