Sen. Franken seeks data on privacy controls in iPhone 5S fingerprint tech
Lawmaker seeks answers to a list of 'substantial privacy questions' sent to Apple CEO Cook
Computerworld - A U.S. lawmaker wants to know whether the Touch ID fingerprint reader in Apple's iPhone 5S has adequate controls to protect the personal data of users.
In a letter to Apple CEO Tim Cook, Sen. Al Franken (D-Minn.) sought answers to a set of detailed questions on whether the technology includes controls for securing fingerprint data and whether the company has any undisclosed plans to share the data.
While Touch ID could improve certain aspects of mobile security, it also raises "substantial privacy questions" said Franken, chairman of the Senate Judiciary Subcommittee on Privacy, Technology and the Law.
In the letter, Franken told Cook that he is "seeking to establish a public record of how Apple has addressed these issues internally and in its rollout of this technology."
Apple didn't respond to Computerworld's request for comment on Franken's concerns.
Apple's Touch ID is a fingerprint-based authentication system for the iPhone 5S, that allows up to five users register fingerprints on a single device. Apple says the technology is designed to make the iPhone a less attractive target for thieves.
Industry analysts have so far generally hailed the technology as a step forward in mobile security. Some analysts predict that it won't be long before the Touch ID feature is included on all Apple products.
In the letter, Franken acknowledged that Apple has taken measures like ensuring that fingerprint data is encrypted and only stored locally, and to block third-party access to Touch ID. "Yet important questions remain about how this technology works, Apple's future plans for this technology, and the legal protections that Apple will afford it," Franken said.
Unlike passwords that can be changed at will, fingerprints are permanent, Franken wrote. "You can't change your fingerprints. You have only 10 of them. And you leave them on everything you touch; they are definitely not a secret. If hackers get a hold of your thumbprint, they could use it to identify and impersonate you for the rest of your life."
Franken asked Cook to explain how Apple will convert locally stored fingerprints into a digital or visual format that could be extracted and later used by Apple or third parties. "Is it possible to extract and obtain fingerprint data from an iPhone? If so, can this be done remotely, or with physical access to the device?" he said.
He also asked whether the iPhone 5S is designed to transmit diagnostic information about the Touch ID back to Apple or other third parties, and whether fingerprint data would be backed up on a user's computer.
He also sought information on how Touch ID interacts with iTunes, iBooks and Apple's App Store. "Can Apple assure its users that it will never share their fingerprint data, along with tools or other information necessary to extract or manipulate the iPhone fingerprint data, with any commercial third party?" Franked asked.
John Zurawski, vice president at Authentify, a vendor of voice-based authentication tools, said questions like thosed posed by Franken should be asked of any vendor of biometric devices.
Biometrics does offer a secure layer of authentication, he noted. "The ability to reverse engineer a fingerprint from its encrypted digital form would be very labor intensive," and probably not worth the effort for cybercriminals he said.
"The average consumer's credit and identity information may not be worth the computational effort required to reverse engineer," he said.
"I think many of Senator Franken's questions hit important areas," added Joe Schumacher a security consultant with Neohapsis, a vendor of mobile and cloud security services. "It is important for the consumer to understand how Touch ID communicates with Apple regarding use of the service, diagnostic information and interaction with other Apple applications."
The fact that fingerprint data is stored locally on the iPhone is a good thing from a security and privacy perspective, Schumacher noted.
However, Apple must clarify how the sharing of fingerprint data will proceed when Apple rolls out the technology to other devices. "Biometric fingerprint technology is a great form of identification but not the best form for authentication, at least not by itself," he said.
Jaikumar Vijayan covers data security and privacy issues, financial services security and e-voting for Computerworld. Follow Jaikumar on Twitter at @jaivijayan, or subscribe to Jaikumar's RSS feed . His email address is firstname.lastname@example.org.
- Carmakers put Apple's CarPlay in the slow lane
- What matters in the fall smartphone lineup: brand, display size, battery life, LTE
- Why HTC put Windows on its M8 smartphone
- iPhone 5C's China bust raises questions about Apple's pricing for '14 models
- China scrubs Apple's iPad and MacBooks from government buying list
- Navdy's planned heads-up car display works with iPhone or Android
- Circle the date: Apple's iPhone 6 event slated for Sept. 9
- Stable Mac prices fuel reliable profit engine
- Apple will 'set the world on fire' with iPhone 6 sales
- The other Apple economy: $2B in devices on eBay
Read more about Mobile/Wireless in Computerworld's Mobile/Wireless Topic Center.
- Leverage the Power of APIs to Turbocharge Your Mobile Strategy: 7 Steps to a Successful API Program In this guide, Intel® Services-which offers industry-leading API management solutions for over 150 top enterprises, including Best Buy, Netflix, Expedia, ESPN, and The...
- Mission Critical Cloud Powers Freesat Website, Mobile App When subscription-free satellite TV service Freesat needed a scalable, cost-effective infrastructure it found the disaster recovery and security features it needed with Peer...
- Bring Your Own Device: From Security to Success Download this e-Book to learn best practices for executing a BYOD policy.
- Securing Mobile App Data - Comparing Containers and App Wrappers Analysts agree that Mobile Device Management (MDM) is not enough when it comes to securing app data. Although it remains a critical component...
- API Management: The Key to Improving the Consumer Travel Experience Join PhoCusWright's Senior Technology Analyst, Norm Rose, as he shares his insights on how travel suppliers and intermediaries can improve industry data flow...
- Don't Believe the Hype: Not All Containers are Created Equal Hear executives discuss the 3 C's of Secure Mobility-content, credentials, and configurations-and learn the inherent security risks to your organization of using MDM... All Mobile/Wireless White Papers | Webcasts