Live data from Hacker News

Feds Walk into a Building and Demand Everyone's Fingerprints to Open Phones

forbes.com

171–180 of 190 posts

Re: Feds Walk into a Building and Demand Everyone's Fingerprints to Open Phones

#171
post #2

Just another reason to forgo the convenience of biometrics in favor of a password/phrase that exists only in your mind. At least for now, that's something you can't be compelled to produce. Really though, this descent into a police state is such a pathetic outcome for this country. Dangerous, scary, and tragic, but also... pathetic. This is what happens when a sizeable majority don't even participate in the electoral…

Reading this from the Forbes article: https://assets.documentcloud.org/documents/3143273/Mass-Fing... Relevant bits start at page 5 (III - LEGAL DISCUSSION). Compelling a person to provide his or her fingerprint does not implicate, let alone violate, the Fifth Amendment. "[B]oth federal and state courts have usually held that [the Fifth Amendment] offers no protection against compulsion to submit to fingerprinting."…

Exactly, the fingerprints aren't material evidence in this case, but communicative testimony that could lead them to unspecified future material evidence on their phone. It's not the same thing at all.

Re: Feds Walk into a Building and Demand Everyone's Fingerprints to Open Phones

#172
post #155

Earlier quoted context omitted.

Exactly. I'd even do locally-sourced hardware if the device ever leaves my site or they plug anything into it. Download the data via a VPN to be stored in an encrypted container. Upload and wipe it when you're done for your next round back. Not as much trouble as one would think if you use easy disk encryption, VPN, and syncing. I don't have an up-to-date recommendation on what combo to use, though.

yeah. while the two of you deal with stupid workarounds that work for only you, i'll rather try and fix the issue.

What's your proposed fix for establishing privacy from police at borders in all industrialized nations despite lack of voters or media campaign backing you? Cuz I call bullshit on that.

Re: Feds Walk into a Building and Demand Everyone's Fingerprints to Open Phones

#173
post #121

Earlier quoted context omitted.

Right, and considering fingerprint's long history as identification, it seems like it would be both impossible & unreasonable to try to split the two uses. Can we really say "You only obtained his fingerprint for the purpose of identifying him, you can't use it to unlock the phone"? And, we can't reasonably try to end the use of fingerprints as ID...

> Can we really say "You only obtained his fingerprint for the purpose of identifying him, you can't use it to unlock the phone"? That seems to me to be a very reasonable thing to say. It seems to me that we have plenty of mechanism in place to say "you have X, you can use it for Y, and not Z, because using it for Z violates someone's rights". As a super contrived strawman example, if your computer ever gets confisca…

To be clear I don't think it's unreasonable, it just seems it would be difficult to define & enforce, because it's already matter of public record. For example, what if the fingerprint was lifted from the scene of the crime? Can you use that to unlock the phone?

Re: Feds Walk into a Building and Demand Everyone's Fingerprints to Open Phones

#174
post #121

Earlier quoted context omitted.

> Can we really say "You only obtained his fingerprint for the purpose of identifying him, you can't use it to unlock the phone"? That seems to me to be a very reasonable thing to say. It seems to me that we have plenty of mechanism in place to say "you have X, you can use it for Y, and not Z, because using it for Z violates someone's rights". As a super contrived strawman example, if your computer ever gets confisca…

To be clear I don't think it's unreasonable , it just seems it would be difficult to define & enforce, because it's already matter of public record. For example, what if the fingerprint was lifted from the scene of the crime? Can you use that to unlock the phone?

if your house key is laying outside, can they use it without a warrant?

Re: Feds Walk into a Building and Demand Everyone's Fingerprints to Open Phones

#175
post #167
post #143

Earlier quoted context omitted.

Thieves sell the phone on to people who know how to exploit what is on your phone to try to get access to your accounts and money.

