I recommend against using biometric identification
31–40 of 239 posts
Re: I recommend against using biometric identification
#32The issues raised in the article may explain why Apple just added the ability to passcode-lock your device by pressing the power button 5 times. Though people have been raising similar issues about biometric identification for years. See this article from back when TouchID was released 2013, titled Fingerprints are Usernames, not Passwords . http://blog.dustinkirkland.com/2013/10/fingerprints-are-user...
It's more like fingerprints are door locks. Any determined thief can get around it. But it protects you from people who aren't really all that determined. And for most people door locks are sufficient. But if you are a major crime lord, protecting something extremely valuable, or just really into security then door locks are not enough.
Re: I recommend against using biometric identification
#33I don't know what's up with his sample JS, a simple "Math.floor(Math.random() * 9999)" would be better.
(Math.floor(Math.random() * 10000) + 10000 + "").substr(1)
Re: I recommend against using biometric identification
#34While technically true this is false in practice. While they can't force you to provide your passcode they can force you to unlock your phone. Francis Rawls has been in prison for two years now over refusing to decrypt a hard drive.[1] The same principle applies to phones. If a judge finds you in contempt-of-court they can imprison you indefinitely.
1: https://arstechnica.com/tech-policy/2017/09/judge-wont-relea...
Re: I recommend against using biometric identification
#35Earlier quoted context omitted.
Biometric data is not a username. Biometric data is also not a password. Biometrics is biometrics. I like to think of it sitting between a continuum between "username" and "password". I might like a setting to require both a Touch ID (or Face ID) and a passphrase to unlock my iPhone. However, Touch ID has flaked out enough times for me (not accepting my fingerprints) that I probably wouldn't like to risk it in practi…
Biometrics is closer to a username.
Re: I recommend against using biometric identification
#36I would suggest rolling dice instead. The PIN that produced would be truly random.
Re: I recommend against using biometric identification
#37Just Realized : Face recognition unlock : Biggest Security Scare - Case 1 : Imagine crossing security check or border crossing. Guards just take your phone and point it to you : UNLOCKED . No need to resis to give passwd - Case 2 : drug the activist and point unconscious victim ! Voila ! - Case 3 : Steal the phone, and change the cover and flash it in front of the real owner ! could go on and on ...
Re: I recommend against using biometric identification
#38It adds an extra layer of security. Not only that, you get to wink at your phone often as a sign of affection (LOL).
Instead of winks, one might choose to do other facial gestures such as stick their tongue out, do a duck-face, etc.
Re: I recommend against using biometric identification
#39The issues raised in the article may explain why Apple just added the ability to passcode-lock your device by pressing the power button 5 times. Though people have been raising similar issues about biometric identification for years. See this article from back when TouchID was released 2013, titled Fingerprints are Usernames, not Passwords . http://blog.dustinkirkland.com/2013/10/fingerprints-are-user...
Ehh... it's not the same as a username. It's more like fingerprints are door locks. Any determined thief can get around it. But it protects you from people who aren't really all that determined. And for most people door locks are sufficient. But if you are a major crime lord, protecting something extremely valuable, or just really into security then door locks are not enough.
A judge can allow the police to knock down your apartment door through a warrant. But they can't compel you to speak and incriminate yourself.
Much the same, they can force you to reveal your fingerprint, but cannot compel you to share a password.
Re: I recommend against using biometric identification
#40All I need is a way for the screen to ignore input (when it turns itself on) unless I activate it with the power button.
Are there really that many people who truly need very high security on their phones?
Seems to me most people just want to deter casual snooping.
Personally I would rather that any app that has high security requirements would secure itself and not require that the entire phone be secured.