I've had my thumb pressed against my phone's home button about four hundred times today just testing whether it still bugs me, and it does. Not because it doesn't work (it works fine on my sister's 5s, I don't actually own one) but because of what happened to it last week and how fast everyone moved on.
Quick recap for the two people who missed it: the Chaos Computer Club, a German hacker collective that's been poking holes in security systems since before I was reading Ars Technica in study hall, announced they'd broken Touch ID within about 48 hours of the iPhone 5s hitting stores. Their method wasn't some exotic lab technique either. Someone lifted a fingerprint off a glass surface, photographed it at high resolution, cleaned up the image, and printed it onto a transparent sheet using a laser printer with thick toner. Then they used that as a mold for a thin layer of latex or wood glue pressed onto a fake finger. Press that against the sensor and apparently it unlocks like nothing happened.
The CCC guy behind it (they credit someone going by Starbug, which is a great hacker name, I'll give him that) basically said the whole point was to remind people that a fingerprint isn't a secret. Your password lives in your head. Your fingerprint is on every glass you drink from, every doorknob you touch, the screen of the phone itself. Apple built a very slick piece of hardware and then based its security model on something you hand out constantly without thinking about it.
Here's my actual opinion on this, and I know it's not a popular one among the just-buy-the-new-thing crowd: Touch ID was never really about security for most people. It's about convenience, and I think Apple knows that, and I think the marketing blurred the line on purpose. They tossed around a "1 in 50,000" false-accept stat during the keynote like that settles it, but a statistical false accept rate has nothing to do with whether someone can deliberately go make a fake finger targeting you specifically. Different threat model entirely. If you're worried about a random stranger picking up your phone, Touch ID is a huge improvement over nothing. If you're worried about someone who actually wants into your specific phone, badly enough to lift a print off your coffee mug, it buys you almost nothing.
And I get why this story didn't stick around in the headlines. It broke during the exact week everyone's inbox was full of iPhone 5s and 5c launch photos, gold-color jokes, lines outside the Apple Store on Fifth Avenue, and reviews of the camera and the M7 chip. A "German hackers used glue" story is a weird, slightly gross footnote next to all that, so it got its 48 hours of attention and then the news cycle moved back to plastic colors and slow-motion video. Which, fine, that's how it goes, but it bugs me that the security angle basically evaporated within a week when it's genuinely the more interesting story of the two.
Small tangent because I can't help myself: this was also the week BlackBerry agreed to a tentative buyout, something like 4.7 billion dollars from Fairfax Financial, while Apple was selling nine million 5s and 5c units over a single weekend. I don't think there's a cleaner snapshot of where that company ended up than those two headlines running side by side on the same Monday.
None of this means I think Touch ID is a bad feature. I'd use it. Typing a passcode fifty times a day is genuinely annoying and most people who lose their phone lose it to theft or to a nosy roommate, not to a state-level adversary with a laser printer and a mold kit. But I wish the keynote framing had been "this is way more convenient" instead of leaning so hard into the security angle, because now every tech writer gets to do the gotcha-it's-hackable post, including me apparently, and the actual nuance, convenience versus security, they're not the same thing, gets lost in the back and forth.
Anyway. My thumb still works fine on doorknobs, no glue required.