iPhone's TouchID fingerprint reader hacked by German group in just days

iPhone's TouchID fingerprint reader hacked by German group in just days

Hackers get touchy.

With the weekend only just winding up across the globe, the iPhone 5S with Apple's new Touch ID fingerprint reader has been available for only a couple of days since its release last Friday.

Which is apparently all the time that was needed for German group Chaos Computer Club (CCC) to hack the new iPhone's fingerprint reader.

"A fingerprint of the phone user, photographed from a glass surface, was enough to create a fake finger that could unlock an iPhone 5s secured with Touch ID," the group wrote in a blog post on September 21 at 10pm.

The post then suggests that the hack, discovered by CCC member Starbug, can be done using household materials.

The method

Described in just a paragraph on CCC's blog, the first step is photographing the enrolled users fingerprint in 2,400 dpi resolution.

The image then needs to inverted and laser printed on to a transparent sheet in 1,200 dpi resolution and thick toner setting. This is apparently where the difficult part ends.

Latex milk or white wood-glue can be used to create a mould by spreading it onto the transparent sheet and letting it dry. Then you breathe on the mould for moisture and place it on the sensor to unlock the phone.

Here's a video of the latex in action:

Fingerprint caution

Although you'll still need to have a good quality photo of the fingerprint first to be able to use CCC's method, there are those that argue that while passcodes can be kept secret or changed, fingerprints are public and cannot be changed.

"We hope that this finally puts to rest the illusions people have about fingerprint biometrics," said CCC spokesperson Frank Rieger.

"It is plain stupid to use something that you can´t change and that you leave everywhere every day as a security token," he added.

Of course, the counter argument is that passcodes can be hacked as well or someone can simply look over your shoulder, and Apple has spoken about Touch ID security concerns, saying it has everything under control.

Also, a Control Centre bug was revealed last week on the newly released iOS 7, which could leave open the iPhone 5S despite the fingerprint scanner, though Apple is working on a fix.

  • Here's our review of the iPhone 5S, including what we think of the Touch ID.

Source : techradar[dot]com

BlackBerry founder and ex-CEO lining up bid to save the company?

BlackBerry founder and ex-CEO lining up bid to save the company?

Lazaridis reportedly wants back in at BlackBerry

Mike Lazaridis, the BlackBerry co-founder and former chief executive, is reportedly seeking to take control of the rapidly disintegrating mobile company.

Lazaridis and Jim Balsillie stepped down as co-CEOs in the May 2012 after overseeing the firm's dramatic fall from grace as iOS and Android moved to dominate the mobile market.

Now, according to a report in the New York Times this weekend, Lazaridis who still owns 5.7 per cent of the company, has approached private equity firms about a possible buyout.

According to people 'familiar with the matter' the former boss has approached the Blackstone Group and the Carlyle Group over a potential takeover.

Comeback kid?

BlackBerry has been officially up for sale for the last month, with the company admitting it is actively encouraging offers.

Just this Friday the company was plunged further into crisis when it announced it would be retreating from the consumer market and shedding 4,500 jobs.

Could the man who, some would say, perhaps fell asleep at the wheel during the most crucial period in BlackBerry's history, really be the person to save it?

Let us know your thoughts in the comments section below.


Source : techradar[dot]com

BlackBerry pauses BBM for iOS and Android roll out following leak

BlackBerry pauses BBM for iOS and Android roll out following leak

BBM For All... just not yet

BlackBerry has been forced to halt its global roll out of BBM for Android and iOS, after an unofficial version of the Android app was posted online this weekend.

As the Waterloo-based company began rolling out in various territories around the world, an build of the Android app was posted online, prompting a rush among former BlackBerry loyalists to obtain the app.

The unofficial version of the app was downloaded 1.1 million times in just 8 hours, but caused the company issues it spent most of Saturday attempting to resolve.

As a result, the iOS rollout, which began in New Zealand yesterday, has been paused. The official Android release is still MIA, while the unofficial version has been disabled.

Expectations

In a post on the official Inside BlackBerry blog, Luke Reimer wrote: "Prior to launching BBM for Android, an unreleased version of the BBM for Android app was posted online. The interest and enthusiasm we have seen already – more than 1.1 million active users in the first 8 hours without even launching the official Android app – is incredible. Consequently, this unreleased version caused issues, which we have attempted to address throughout the day."

"Our teams continue to work around the clock to bring BBM to Android and iPhone, but only when it's ready and we know it will live up to your expectations of BBM. We are pausing the global roll-out of BBM for Android and iPhone. Customers who have already downloaded BBM for iPhone will be able to continue to use BBM. The unreleased Android app will be disabled, and customers who downloaded it should visit www.BBM.com to register for updates on official BBM for Android availability."

The unfortunate situation is a blow for BlackBerry, whose long-awaited roll-out of BBM to other platforms was set to be a rare sunny moment for the ailing company.

On Friday the company posted grim financials, announced it was moving away from the consumer market and cutting 4,500 jobs - around 40 per cent of its total workforce. The end seems nigh.


Source : techradar[dot]com

Latest iOS 7 bug allows calls to be made from a locked iPhone

Latest iOS 7 bug allows calls to be made from a locked iPhone

Yes, it is an emergency.

An iOS 7 user has discovered a worrying security flaw within the software, which enables calls to be made while the iPhone is locked.

The flaw can be exploited using the emergency call screen that can be accessed from the lock screen. Once the phone's keypad is open, any number can be dialled by repeatedly tapping the call button.

In a video shot by iPhone users Karam Daoud and passed onto Forbes, tapping the call button numberous times causes the screen to go black and the Apple logo to appear.

After that, the call to any number, including international and premium phone numbers is completed as if the phone were unlocked.

Any number, any time

"Once the black screen appeared, it was pretty clear that this is a bug," says Daoud from Ramallah in Palestinian. "You can dial a number anywhere, any time."

He also claims to have repeated the trick on older iPhones running older versions of iOS and enjoyed further success, so it appears the problem is not confined to iOS 7.

The bug is the second security flaw uncovered within iOS 7 since its release in midweek. The first lockscreen vulnerability allowed access to the device's photos and email. However, that required a much more complex combinations of presses and swipes.

Apple says it is working on a fix for the first issue, but is yet to comment on the more recent discovery.


Source : techradar[dot]com

iPhone 5S Touch ID tech is no joke, says comedian-turned-politician

iPhone 5S Touch ID tech is no joke, says comedian-turned-politician

Franken wants assurances over Touch ID sensor

The new Touch ID fingerprint sensor within the iPhone 5S handset has come under fire from a prominent U.S. politician, who has expressed concern the data could be used to 'impersonate a person for life.'

Senator Al Franken, a former comedian who is chairman of the Senate Judiciary Subcommittee on Privacy, Technology and the Law, wants assurances from Apple regarding how the prints will be safeguarded.

In an open letter to Apple CEO Tim Cook, the representative for Minnesota pointed out that passwords can be changed infinitely, but once thieves get hold of our prints, it's the end of the road.

He wrote: "Passwords are secret and dynamic; fingerprints are public and permanent. If you don't tell anyone your password, no one will know what it is. If someone hacks your password, you can change it -- as many times as you want. You can't change your fingerprints. You have only ten of them. And you leave them on everything you touch; they are definitely not a secret. What's more, a password doesn't uniquely identify its owner -- a fingerprint does. Let me put it this way: if hackers get a hold of your thumbprint, they could use it to identify and impersonate you for the rest of your life."

Can it be extracted?

Apple has assured that the fingerprint data will never leave the iPhone 5S and will never be stored on the company's servers or uploaded to iCloud.

Third party developers have also been shut-out from using the tech at this stage.

However, despite conceding that Apple has probably implemented this tech responsibly, Franken wants to know whether its possible to extract the fingerprint data from the device itself.

In one of a number of questions within the letter he asked: "Is it possible to extract and obtain fingerprint data from an iPhone? If so, can this be done remotely, or with physical access to the device?"


Source : techradar[dot]com

It's free
index