Categories: HackingMobileSecurity

The iPhone 6 Touch ID fingerprint reader is still vulnerable to hack

Security expert Marc Rogers, chief security researcher at Lookout Mobile Security, revealed that Apple’s Touch ID is still vulnerable to hack on iphone 6.

A few days ago we discussed about the availability on the Internet of the exploit for iOS 7.x based devices, due to the diffusion of Apple Smartphones and tablets the security issued attracted the attention of the media as already occurred in the past for other flaws. One of the most debated security issue is related to the Touch ID fingerprint reader that appeared flawed for the iPhone 5S. My readers remember that exactly one year ago the Chaos Computer Club claimed to have bypassed the biometric security technology designed by Apple simply by making a copy of a fingerprint photographed on a glass surface.

Now Apple has released the new iPhone 6, a jewel rich of improvements, especially under the security perspective, but experts have discovered that Apple Touch ID still vulnerable to hack.

Marc Rogers, chief security researcher at Lookout Mobile Security, discovered that the Touch ID fingerprint reader on the new iPhone 6 can be fooled by the same trick that was working with iPhone 5S.

“I don’t think people need to worry just yet, but there are distinct flaws that could lead to problems down the line,” “Sadly there has been little in the way of measurable improvement in the sensor between these two devices,” Rogers wrote in a blog post. “Fake fingerprints created using my previous technique were able to readily fool both devices.”

In time I’m writing Apple still hasn’t responded to a request for comment to the researcher. Technically Rogers used fingers coated in a gummy substance like Elmer’s glue to lift and replicate fingerprints.

“I used a technique demonstrated by Tsutomu Matsumoto in his 2002 paper “The Impact of Artificial “Gummy” Fingers on Fingerprint Systems”. In this technique, you take the cleaned print image and without inverting it, print it to transparency film. Next, you take the transparency film and use it to expose some thick copper clad photosensitive PCB board that’s commonly used in amateur electrical projects. After developing the image on the PCB using special chemicals, you put the PCB through a process called “etching” which washes away all of the exposed copper leaving behind a fingerprint mold. Smear glue over this and when it dries, you have a fake fingerprint.” explained in a previous post describing the hack on iPhone 5s.

The impact of the flaw could be serious considering that Touch ID is the authentication system adopted by Apple for Apple Pay, a system implemented starting from the latest iPhone 6 and based on new near-field communication chip and credit card management software with Touch ID to allow people carry out mobile payments by tapping their device with an NFC reader and confirming the purchase with their fingerprint. Touch ID is a key component for the overall payment architecture, it was used with the purpose to make attractive to consumers the new payment method

Rogers explained that the sensor has been improved since its previous version but that anyway if fails the fingerprint validation.

“Another sign that the sensor may have improved is the fact that slightly “dodgy” fake fingerprints that fooled the iPhone 5S did not fool the iPhone 6. To fool the iPhone 6 you need to make sure your fingerprint clone is clear, correctly proportioned, correctly positioned, and thick enough to prevent your real fingerprint coming through to confuse it.” said Rogers.

Rogers hasn’t demonized the Touch ID, he considers it an effective security control that is anyway that is underused with unique usage for unlock of the phone.

Anyway Rogers remarks that since the system involves credit cards it would be better protected by Touch ID and a second authentication factor.

Let’s wait for Apple reply.

Pierluigi Paganini

(Security Affairs – iOS6, Touch ID)

 

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Fintech firm Figure disclosed data breach after employee phishing attack

Fintech firm Figure confirmed a data breach after hackers used social engineering to trick an…

1 hour ago

U.S. CISA adds a flaw in BeyondTrust RS and PRA to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in BeyondTrust RS and…

2 hours ago

Suspected Russian hackers deploy CANFAIL malware against Ukraine

A new alleged Russia-linked APT group targeted Ukrainian defense, government, and energy groups, with CANFAIL…

7 hours ago

New threat actor UAT-9921 deploys VoidLink against enterprise sectors

A new threat actor, UAT-9921, uses the modular VoidLink framework to target technology and financial…

20 hours ago

Attackers exploit BeyondTrust CVE-2026-1731 within hours of PoC release

Attackers quickly targeted BeyondTrust flaw CVE-2026-1731 after a PoC was released, enabling unauthenticated remote code…

1 day ago

Google: state-backed hackers exploit Gemini AI for cyber recon and attacks

Google says nation-state actors used Gemini AI for reconnaissance and attack support in cyber operations.…

1 day ago

This website uses cookies.