Earlier quoted context omitted.
And it’s defeated by someone just watching you unlock your phone in public once.
As is a passcode?
I recommend against using biometric identification
51–60 of 239 posts
Re: I recommend against using biometric identification
#52Earlier quoted context omitted.
Biometrics is closer to a username.
Why? I am not terribly upset if someone has my username, but I would be very concerned if they had reproducible biometrics of mine (fingerprints, facial, etc).
Re: I recommend against using biometric identification
#53Obviously facial recognition and fingerprints aren't as good as a passcode. But they're better than the previous alternative, nothing. Before fingerprint/facial recognition, for the most part the only people who used a passcode were forced to because it was a company phone.
Ideally there would be a way to use both, as a two-factor auth mechanism. CopperheadOS supported using fingerprint + passphrase/code briefly but it broke when they moved to Android 7 and they never could find the resources to fix it.
Re: I recommend against using biometric identification
#54What percent of ios users never create a passcode / pin ? I'm just thinking that if face id is defaulted on it would be better than the crowd that never create a pin. I agree it is better to have a pin enabled than faceid and even better both.
Re: I recommend against using biometric identification
#55I'd like to add a feature to the FaceID, requiring the user to wink instead of looking with both eyes open, or have a customized facial gesture, which only the user knows. It adds an extra layer of security. Not only that, you get to wink at your phone often as a sign of affection (LOL). Instead of winks, one might choose to do other facial gestures such as stick their tongue out, do a duck-face, etc.
And it’s defeated by someone just watching you unlock your phone in public once.
Re: I recommend against using biometric identification
#56Earlier quoted context omitted.
Ehh... it's not the same as a username. It's more like fingerprints are door locks. Any determined thief can get around it. But it protects you from people who aren't really all that determined. And for most people door locks are sufficient. But if you are a major crime lord, protecting something extremely valuable, or just really into security then door locks are not enough.
I think the idea is that legally it is closer to a username. A judge can allow the police to knock down your apartment door through a warrant. But they can't compel you to speak and incriminate yourself. Much the same, they can force you to reveal your fingerprint, but cannot compel you to share a password.
Unfortunately this is dependent on your jurisdiction. In Virginia it's been ruled that law enforcement can't force a password out of you, but in federal court and in other jurisdictions (Florida), they can imprison you indefinitely for not revealing your password.
The justification used is that the password itself doesn't incriminate you, it's just a password. The stuff that would be revealed with the password might be incriminating, but that's different.
Re: I recommend against using biometric identification
#57> And to be clear, a court in the US cannot force you to give up your passcode. That passcode exists in your head, and yours alone. It is your property, and won’t be used to incriminate you or strong-arm access to your data unless you voluntarily give it up. While technically true this is false in practice. While they can't force you to provide your passcode they can force you to unlock your phone. Francis Rawls has…
Re: I recommend against using biometric identification
#58I would personally like to have groups of things that can be unlocked - that I can define - Nothing - essential what's on lock (weather, maybe news headlines) - Face - basic stuff - games, calculator, News apps - Fingerprint - mail, calendar, text message, browser - Pass code - banking, settings A one all seems backward - there are something things I don't want to protect at all (don't care if someone can access) on…
If it is a totalitarian regime, they'll just kill you. If you're ever really in such a situation, a blank phone is probably the worst thing you can give them.
Instead, why not a dummy profile that's complete with user activity, social media presence, and showing active harmless use? Why not multiple profiles?
For the rest of us, those who are not spies traveling in totalitarian regimes, what this means is you can hand someone your phone to let them use it. It means you can let your kid use it and not expect to get it back with problems. You can even make the profiles based on the password, so that it only appears to have a single account.
Realistically, the biggest threat is theft. This doesn't hinder theft protection at all. It can still have the same protections, while just offering additional profiles.
Re: I recommend against using biometric identification
#59I don't understand why what's essentially a login (fingerprint, face, dna) is considered a password. It simply isnt. And I don't understand why I cant (on Android 7) combine fingerprint and then PIN/Pattern to unlock my device. It's mind boggling and completely stupid.
This. I've been looking for a way to have two factor unlock (Fingerprint + PIN) for a long time.
Re: I recommend against using biometric identification
#60Earlier quoted context omitted.
Ideally there would be a way to use both, as a two-factor auth mechanism. CopperheadOS supported using fingerprint + passphrase/code briefly but it broke when they moved to Android 7 and they never could find the resources to fix it.
I see people saying Apple should allow fingerprint plus passcode, but I've yet to hear someone explain how it would work if it can't read your fingerprint? A longer passcode? Why not just use the longer passcode in the first place.