Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I would hope that they simply save a hash of the fingerprint with a reasonable level of collision built in to make it difficult to tie a hash to a single person's fingerprint (maybe ~10 people would have that hash?). I would imagine they could then use some sort of secret tied to the device id and hash pair to positively identify to the server.

edit for clarity



So there are two things going on here.

1)They said the detection gets better every time you use it. So my guess would be that multiple versions of the raw fingerprint data are stored inside the A7 chip. (That information never leaves the chip.)

2) You can use your fingerprint to authenticate apps like iTunes, as well as third party apps. For this, yes I am sure they will use some hash that cannot rebuild the fingerprint.


For 2, the apps have no reason to see a fingerprint hash, only an authenticated identity.


How does it work now when you have to type in your iTunes password to authorize an in-app purchase?

I thought the password got hashed and sent out to Apple's servers to authenticate?

If so, wouldn't a new fingerprint based password have to do the same thing?


I think they would implement a password manager, and instead of a master password ,they'll use fingerprints/fingerprints-hash


That's not how fingerprint scanners normally work I'm afraid...




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: