Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: Swordmaker
IPhones use TouchID or FaceID for ApplePay transactions. They are both secure from hacking.

Unnnnhhh. No. Both have been proven spoofable. But they are pretty much, good enough.

37 posted on 12/02/2017 9:05:50 PM PST by glorgau
[ Post Reply | Private Reply | To 10 | View Replies ]


To: glorgau
hh. No. Both have been proven spoofable. But they are pretty much, good enough.

Do a Google search for such spoofs. The only supposedly successful ones are highly questionable. There's the Bkav mask from Vietnam and the woman and her pre-teen son for FaceID. TouchID are all old from 2013 and replications of the original 2013/2014 on older iPhones.

That mask thing Bkav the Vietnamese "Security company" pulled was a hoax. . . Bkav actually is an ANDROID CELL PHONE company that is selling a fingerprint protected Android phone they were claiming was more secure than Apple's FaceID—not the Computer Security Company they claim they are—so they cobbled together a joke of a mask using a 3D"silicone" printed mask, as if that were something special, and then adding a hand made nose, because the 3D printed one was not accurate enough, and an "artists" applied skin texture, that they claimed fooled FaceID plus printed 2D eyes. They then announced their Bkav Bphone was far more secure than the trivially easy to fool FaceID. . . but to date have refused to specify exactly how they make their masks that will work.

However, the video Bkav showed did not unlock the way my iPhone X unlocks, or any iPhone X unlocks for that matter. . . theirs opened immediately to the home screen instead of to the alert screen that is expected to be swiped up. Nor did the lock icon animate to unlock. It stayed locked. In fact, it opens to the Enter PassCode LOCK SCREEN, even though they stated they had NOT entered a passcode (an impossibility when you set up faceID) and which you would NOT see unless you HAD entered a passcode, which they they just swipe up. . . revealing the home screen. . . which is what you'd see if you just swiped a photo of the Enter PassCode screen off the screen to reveal the home screen behind it.

The best Hollywood mask makers, building completely identical masks of the iPhone FaceID users, indistinguishable from the real people's faces, with laser measurements to assure accuracy, with their REAL EYES looking through them, could not unlock it. And these were ALSO made using "silicone" materials, yet these Vietnamese amateurs could in less than a week? Nope, they didn't. Even the Mask 2.0 from November 27, using a new 2D printed eyes with attention turned on is STILL a hoax to sell their Bkav fingerprint sensor Bphones.

The original "Starbug" spoofing of the TouchID was a guy using his OWN finger inside the rubber copy of his fingerprint. . . and the sensor read his subcutaneous fat pads THROUGH the fingerprint image on one out of five attempts. When his buddy put the rubber finger on his finger, it would not work at all.

Most of the other articles on spoofing fingerprint sensors are talking about Android phones. They were NEVER really reliably successful on iPhones or the FBI would not have had a problem unlocking the several thousand iPhones they have they need to unlock when they first got them. These supposedly simple TouchID hacks just don't work before an iOS device would have permanently locked if the owner had not been available to unlock it and reset the attempts. None have been spoofed by copying a fingerprint taken from any surface contact print (although one "researcher claimed to have done it, but no one was able to replicate his results.). One partial success used a system that cost almost a thousand dollars per finger model to make. . . but took longer to make the finger (AND required the user's original finger to scan) than the now less than over night time allowed before requiring a passcode to unlock.

40 posted on 12/02/2017 10:30:39 PM PST by Swordmaker (My pistol self-identifies as an iPad, so you must accept it in gun-free zones, you racist, bigot!)
[ Post Reply | Private Reply | To 37 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson