FB pixel

Chaos Computer Club claims Touch ID fake fingerprint spoof

 

Well that was fast.

German hacker collective, Chaos Computer Club, has claimed that it has already spoofed the iPhone 5S’s Touch ID fingerprint sensor with a fake fingerprint, and it doesn’t seem to have taken much MacGyvering.

Specifically, a hacker by the name of Starbug from the group’s biometrics hacking team claimed responsibility for the attack, which is outlined in a couple of YouTube videos posted over the weekend. (video 1, video 2)

According to the group, the jack is performed with everyday items. “First, the fingerprint of the enroled user is photographed with 2400 dpi resolution. The resulting image is then cleaned up, inverted and laser printed with 1200 dpi onto transparent sheet with a thick toner setting. Finally, pink latex milk or white woodglue is smeared into the pattern created by the toner onto the transparent sheet. After it cures, the thin latex sheet is lifted from the sheet, breathed on to make it a tiny bit moist and then placed onto the sensor to unlock the phone. This process has been used with minor refinements and variations against the vast majority of fingerprint sensors on the market.”

Though the video seems pretty straightforward, the hack has yet to be officially confirmed.

“CCC is Europe’s largest hacker organization and it has a reputation to uphold,” David Meyers said in a Gigaom post this morning. “I sincerely doubt anyone’s pranking the world on this one.”

Apple has yet to issue a response, and if it does, this post will be updated to reflect it.

“In reality, Apple’s sensor has just a higher resolution compared to the sensors so far. So we only needed to ramp up the resolution of our fake,” Starbug says in a report on the collective’s website. “As we have said now for more than years, fingerprints should not be used to secure anything. You leave them everywhere, and it is far too easy to make fake fingers out of lifted prints.”

Reported previously, Apple’s new smartphone was released for sale in North America on Friday and a separate group of hackers began a crowdfunding campaign to raise a reward for the first person to confirm a Touch ID spoof attack from a lifted print.

The istouchidhackedyet campaign website acknowledges the attack but says that it is waiting for a video showing the print being lifted and then used to perform the device unlock before it declares the German collective the winner. More than $15,000 as well as bitcoins and other rewards have been promised to the successful hacker.

Article Topics

 |   |   |   |   | 

Latest Biometrics News

 

Sphinx raises $7.1m to expand AI-powered compliance agents

Identity checks were once reliant on human eyes and human discernment, but making sure people and entities are who they…

 

Identity fraud revs up in the automotive sector as purchases move online

Like most industries, the automotive sector is dealing with a spike in fraud. A survey snapshot released by identity provider…

 

DHS RIVR results suggest most ID document validation disastrously ineffective

The results of the identity document validation track within the 2025 Remote Identity Validation Rally are sobering. They indicate that…

 

DHS signals major expansion of biometric matching infrastructure

The Department of Homeland Security (DHS) has issued a Request for Information (RFI) seeking industry input on biometric matching software…

 

ROC impresses in NIST biometric age estimation benchmark, Shufti makes debut

Two new entrants to NIST’s Face Analysis Technology Evaluation (FATE) Age Estimation & Verification, one a debut and the other…

 

Online dating at risk as romance scams, deepfakes infiltrate platforms

Online dating sites are being flooded with deepfakes and AI content, making it hard for users to distinguish real matches…

Comments

5 Replies to “Chaos Computer Club claims Touch ID fake fingerprint spoof”

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events