iPhone 5S fingerprint spoof could lead to ID theft, German researchers says
A German security company says spoofing the iPhone 5S's fingerprint reader can be used to beat the phone's “remote wipe” facility to carry out identity theft. — SRL demonstrates the hack on its website.
Context & Ripple Effects
Apple’s biometric-security work had been anticipated years earlier, and a September report had already described bypassing Touch ID as straightforward. This report extends the concern from handset access to the protections intended to protect data after a device is lost or stolen.
The finding also lands alongside questions about compelled fingerprint use, underscoring that a fingerprint is both an authentication method and an enduring personal identifier rather than a credential a user can simply replace.
First-order effects
- SRL’s demonstration means iPhone 5S owners cannot treat the fingerprint reader alone as a reliable safeguard for remote-wipe protections when a spoofed print can be used to defeat them.
- Apple faces pressure to address a Touch ID weakness whose reported consequence reaches beyond unlocking a handset to potential identity theft.
Second-order effects
- Enterprise IT teams using iPhones must reassess whether remote-wipe policies provide adequate protection for lost devices, particularly where access depends on biometric authentication.
- The episode raises the security bar for handset makers adopting fingerprint readers: they must defend not only the sensor, but the recovery and remote-management workflows attached to it.
Third-order effects
- Device security is moving toward treating biometric data as a non-revocable identifier with distinct failure modes from passwords, requiring layered safeguards around high-value actions.
- If biometric unlocking becomes a primary access method, trust will depend less on convenience and more on whether vendors can contain the damage from a copied physical credential.
The trend: Mobile authentication is shifting from password-based access toward biometrics, making the security of the surrounding account-recovery and device-management systems more consequential.