FB pixel

Can the iPhone 5S be spoofed with a lifted print? Hackers crowdfund reward to find out

 

Apple’s iPhone 5S goes on sale today, and there’s already an award for the first person to successfully hack the device.

Specifically, a group of hackers have created a twitter-fuelled crowdfunding campaign to rack up rewards for the first person to spoof the TouchID sensor. The winner must enroll a print on the device, lift that some print from somewhere else, reproduce it and then use the reproduction to unlock the iPhone without being locked out.

The campaign is being spread through the hashtag #istouchidhackedyet and istouchidhacketyet.com. So far the rewards have been piling up, totalling more than $15,000. Typically unconventional, rewards offered to the campaign range from dollars, to euros, to bitcoin and even books and bottles of bourbon. IO Capital has added $10,000 to the contest and Apple reportedly has yet to respond.

“To be clear, the main reason Nick and I are doing this is because we think it’s harder than most people think,” Robert David Graham, an organizer of the campaign told ZDNet Thursday.

Though it has yet to be seen if the sensor can really be hacked with a lifted fingerprint, Graham is likely right. Considering the TouchID sensor looks beyond ridge patterns and scans subdermal layers, a gummy bear attack isn’t a feasible approach to spoofing.

Reportedly previously in BiometricUpdate.com, some concerns have already been raised about the new iPhone, including the proprietary nature of the Touch ID system, as well as the high price-tag of the new fingerprint-enabled phone.

As it stands, Apple says third-party apps won’t have access to the fingerprint sensor and that it will only be used to unlock the device and authorize iTunes purchases. That being said, it’s been widely speculated that Apple will wait for another smartphone — almost certainly an Android – to launch a phone with an open and accessible sensor and then make a determination about how to allow access to its sensor, based on the experience from these other device launches.

Though it doesn’t represent a vulnerability for the new sensor, TechCrunch posted a video yesterday of a cat’s paw unlocking the device. Though on the surface – pun definitely intended – this makes the device look easy to hack, all this shows is the sensor’s ability to recognize unique pieces of skin. A different cat’s paw probably wouldn’t unlock the device, but this does show that owners could feasibly authorize their pets as trusted users.

Article Topics

 |   |   |   | 

Latest Biometrics News

 

KYA emerges as essential tool to ensure agentic AI is trustworthy

It’s 2026; do you know who your agents are? This is the question of the moment, as the agentic AI…

 

UNHCR lauds role of Fayda digital ID in facilitating life for Ethiopia refugees

Thanks to the Fayda digital ID, access to services for refugees hosted by Ethiopia has become much easier, a development…

 

A New Year’s resolution for AI – don’t blame the bot

By Professor Fraser Sampson, former UK Biometrics & Surveillance Camera Commissioner According to the old saying, blaming our tools is a…

 

Digital identity’s role in IATA’s ecosystem grows with NDC, Macau’s One ID launch

The International Air Transport Association’s plan to upgrade air travel infrastructure to make the sector more efficient for the hundreds…

 

Inetum installing biometric scanners at 2 Spanish ports for EES rollout

Biometrics and passport scanners are being installed at Cadiz, Spain’s two major ports by Inetum España as part of the…

 

Lawmakers move to rein in ICE’s use of mobile facial recognition

U.S. Rep. Bennie G. Thompson, the top Democrat on the House Committee on Homeland Security, introduced legislation aimed at sharply…

Comments

6 Replies to “Can the iPhone 5S be spoofed with a lifted print? Hackers crowdfund reward to find out”

  1. Chaos Computer Club breaks Apple TouchID
    2013-09-21 22:04:00, frank

    The biometrics hacking team of the Chaos Computer Club (CCC) has successfully bypassed the biometric security of Apple’s TouchID using easy everyday means. A fingerprint of the phone user, photographed from a glass surface, was enough to create a fake finger that could unlock an iPhone 5s secured with TouchID. This demonstrates – again – that fingerprint biometrics is unsuitable as access control method and should be avoided.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events