Breaking News

LG Display becomes world’s first to mass-produce 1-120Hz laptop panel ASRock Launches new 240Hz Gaming Monitors Arctic announces Senza AI 370 Under Desk PC for AI Applications CORSAIR Announces the Airflow-focused 3200D Mid Tower for Ambitious DIY PC Builds Silicon Power Launches Enterprise-Grade DDR5 RDIMM to Accelerate AI Workloads

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Security Firm Hacks iPhone Fingerprint Scanner

Security Firm Hacks iPhone Fingerprint Scanner

Smartphones Oct 4,2013 0

A German security company has figured out an easy way to crack the fingerprint scanner of the new iPhone 5S. Berlin's Security Research Labs (SRL) published a video demonstrating the newly discovered flaw.

SRL, which has also disclosed a major security flaw in SIM card technology that affected mobile systems around the globe, said it has shared its research with Apple's security team.

According to SRL, using fingerprints as credentials for local user authentication has two shortcomings when compared to passwords. Once a fingerprint gets stolen, there is no way to change it. To offset this high compromise penalty, fingerprints would need to be very hard to steal. However, users leave copies of their fingerprints everywhere; including on the devices they protect. Fingerprints are not fit for secure local user authentication as long as spoofs ("fake fingers") can be produced from these pervasive copies.

"The iPhone 5s?s fingerprint sensor does not only appear to provide no additional protection, its use even undermines other security mechanisms," SRL said.

The iPhone 5s has moved slightly beyond the capabilities of earlier touch sensors: It provides a higher resolution image of the users' fingerpints and according SRL, it uses this higher resolution to match based on finer structures. However, SRL claims that even these finer structures can be spoofed, for example based on an equally high resolution smartphone camera image, showing that some defense strategies only improve at the pace of the corresponding attack technique.

"Fingerprint spoof prevention would better be based on intrinsic errors in the spoof-creation process or on fingerprint features not present in latent prints (and become much harder to steal)," SRL added.

The iPhone 5s, on the other hand, was defeated by techniques widely published years ago.

The researhcers also identified vulnerability that could potentially give criminals time to break into the phones, gain complete control of data, access email accounts and then potentially take over the user's bank accounts.

In this video SRL demonstrated how other flaws in iOS and iCloud are exposed that ? when combined with Touch ID?s vulnerability to fingerprint spoofing ? allow for online identity theft.

Tags: iPhoneApple
Previous Post
LCD TV Panel Shipments Dip in Q3 For The First Time
Next Post
New Acer and Gateway All-in-Ones Arrive Soon

Related Posts

  • Apple introduces AirPods Max 2

  • Apple introduces the new M5 Pro/Max powered laptops and new Studio Display

  • Apple introduces iPhone 17e and new new iPad Air

  • Leica LUX Case for the iPhone 17 Pro/Pro Max

  • Apple introduces new AirTag with expanded connectivity range and improved findability

  • Apple introduces Digital ID

  • Apple unleashes M5 CPU and new devices

  • Apple debuts iPhone 17, Pro, Max, Air, Watch Series 11, Watch Ultra 3, Watch SE 3, AirPods Pro 3

Latest News

LG Display becomes world’s first to mass-produce 1-120Hz laptop panel
Enterprise & IT

LG Display becomes world’s first to mass-produce 1-120Hz laptop panel

ASRock Launches new 240Hz Gaming Monitors
Gaming

ASRock Launches new 240Hz Gaming Monitors

Arctic announces Senza AI 370 Under Desk PC for AI Applications
Consumer Electronics

Arctic announces Senza AI 370 Under Desk PC for AI Applications

CORSAIR Announces the Airflow-focused 3200D Mid Tower for Ambitious DIY PC Builds
Cooling Systems

CORSAIR Announces the Airflow-focused 3200D Mid Tower for Ambitious DIY PC Builds

Silicon Power Launches Enterprise-Grade DDR5 RDIMM to Accelerate AI Workloads
Enterprise & IT

Silicon Power Launches Enterprise-Grade DDR5 RDIMM to Accelerate AI Workloads

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Arctic Liquid Freezer III 360 Pro Argb

Arctic Liquid Freezer III 360 Pro Argb

Soft2bet and the unseen hardware that makes instant play possible

Soft2bet and the unseen hardware that makes instant play possible

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed