Apple Wallet limits users to one Touch ID finger profile when authenticating state IDs

Posted:
in iOS edited November 2022
Apple on Wednesday offered a detailed rundown of Apple Wallet's upcoming support for state IDs and driver's licenses, noting rigid biometric safeguards will be used to secure user information and protect against fraud.

Apple Wallet ID


Earlier today, Apple revealed the first states to support a planned rollout of Apple Wallet for state IDs and driver's licenses.

As part of the announcement, the company outlined how the system will work, saying the process of adding ID credentials is similar to provisioning credit cards and transit passes. Users simply tap on the "+" button in Wallet on iPhone and follow prompts to scan a physical state ID or driver's license. A selfie will be taken and securely transmitted to the issuing state for verification. An additional security step entails performing unique face and head movements.

A copy of the card can also be sent to Apple Watch.

When adding an ID to Wallet on an iOS device with Touch ID, only one finger can be used during the registration process, Apple told Daring Fireball's John Gruber. This ensures only registered users, and not others who might have their fingerprint provisioned for general device access, are presenting a given ID.

The process of presenting an ID is also similar to existing Wallet functions, albeit with a number of additional protections. When users tap iPhone or Apple Watch to a TSA identity reader or other compatible device, a prompt displays the specific information being requested. Authorizing the request via Face ID or Touch ID releases the data from, a procedure that Apple notes does not require users to unlock, show or hand over their device.

As usual, Apple's solution is built on a foundation of data security and takes advantage of hardware and software advancements. For example, IDs are only presented digitally through encrypted communication directly between the device and the identity reader, Apple says. Further, neither Apple nor issuing states know when or where an ID is presented.

Finally Apple's system supports the ISO 18013-5 mDL (mobile driver's license) standard, which the company had a hand in developing.

Wallet support for IDs will see an initial rollout in Arizona and Georgia, to be followed by Connecticut, Iowa, Kentucky, Maryland, Oklahoma and Utah. The TSA will also accept digital IDs from Wallet at select airport security checkpoints. The feature is expected for release with iOS 15.

Read on AppleInsider

Comments

  • Reply 1 of 5
    "Authorizing the request via Face ID or Touch ID releases the data from, a procedure that Apple notes does not require users to unlock, show or hand over their device."  

    Uh, I think the author had a stroke while writing this sentence.  Can you please review and edit?  It seems like a word is missing after "from."
    edited September 2021 peterhartwatto_cobra
  • Reply 2 of 5
    rcfarcfa Posts: 1,124member
    I understand why there’s just a single fingerprint, but who says it’s actually the correct one?
    One can do face identification, and yet use someone else’s finger…

    Also, the main purpose of having stored more than one finger isn’t to let others use the device, but to make sure one can continue using the device after e.g. cutting a finger while cooking and wearing a band-aid, or to be able to use thumb or index finger, depending on how one holds the device.

    So I used to store left and right thumbs and index fingers, but certainly NEVER someone else’s paw prints.
    watto_cobra
  • Reply 3 of 5
    AppleZuluAppleZulu Posts: 2,007member
    rcfa said:
    I understand why there’s just a single fingerprint, but who says it’s actually the correct one?
    One can do face identification, and yet use someone else’s finger…

    Also, the main purpose of having stored more than one finger isn’t to let others use the device, but to make sure one can continue using the device after e.g. cutting a finger while cooking and wearing a band-aid, or to be able to use thumb or index finger, depending on how one holds the device.

    So I used to store left and right thumbs and index fingers, but certainly NEVER someone else’s paw prints.
    It’s a trade-off. Some people might be willing to allow someone else to add their fingerprint to enable use of their ID to circumvent age verifications and the like, or they might not pay attention while a friend or family member surreptitiously uses such a security loophole. The same person will be more vigilant, however, if only one fingerprint is allowed. 

    This precludes use of alternate fingerprints in cases of temporary injuries as you mention, but it’s a cost-benefit calculation to achieve the security above. 
    watto_cobra
  • Reply 4 of 5
    MplsPMplsP Posts: 3,925member
    Has anyone seen if FaceID will make any attempt to use facial recognition to match the picture in your to your facial profile off the camera? I know the pictures in IDs aren’t always great but it seems like that would be another good safegurard.
    watto_cobra
  • Reply 5 of 5
    macguimacgui Posts: 2,358member
    "Authorizing the request via Face ID or Touch ID releases the data from, a procedure that Apple notes does not require users to unlock, show or hand over their device."  

    Uh, I think the author had a stroke while writing this sentence.  Can you please review and edit?  It seems like a word is missing after "from."
    "Authorizing the request via Face ID or Touch ID releases the data from, a procedure that Apple notes does not require users to unlock, show or hand over their device."  

    Uh, I think the author had a stroke while writing this sentence.  Can you please review and edit?  It seems like a word is missing after "from."
    Remove "from" and the sentence makes sense, no additional words needed. In the meantime, your medical license should be reviewed.
    watto_cobra
Sign In or Register to comment.