Berlin-based Security Research Labs has detailed various exploits within the iPhone 5s' Touch ID security feature and iOS 7 that allow would-be criminals to bypass the device's security features, reports Reuters.

The method for bypassing the Touch ID security feature found on the iPhone 5s is very similar to the one used by the Chaos Computer Club, which also claimed to hack Touch ID earlier this month. A video posted on the group’s website shows how Touch ID can be bypassed using information gathered from fingerprints left on the victim’s phone display, demonstrating that a photo taken with the iPhone 4s can be used for developing a mold.


Another video by the group outlines a scenario in which a knowledgeable criminal could steal an iPhone 5s running iOS 7, use Control Center on the lock screen (enabled by default) to turn on Airplane Mode and disable the device’s connectivity, then using a fingerprint mold to bypass the lock screen and disable other various security features. Ultimately, the group shows how an attacker could conceivably gain complete control of a victim's device, Apple ID, and even other services such as Google accounts.

The group ends the video by suggesting Apple do the following to increase security efficiency in iOS 7:

1. Make Airplane Mode inaccessible from the lock screen by default and require PIN after setting Airplane Mode or removing SIM Card
2. Warn users not to store password-reset email accounts on iDevices
3. When device is lost for good, advise users to revoke its privileges
4. Do not inform potential attackers how the device is protected
5. Upon reconnecting to the Internet, iOS should not allow email retrieval before the device’s wipe- or don’t-wipe status can be retrieved


Aside from any future changes Apple may make to increase security, users can already prevent the simple bypass of the Remote Wipe feature by turning off access to Control Center from the lock screen.

iOS 7 has recently been the subject of much praise by security officials, including the New York Police Department, which passed out flyers in New York City recommending users to update to iOS 7, along with government officials who have praised iOS 7’s Activation Lock. Meanwhile, Touch ID has been the subject of much scrutiny since its release, with U.S. Senator Al Franken sending a letter to Tim Cook asking a number of questions about the security of the system and the exact fingerprint storage process. Apple has also published an extensive knowledge base article about the benefits of the Touch ID system to alleviate some consumer concerns.

Top Rated Comments

Technarchy Avatar
140 months ago
So far it looks like Touch ID is a pain in the ass to bypass.
Score: 20 Votes (Like | Disagree)
smiddlehurst Avatar
140 months ago
I hope Apple will listen.

I have seen a lot of "not thought of / invented here" attitude.

Not saying they don't, but it takes a lot of crying on many occasions.

Listen to.... what, exactly?

Pretty much all security can be bypassed if you have physical access to the device and enough time / money / resources / skill. Security on phones is no exception to this, indeed they can be far less secure than say a desktop as if it's stolen with other items those items often provide data to help bypass that security.

Touch ID is simply another form of pass code and all pass codes do is try to discourage the 'casual' theft of phones for resale and prevent a typical thief from accessing your data. Touch ID isn't suddenly going to turn a device into a digital Fort Knox. What it will do is actually far more useful - it removes a pain point and makes using a pass code far easier and more convenient (dare I say, even makes it a little bit fun). That, in turn, will see a far higher percentage of iOS devices having some form of security active and that will make them a less attractive target.

The only time anyone really needs to worry about this is if someone figures out a genuine bypass that removes security and gives full access to the phone that can be done simply and easily. Everything else is just grandstanding for media attention.
Score: 3 Votes (Like | Disagree)
Slim02 Avatar
140 months ago
Well people stop calling the bypass a damn hack.. It is not a hack because there is nothing being hack...
Score: 3 Votes (Like | Disagree)
Iampr Avatar
140 months ago
Why not just set a restriction (Settings | General | Restrictions) on making changes to accounts? Then the find my iPhone can't be turned off without knowing an additional 4 digit code
Score: 3 Votes (Like | Disagree)
caliguy Avatar
140 months ago
I want to see them bypass the sensor with "real world" fingerprints. Take the iPhone sitting on my desk and lift one of those smudges...
Score: 3 Votes (Like | Disagree)
fallenjt Avatar
140 months ago
How the hell can you get that fingerprint on the glass so easily? You coated your finger with some type of grease? I press my thumb hard on the glass and got no fingerprint at all after multiple times. Your method may work in theory, but in reality, you wont be able to get a fringerprint from iPhone screen. Even if you can get that print, it must be the correct fingerprint on file.
Somehow, middle finger can work the best for touch ID because you dont use it to operate the phone ever, but thumb and index fingers.
Score: 2 Votes (Like | Disagree)

Popular Stories

iOS 18 CarPlay Feature

iOS 18 Adds These 5 New Features to CarPlay

Thursday June 13, 2024 7:44 am PDT by
Apple did not mention CarPlay during its WWDC keynote this week, but iOS 18 includes a handful of new features for the in-car software. Overall, there is not a whole lot new for CarPlay on iOS 18, with changes seemingly limited to the Messages and Settings apps so far. Below, we recap everything new for CarPlay on iOS 18. New for CarPlay on iOS 18 1. Contact Photos in Messages App...
ios 18 button bulge

iOS 18 Adds Pop-Out Bezel Animation When Pressing iPhone Buttons

Tuesday June 11, 2024 10:40 am PDT by
iOS 18 includes a small but interesting change for the buttons on the iPhone, adding more of a visual element when changing volume, activating the Action button, or locking the screen. When you press an iPhone button in iOS 18, the display bezel bulges outward slightly. This feature is available for the volume buttons, Action button and the power button, and it will also likely be used for...
iOS 18 Mock iPhone 16 Feature Gray

Revealed: iOS 18 Works With These iPhone Models

Monday June 10, 2024 3:57 am PDT by
iOS 18 will be compatible with the same iPhone models as iOS 17, according to a post on X today from a private account with a proven track record of sharing build numbers for upcoming iOS updates. iOS 18 will be compatible with the iPhone XR, and hence also the iPhone XS and iPhone XS Max models with the same A12 Bionic chip, but older iPhone models will miss out. Here is the full...
maxresdefault

First Look at Messages via Satellite in iOS 18

Thursday June 13, 2024 11:29 am PDT by
Apple has been gradually expanding its suite of satellite connectivity features for iPhone, and iOS 18 brings a significant new one in the form of Messages via satellite. The feature allows users to send and receive iMessages and SMS texts, including emoji and Tapbacks, while out of range of cellular and Wi-Fi networks. CNET met up with Apple's senior director of platform product marketing,...
iOS 18 Siri Integrated Feature

Massive iPhone Upgrade Coming This Week But These Devices Will Miss Out

Sunday June 9, 2024 1:25 pm PDT by
Apple is planning a major AI overhaul in iOS 18, with a feature set it is referring to as "Apple Intelligence." However, these new features will not work on older iPhones, even if they do appear on the new operating system's device compatibility list. Apple's initial AI roadmap for iOS 18 is said to come in two parts: Basic AI features that will be processed on-device, and more advanced...
Generic iOS 18 Feature Real Mock

Your iPhone 15 Can Show the Time When It's Out of Battery in iOS 18

Wednesday June 12, 2024 2:57 pm PDT by
The iPhone has had a Power Reserve function that holds back a small amount of battery life to allow features like Find My and NFC unlocking to work even when your device has died, and in iOS 18, Apple seems to be improving the feature further for the iPhone 15 models. As demonstrated on Reddit, when the battery on an iPhone running iOS 18 is exhausted, the phone can continue to show the time ...