Well, that didn't take long. Apple's fingerprint-based TouchID system has been hacked just days after the iPhone 5S's release. The Chaos Computer Club is behind the exploit, which is described on the group's blog.
First, the fingerprint of the enroled user is photographed with 2400 dpi resolution. The resulting image is then cleaned up, inverted and laser printed with 1200 dpi onto transparent sheet with a thick toner setting. Finally, pink latex milk or white woodglue is smeared into the pattern created by the toner onto the transparent sheet. After it cures, the thin latex sheet is lifted from the sheet, breathed on to make it a tiny bit moist and then placed onto the sensor to unlock the phone.
This process has apparently been used to defeat numerous fingerprint sensors. The hackers had to increase the resolution to trick TouchID, but they otherwise used a method detailed way back in 2004. As the author of those instructions points out, fingerprints make lousy passwords. "You leave them everywhere," he says, "and it is far too easy to make fake fingers out of lifted prints."
Having seen the folks at Mythbusters fool fingerprint sensors years ago, I figured it was only a matter of time before Apple's implementation was exposed. I'm a little surprised it only took a few days and a slight modification to an existing method, though. Surely, Apple had to be aware that its system was susceptible to attack.
Faking fingerprints still takes a bit of work, and you do need to lift the originals, so it will be interesting to see if TouchID users feel vulnerable enough to go back to passcodes. One-touch unlocking may be too convenient for some to give up. Thanks to TechEye for the tip.
|1. Ryszard - $603||2. Hdfisise - $600||3. Andrew Lauritzen - $502|
|4. Redocbew - $350||5. the - $306||6. SomeOtherGeek - $300|
|7. chasp_0 - $251||8. Ryu Connor - $250||9. mbutrovich - $250|
|10. YetAnotherGeek2 - $200|
|ASRock kills its SkyOC BCLK overclocking feature||45|
|Deals of the week: Samsung's 850 EVO 1TB SSD for $290 and more||41|
|National Bubble Gum Day Shortbread||15|
|NEC PA322UHD-2 blends a 4K IGZO panel with pro features||18|
|Google Safe Browsing blocks sites with fake download buttons||52|
|National Homemade Soup Day Shortbread||38|
|Audiosurf 2 is worth a look||26|
|ASRock A88M-ITX/ac gives AMD APUs a fun-sized foundation||37|
|Logitech's G810 Orion Spectrum keyboard puts on a suit and tie||28|
|Stop bezel shaming. All bezels are beautiful.||+69|