What are the privacy implications of the iPhone 5s fingerprint sensor? U.S. Senator Al Franken wants Apple CEO Tim Cook to answer that question and more. In a published letter to Cook, Franken writes that âimportant questions remain about how this technology works.â In addition, the senator wants the Apple chief to explain how the Touch ID sensor may be used in the future.
In response, Apple published online a document explaining that fingerprints obtained by the new iPhone 5s are walled-off from the iOS software and application developersâ¦
While recognizing Apple âhas worked hard to secure this technology and implement it responsibly,â Franken writes that the fingerprint technology developed by the iPhone maker âwill surely pave the way for its peers and smaller competitors to adopt biometric technology, with varying protections of privacy.â [1]
Among Frankenâs concerns is will Apple protect the fingerprint data from government inquiries. Unlike the âcontentsâ of email and other communications which require a warrant, âsubscriber number or identityâ can be obtained with just a subpoena.
âDoes Apple consider fingerprint data to be the âcontentsâ of communications, customer or subscriber records, or a âsubscriber number or identityâ as defined in the Stored Communications Act?â he asks.
The question gets at the heart of whether Apple sees the fingerprints stored as belonging to the iPhone owner or a record which the company maintains.
Although Appleâs support document isnât an official response to Frankenâs questions, it does provide some insight into the hardware protections afforded fingerprints.
âTouch ID does not store any images of your fingerprint. It stores only a mathematical representation of your fingerprint and compares this to your enrolled fingerprint data to identify a match and unlock your iPhone,â reads Appleâs support document [2] .
It isnât possible for your actual fingerprint image to be reverse-engineered from this mathematical representation.
The iPhone 5s includes something called Secure Enclave within the A7 chip.
The encrypted fingerprint data is only available to Secure Enclave, according to the company. That data is then used to verify fingerprints against that stored.
Fingerprint data is encrypted and protected with a key available only to the Secure Enclave. Fingerprint data is used only by the Secure Enclave to verify that your fingerprint matches the enrolled fingerprint data.
The Secure Enclave is walled off from the rest of A7 and iOS.
âYour fingerprint data is never accessed by iOS or other apps, never stored on Apple servers, and never backed up to iCloud or anywhere else,â according to Apple.
âOnly Touch ID uses it and it canât be used to match against other fingerprint databases,â noted the firm.
This isnât the first time Apple has had to answer security questions.
Most recently, the company denied its involvement in releasing user data to the NSA. As for Franken, back in 2011 CEO Steve Jobs came in for questions regarding the ability of the iPhone to track users.
Links
- ^ Franken writes (www.franken.senate.gov)
- ^ support document (support.apple.com)
No comments:
Post a Comment