Live data from Hacker News

Understanding the ginormous Philippines data breach

troyhunt.com

71–80 of 93 posts

Re: Understanding the ginormous Philippines data breach

#71
post #53

So if I ever traveled to Philippines and scanned fingerprints at the border, anyone in the world can unlock my TouchID?

It's not quite that easy.

But in any case you don't need a data breach to get you fingerprint - it's probably right on the phone.

A fingerprint is the weakest form of security out there.

Re: Understanding the ginormous Philippines data breach

#72
post #27

> As serious as the info above is, it’s only scratching the surface. Per the reports linked to earlier, there’s also biometric data relating to fingerprints in the system. This contains columns names such as these: > PRINT_FLAG, FINGER_INFO, FINGER_TOPO_COORD, QUALITY, MATCHING_FINGER > The values within there can be quite detailed and I’ve no reason to think that this isn’t indeed legitimate print data uniquely and…

The whole notion of using fingerprints for authentication is weird. Essentially something that's akin to a username is being used as a password. I've wrote about this practice the other day[0]. It's interesting to observe that when Apple announced Touch ID for example it was presented as something with improved security. 0: https://hugotunius.se/2016/04/11/why-i-disabled-touch-id-and...

Given today's legal climate, this is what I have come up with as a compromise.

* PIN to unlock the phone, no Touch ID. Phone set to self-erase after x attempts.

* TouchID to only unlock 1Password. 30 char master password

* TouchID used for nothing else.

I would welcome any feedback if there is something that I have missed.

Re: Understanding the ginormous Philippines data breach

#73
post #64

Earlier quoted context omitted.

Really depends of the type of data, how it's being used, etc. - is there a specific problem you personally are facing and how big of a problem is it to you?

His point is that the government asks for this information, maybe as a requirement in order to procure official documents needed for everyday life and business. There's not much to do when the government of your country makes your giving of certain information a requirement. Sure, you could fight it in court but it's very likely that that will not get you very far or produce the official documents you may need. Not a…

Even in the US, for practical purposes you need to hand your data over to private entities, state governments and, yes, even the federal government, at times.

Re: Understanding the ginormous Philippines data breach

#74
post #64

Earlier quoted context omitted.

Really depends of the type of data, how it's being used, etc. - is there a specific problem you personally are facing and how big of a problem is it to you?

His point is that the government asks for this information, maybe as a requirement in order to procure official documents needed for everyday life and business. There's not much to do when the government of your country makes your giving of certain information a requirement. Sure, you could fight it in court but it's very likely that that will not get you very far or produce the official documents you may need. Not a…

First, not going to assume that's what the comment meant, but happy to address your comment as is.

Basically my position is that I agree it's complex, but I believe possible to address the issue in a way that for all parties (individual,government,3rd-party) that more value is created and less risk exists; this applies universally in my opinion.

Any rate, unclear how responding to my question with questions addresses my question other than to assume that the lack of an answer means that there are no startups that address this issue; meaning any solution I've seen requires a central authority to be involved.

Re: Understanding the ginormous Philippines data breach

#75
post #67

Earlier quoted context omitted.

Your analogy only works if usernames were stored in a secret database, not displayed publically.

Why?

Because this is the assumption behind using fingerprints as authentication.

Re: Understanding the ginormous Philippines data breach

#76
post #74

Earlier quoted context omitted.

His point is that the government asks for this information, maybe as a requirement in order to procure official documents needed for everyday life and business. There's not much to do when the government of your country makes your giving of certain information a requirement. Sure, you could fight it in court but it's very likely that that will not get you very far or produce the official documents you may need. Not a…

First, not going to assume that's what the comment meant, but happy to address your comment as is. Basically my position is that I agree it's complex, but I believe possible to address the issue in a way that for all parties (individual,government,3rd-party) that more value is created and less risk exists; this applies universally in my opinion. Any rate, unclear how responding to my question with questions addresses…

Even if some startup solved the problem, 1) I have to trust them instead of the government, so the problem hasn't really disappeared and 2) you'd have to compel everyone to work with them somehow

Re: Understanding the ginormous Philippines data breach

#77
post #67

Earlier quoted context omitted.

Why?

Because this is the assumption behind using fingerprints as authentication.

That's my whole point. Usernames are public info, passwords are private, and fingerprints occupy a weird in-between world where they're sort of public but difficult to obtain and difficult to use if you're not the one whose fingers they're on.

Re: Understanding the ginormous Philippines data breach

#78
post #44

Earlier quoted context omitted.

I think Touch ID does improve security in practice for most people, because it makes it practical to use a proper password for your phone, rather than a four-digit passcode or no passcode at all, as most people did before. You have to consider the limitations it has as well. An attacker could potentially lift your fingerprints and use it to unlock your phone. But they only get five chances to fool the sensor before T…

https://xkcd.com/538/

That comic is irritating. Most people are far more concerned with lost devices and opportunistic theft than they are worried about targeted theft or malicious actors with wrenches. Encryption reduces the pain of the lost or casually stolen device, it doesn't have to resist a wrench to be useful.

Re: Understanding the ginormous Philippines data breach

#80
post #34
post #25

Earlier quoted context omitted.

Considering you need to provide fingerprints to request all sorts of documents, what would the government be able to do that they aren't already able now? Here's a list of documents you need to provide fingerprints, off the top of my head: – National identity card (RG), mandatory for all citizens over 18 years of age; – Military conscription certificate (CAM), mandatory for all male citizens over 18 years of age; – V…

> Considering you need to provide fingerprints to request all sorts of documents, what would the government be able to do that they aren't already able now? If they already have fingerprints, and now fingerprints are suddenly required for voting, that makes election fraud easier for the government.

How does it make it easier than doing everything the same except not requiring fingerprints?
Post reply on HN