Skip to main content

Don’t be afraid of the big, bad Apple ‘Touch ID’ hack

iphone fingerprint unlocking texas 5s touchid
Image used with permission by copyright holder

Apple’s Touch ID fingerprint sensor, used to unlock the new iPhone 5S, can be tricked using a “fake finger,” according to a hacker group that claims to have broken the biometric security feature. If true, the hack undermines Apple’s assertions that Touch ID provides stronger security for iPhone users than the iPhone’s 4-digit pin lock – but don’t fret: Touch ID is still a valuable feature.

Before we get into why this isn’t that big of a deal, here’s how the anti-biometrics hacker group, Chaos Computer Club (CCC), successfully bypassed Touch ID, in their own words:

Recommended Videos

First, the fingerprint of the enroled (sic) user is photographed with 2400 dpi resolution. The resulting image is then cleaned up, inverted and laser printed with 1200 dpi onto transparent sheet with a thick toner setting. Finally, pink latex milk or white woodglue is smeared into the pattern created by the toner onto the transparent sheet. After it cures, the thin latex sheet is lifted from the sheet, breathed on to make it a tiny bit moist and then placed onto the sensor to unlock the phone. This process has been used with minor refinements and variations against the vast majority of fingerprint sensors on the market.

As you can see, the hack requires that whoever wants access to the device has the ability to take a high-resolution scan of the phone owner’s fingerprint, then print that out using a high-res scanner – not exactly an easy feat, or one that is easily repeatable in everyday life (as opposed to CCC’s intentional test of the security system, in which all parties were presumably complicit). Still, according to CCC spokesman Frank Rieger, the fact that this hack is possible should dispel “the illusions people have about fingerprint biometrics.”

“The public should no longer be fooled by the biometrics industry with false security claims. Biometrics is fundamentally a technology designed for oppression and control, not for securing everyday device access,” he added.

While it is disappointing that someone was able to trick Touch ID using simple methods, there are a number of reasons to take this hack with a grain of salt.

First, the easy-to-use nature of Touch ID is sure to increase the number of iPhone owners who lock their devices. Before the release of the iPhone 5S, a mere 50 percent of users locked their devices at all. Now that Touch ID is an option, that number will almost certainly increase.

Second, the CCC hack, though doable, is still a giant pain in the ass. Most thieves, I’d guess, do not have the knowledge, skill, tools, patience, or wherewithal to recreate the CCC hack. So if you’re device gets stolen, Touch ID will still do its job just fine.

Third, Touch ID still provides ample protection from the people we most want to keep out: Snooping family member, roommates, co-workers, and other people close to us. On that front, it keeps people out better than the 4-digit pin without the minor hassle of entering the pin every time the device is used.

Finally, as it’s currently configured, it is still possible to access a locked iPhone 5S using only the 4-digit pin – just swipe the screen, and the 4-digit pin unlock option appears, no fingerprint needed. Apple can, presumably, add an option to iOS 7 that allows a user to require both the fingerprint scan and the 4-digit pin to unlock the device. Do that, and the CCC hack will no longer work. I’d guess Apple will release this option once more people have become comfortable with Touch ID.

There are other reasons to be concerned about Touch ID. Minnesota Democrat Sen. Al Franken recently detailed some of them in a letter about the feature to Apple CEO Tim Cook. But the CCC hack just isn’t something to lose sleep over.

Andrew Couts
Former Digital Trends Contributor
Features Editor for Digital Trends, Andrew Couts covers a wide swath of consumer technology topics, with particular focus on…
Don’t buy a Galaxy S24 Ultra or iPhone 15 Pro Max. Do this instead
Samsung Galaxy S23 FE Mint Green color along with a Samsung notebook and a cermaic bowl with lemons.

“Do I need all that?” That’s the question on the mind of shoppers before they splurge a now-standard $1,000 asking price for a top-tier phone in 2024. Ideally, that dilemma should be there. The likes of Samsung Galaxy S24 Ultra and Apple’s iPhone 15 Pro Max have won laurels for a handful of standout features they offer. But you might not need those standout features at all.

I’ve been on that road, and more frequently than I have the temerity to admit. For some reason, regret comes as part of the $1,200 flagship parcel. That's unless your phone is a part of your creative or work process, or you just don’t care and only want the latest and greatest for the vanity of it. A segment like that certainly exists, but that affluent user base doesn’t dictate the journey of a product.

Read more
Samsung Galaxy S24 vs. iPhone 15: don’t buy the wrong one
Renders of the Galaxy S24 and iPhone 15 next to each other.

The Samsung Galaxy S24 is the newest flagship phone on the market, joining its stablemates, the Galaxy S24 Plus and Galaxy S24 Ultra in Samsung's latest range. While not obvious from the outside, the Galaxy S24 has had some hefty upgrades — including a new, more powerful processor, an improved and larger display, and Samsung's all-new Galaxy AI. With prices starting at $800, the Samsung Galaxy S24 is a strong choice if you're looking for a great flagship smartphone that doesn't cost four figures.

But it's not alone in this space. Apple's iPhone 15 also starts from $800 and has a strong processor, a great camera, battery life, and the polished iOS 17. Both devices have a lot to love, and you may be unsure which of these two suits you better.  That's why we've compared the Samsung Galaxy S24 and Apple iPhone 15, pitting the two head to head, explaining the differences, and letting you know which is better.
Samsung Galaxy S24 vs. iPhone 15: specs

Read more
How to remove someone else’s Apple ID from your iPhone
iPhone 11 Pro Settings

While it's always a good idea to wipe your iPhone before selling it or passing it on to someone else, it's not uncommon for some folks to forget this important step, especially if they're just handing an old iPhone down to a friend or family member. Hence, if you've acquired a used iPhone from somewhere, you may find that it's still signed into the Apple ID of the previous owner, which can be a pretty frustrating situation as it makes it difficult for you to make your new iPhone truly your own.

Depending on whose Apple ID you're using, this may be more than just an inconvenience. Using an iPhone that's fully signed in to someone else's Apple ID means that you'll be syncing data like your photos and messages with their iCloud account instead of yours, and it's likely they can even track its location via Apple's Find My iPhone. Even if they're a close friend or immediate family member, you may not want them to have that level of access to your personal life.

Read more