So the Touch ID thing lasted, what, two days?
I want to be clear I'm not surprised, exactly. I'm the guy who's been saying for years that fingerprints make lousy passwords because you leave them on literally everything you touch, including the phone they're supposed to protect. But even I didn't expect the crack to land this fast. Apple opened the iPhone 5s for sale Friday morning, people camped outside stores overnight (there were at least a dozen tents outside the Fifth Ave store by Thursday evening, which is its own kind of insane), and by Sunday night a German hacker group called the Chaos Computer Club was already showing video of Touch ID getting fooled with a fake finger made out of wood glue.
The method isn't even that exotic once you read how they did it. Photograph the fingerprint off a glass surface (a smudge on the phone screen itself works fine), bump the contrast up in some photo editing software, print it onto transparent sheet with a laser printer at high toner density, smear on some latex or wood glue, peel it off once it's dry, and press it over your actual finger. The CCC member going by "Starbug" has apparently been doing versions of this trick for close to a decade against other fingerprint sensors, so this wasn't him staying up all weekend cracking new ground, it was him dusting off a technique that already worked.
What gets me is Apple's own marketing language going into launch, the stuff about how Touch ID reads "sub-epidermal" layers of your skin, like it was doing something clever enough to see past a mere photograph. Maybe it does read deeper layers under some conditions. Doesn't matter much if a decent 2400dpi scan of a print lifted off a wine glass gets you in anyway.
None of this means Touch ID is pointless, and I'd push back a little on people acting like Apple just shipped something worthless. For the overwhelming majority of people the actual threat model is "my little brother trying to read my texts" or "the phone falls out of my pocket at the bar," not "a state-funded team with a laser printer and eight hours to spend on my thumbprint." Judged against a four-digit PIN that half of iPhone owners never bothered setting in the first place, Touch ID is still a net improvement, because it's the thing that finally gets lazy people to lock their phone at all. Convenience beats a hypothetically stronger security measure nobody actually uses.
Where it gets genuinely uncomfortable is the parts of the pitch that leaned on Touch ID as something sturdier than a password specifically because you can't lose your finger or forget it. That framing invites people to treat it as sufficient for things it really isn't sufficient for. A password you can change after it leaks. Good luck rotating your thumbprint. And it's not like this was some theoretical concern dreamed up by security researchers with nothing better to do this week, it's the actual sensor on the actual phone that started shipping three days ago.
I haven't decided if I'm getting a 5s yet. Probably will eventually, mostly for the camera and because my old 4S is getting embarrassingly slow opening Twitter of all things. But I'll be setting a real passcode on top of Touch ID rather than leaning on it alone, and I'd tell anyone reading this to do the same, at least until this settles down some. Might be being overly cautious. Wouldn't be the first time.
One more small thing, unrelated but it's been bugging me all weekend: the 5c starts at $99 on contract and the internet spent about four months acting like it was going to be some kind of budget miracle phone, and now that it's actually out people are annoyed it's not cheaper unlocked. $549 for the 16GB unlocked model isn't nothing. I don't know what everyone expected. Plastic doesn't make silicon free.
Anyway. Fingerprints as passwords. Fun idea, rough opening week.