"We protect fingerprint data using a secure enclave, which is uniquely paired to the touch ID sensor. When iPhone is serviced by an authorised Apple service provider or Apple retail store for changes that affect the touch ID sensor, the pairing is re-validated. This check ensures the device and the iOS features related to touch ID remain secure. Without this unique pairing, a malicious touch ID sensor could be substituted, thereby gaining access to the secure enclave. When iOS detects that the pairing fails, touch ID, including Apple Pay, is disabled so the device remains secure.”
Although it hurts that we cannot go to next door repairwala to fix my home button or screen, I for one think that this is a welcome move. This at least shows that Apple is serious about fingerprint security. Those Chinese companies who manufacture replicas of TouchID cannot be trusted.
But then Apple must launch Apple stores in India fast!! The Authorized service centres loot us currently as the service cost includes Apple's margins + authorized centre's margins. This might also discourage manufacturing of fakes.
Some digging revealed that this error is caused because third party replace touch ID along with broken screen. Replacement iPhone 5s/6/6s screens from China come with TouchID sensor attached.When the screen is broken, expert shops should remove touch ID from replacement screen (discard that Touch ID sensor) and and fit only the screen along with existing touch ID of the phone.
I fail to understand how compromised touch ID do anything?
Unless there is an APP which records ur fingerprint and sends over internet.
But then touch ID is controlled only by iOS - no 3rd party can yet "read" fingerprints. Hence no 3rd party app can send any fingerprint data over internet.
Correct me if Im wrong but doesn't Apple already ask for PIN when it boots up?
First rule of hacking assumes that hacker doesn't have physical access to the device. Second, apple can just ask for PIN as authenticator when It detects new physical hardware changes. Or Thirdly, it can just lock the device instead of totally wiping out the device and then ask customers to call apple support.
Apple just wants to control the repair market just like it does with apple certified cable! This is just plain gouging of the customers.
They're making it sound like they're helping the customer. Both the data is already encrypted by iOS and android 5.0 so they can just ask for PIN or just icloud lock it and ask the customer to verify themselves with apple support.
Friend had 5S who got touchID for fraction of cost and now he's afraid to connect to the internet incase apple fucks him over
This website uses affiliate links. This means that if you click on a link and make a purchase, we may receive a commission. This does not affect the price you pay for the product.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.