Touch ID Lasted About Two Days

Touch ID Lasted About Two Days

Tech News apple biometrics iphone 5s security touch-id

So the iPhone 5s has been out for four days now, and I'm sure half the tech blogs on the internet have already done their "here's Touch ID, here's how it feels to unlock your phone with your thumb" post. I'm not going to do that one. Instead I want to talk about how fast the whole thing fell apart.

Touch ID went on sale Friday. By Saturday, the Chaos Computer Club, the German hacker collective that's been poking holes in this kind of thing since before I owned a computer, had already published a method for beating it. Not "in theory, given a lab and six months," but an actual working bypass, with video, less than 48 hours after people started lining up outside Apple Stores.

The trick isn't even that exotic once you read how it works. Their biometrics guy (goes by Starbug, apparently he's been doing this for years) photographed a fingerprint left on a glass surface, cleaned up the image, printed it onto a transparency using a laser printer at high toner density, then coated it with a thin layer of latex or wood glue to build up a fake ridge pattern you can actually press onto the sensor. Basically the same "gummy finger" approach security researchers have been demonstrating against fingerprint scanners since the early 2000s. It's not new science. It's just the first time it's been aimed at something 9 million people were about to carry around in their pocket.

What gets me isn't that Touch ID is beatable. Every biometric system is beatable if someone wants in badly enough and has your fingerprint sitting around somewhere. What gets me is that your fingerprint is, by definition, sitting around somewhere. It's on your phone screen right now. It's on the glass of coffee cup you left on your desk. Unlike a password, you can't rotate it after a breach. If someone lifts a decent print off your doorknob, that particular piece of your identity is compromised for the rest of your life, not just until your next "change your password" email.

I don't think this kills Touch ID as a feature, to be clear. For the thing it's actually good at, replacing a four-digit PIN so you'll bother locking your phone at all instead of leaving it wide open because typing 1-2-3-4 forty times a day is annoying, it's a real improvement for most people. My mom is never going to have a nation-state hacker lifting her prints off a wine glass to get into her Words With Friends. The threat model for 99% of iPhone 5s owners is "kid grabs the phone" or "phone gets lost on a train," and Touch ID solves that fine.

But Apple's marketing during the keynote leaned pretty hard into the "your fingerprint is basically the ultimate secure key" framing, and that's the part that annoyed me watching it back this week. It's convenient. It's neat. It is not, on its own, a security upgrade over a good passcode, and now there's a video out there proving it in under two days. I'd bet real money Apple's response, whenever it comes, is going to be some version of "Touch ID is about convenience, not a replacement for strong security practices", which, fine, sure, but that's not the pitch they gave on stage.

Small tangent because I can't help myself: I still haven't updated my own phone to iOS 7 yet, and reading the CCC writeup made me feel weirdly vindicated about dragging my feet. Half my Twitter feed has been complaining about motion sickness from the new parallax wallpaper effect, the other half is annoyed the icons look like something out of a kids' education app. I'll get around to it eventually. Probably this weekend, once GTA V stops eating every spare hour I have, that game crossed a billion dollars in sales in three days, which is an absurd number to type out, and yes I contributed my $60 to it like everyone else.

Anyway. Watch what gets photographed the next time you hand your phone to someone at a bar to show off a picture. Sounds paranoid, I know. Two days ago it also sounded like security theater to worry about it, and now there's a YouTube video.