Hackers claim to have foiled Apple's new Touch ID system

503

Apple hyped its new Touch ID fingerprint scanning security system as a "convenient and highly secure way to access your phone," but if a new report is accurate, the system may not be as secure as the company claims. Hackers from the Chaos Computer Club claim to have successfully bypassed Touch ID "using easy everyday means."

"In reality, Apple's sensor has just a higher resolution compared to the sensors so far," a hacker nicknamed Starbug said. "So we only needed to ramp up the resolution of our fake."

While the hackers claim the method is easy, it's complicated enough that most iPhone 5S users aren't as likely to have their security compromised by an everyday thief who would have to be willing to obtain a high-resolution photograph of a fingerprint and produce a physical fake. (It's also not nearly as easy to bypass Touch ID with this method as, say, fooling Android's Face Unlock feature with a simple photo of a person). But the method's relative simplicity, which involves photographing a fingerprint left behind on a surface and then creating a glue model of it, calls the sophistication of Touch ID's technology into question. Before Touch ID was officially announced, Wired's Bruce Schneier noted that fingerprint readers have long faced vulnerabilities, and that the simplest readers can be fooled with a good photocopy.

While getting fooled by a fake glue finger isn't great for Touch ID, it's not the most serious security concern facing the system. On Friday, Senator Al Franken said that the system "raises substantial privacy questions," and wrote a letter to Apple CEO Tim Cook requesting more details about Touch ID. Critics are concerned that a user's fingerprints may be accessible to hackers or other bad actors — something Apple says is virtually impossible, since Touch ID is said to only locally store a mathematical representation of a user's fingerprint.

The CCC says that the bypass has been demonstrated in a video, which can be seen below.

We've reached out to Apple for comment and will update if we hear back.

Thanks, Junkie!

Read More: Apple iPhone 5S review

Read More: Fingerprint analysis: will the iPhone’s newest sensor change the world again?

More from The Verge

Back to top ^
X
Log In Sign Up

forgot?
Log In Sign Up

Please choose a new Verge username and password

As part of the new Verge launch, prior users will need to choose a permanent username, along with a new password.

Your username will be used to login to Verge going forward.

I already have a Vox Media account!

Verify Vox Media account

Please login to your Vox Media account. This account will be linked to your previously existing Eater account.

Please choose a new Verge username and password

As part of the new Verge launch, prior MT authors will need to choose a new username and password.

Your username will be used to login to Verge going forward.

Forgot password?

We'll email you a reset link.

If you signed up using a 3rd party account like Facebook or Twitter, please login with it instead.

Forgot password?

Try another email?

Almost done,

By becoming a registered user, you are also agreeing to our Terms and confirming that you have read our Privacy Policy.
Spinner.vc97ec6e

Authenticating

Great!

Choose an available username to complete sign up.

In order to provide our users with a better overall experience, we ask for more information from Facebook when using it to login so that we can learn more about our audience and provide you with the best possible experience. We do not store specific user data and the sharing of it is not required to login with Facebook.

tracking_pixel_5345_tracker