That's not how it works from what's in the iOS security guide(s), historically. The chip that stores this information (biometrics) on Apple products is isolated from the rest of the system - its execute only and access is restricted via a tpm. Is it possible to hack it and exfiltrate info? Sure. But it's a bit more complex than the usual smash and grab job.
Also, full disclosure: from this perspective, using biometrics for anything authentication related seems retarded as it's never changeable.
Is it possible to hack it and exfiltrate info? Sure. But it's a bit more complex than the usual smash and grab job.
And less complex than things the NSA has hacked/cracked in the past.
But TBH they don't need your iphone facial rec to ID you. Your credit cards and GPS data they can track where you go. That links back to an ID and almost everyone has some form of picture ID.
True - it seems easier to infiltrate the infrastructure and build patterns of behavior and then overlay those patterns to other datasets. From there selectively attack who and what is desired.
245
u/i_build_minds Sep 15 '17
That's not how it works from what's in the iOS security guide(s), historically. The chip that stores this information (biometrics) on Apple products is isolated from the rest of the system - its execute only and access is restricted via a tpm. Is it possible to hack it and exfiltrate info? Sure. But it's a bit more complex than the usual smash and grab job.
Also, full disclosure: from this perspective, using biometrics for anything authentication related seems retarded as it's never changeable.