A European hacker group has announced a simple, replicable method for spoofing Apple’s TouchID fingerprint authentication system. “A fingerprint of the phone user, photographed from a glass surface, was enough to create a fake finger that could unlock an iPhone 5s secured with TouchID,” claims the Chaos Computer Club, which demonstrated the hack in a video.
The technique is based on previous methods for spoofing fingerprint authentication systems, and needed only minor adaptation to be applied to the iPhone’s unusually high-resolution scanner. According to the CCC:
First, the fingerprint of the enrolled user is photographed with 2400 dpi resolution. The resulting image is then cleaned up, inverted and laser printed with 1200 dpi onto transparent sheet with a thick toner setting. Finally, pink latex milk or white woodglue is smeared into the pattern created by the toner onto the transparent sheet. After it cures, the thin latex sheet is lifted from the sheet, breathed on to make it a tiny bit moist and then placed onto the sensor to unlock the phone.