How would your phone give them access to any of that? All of that kind of thing is inevitably protected by more security layers they won't be able to break, and meanwhile, the phone itself is worth something once wiped. Worse, the longer they fiddle with your phone, unwiped, the longer they risk someone tracking that phone. They're burglars, not masterminds.

What I heard is phones are often sold off by burglars to organized crime who do know how to exploit the phone to its full potential (and not get tracked, and properly wipe it and resell it after properly copying off the data/login credentials which is sold to another party, which then package the data with other data and sell that, and so on).

Wish I had some better sources. All I could find from a quick google search is that the market rate for full personal info is $20 -- that is certainly something you can get with email inbox access (which is enough to get Amazon login which would have your full address etc etc)

Keep in mind most services only needs your email address and browser cookies for full access, only banking services etc are 2FA.

Re: Feds Walk into a Building and Demand Everyone's Fingerprints to Open Phones

#176
post #85

This is one reason I've always wanted to have two separate authentication credentials for one user. Unfortunately, I've yet to find an acceptable or easy way to implement that on any device that would need it (your phone, your laptop, any device which you want to keep stuff private). For example: have one authentication method that unlocks the device to the typical desktop environment, command line, or whatever -- ju…

What about a 'distress' password that unlocks the device to a benign but plausible state?

This is EXACTLY a best-case-scenario, but I have no idea if/how it can be done. (ie: one user account, username: , but unlocks and boots into a typical desktop, and a separate unlocks into another totally different environment)

Re: Feds Walk into a Building and Demand Everyone's Fingerprints to Open Phones

#177
post #85

This is one reason I've always wanted to have two separate authentication credentials for one user. Unfortunately, I've yet to find an acceptable or easy way to implement that on any device that would need it (your phone, your laptop, any device which you want to keep stuff private). For example: have one authentication method that unlocks the device to the typical desktop environment, command line, or whatever -- ju…

I think Qubes OS ( https://en.wikipedia.org/wiki/Qubes_OS ) does something similar to what you're looking for. You can set it up so when you login your "qube" (The virtual machine you're currently using) is a normal looking operating system that doesn't have access to any of your protected files. You can then load up your protected files and programs by starting another password protected "qube", which is similar to…

This looks very, very interesting. I'll have a deeper look into Qubes this weekend for sure. I wonder how good their repos are in terms of up-to-date packages and software

Re: Feds Walk into a Building and Demand Everyone's Fingerprints to Open Phones

#178

Earlier quoted context omitted.

I am curious. So... how often are you actually in a situation like that? You know, police with a search warrant. Or, do you feel that there is a reasonable possibility that will happen to you?

Every time I go through customs

Uh, ok... what countries are involved?

Also, how does that work? Customs officer asks you to touch-unlock your phone.

You say, no I have a pin code!

And then they say, oooh then, nevermind, please proceed?

That does not make sense.

Re: Feds Walk into a Building and Demand Everyone's Fingerprints to Open Phones

#179

Earlier quoted context omitted.

I am curious. So... how often are you actually in a situation like that? You know, police with a search warrant. Or, do you feel that there is a reasonable possibility that will happen to you?

It does happen by mistake. My apartment was raided by police and I know four others who have been raided too. In two of those cases, the people who were raided had nothing to do with any kind of illegal activity. The other three were drug related, of course.

That sucks, sure. Did they actually ask you to unlock your phone?

Re: Feds Walk into a Building and Demand Everyone's Fingerprints to Open Phones

#180
post #117
post #55

If my device has been powered off, it can't be unlocked with a fingerprint. For me that's enough of a trade-off to take the risk.

I was going to say the same thing, but then the article says: > For that reason, the warrant authorizes the seizure of ‘passwords, encryption keys, and other access devices that may be necessary to access the device,’” the document read. So the "power off the device, now it's a password" seems to be something they were prepared for. The article is unclear as to whether or not this was granted, but if so it'd be seemi…

Would that hold up? Isn't sharing of a password protected?
Post reply on HN