The issues raised in the article may explain why Apple just added the ability to passcode-lock your device by pressing the power button 5 times. Though people have been raising similar issues about biometric identification for years. See this article from back when TouchID was released 2013, titled Fingerprints are Usernames, not Passwords . http://blog.dustinkirkland.com/2013/10/fingerprints-are-user...
I recommend against using biometric identification
81–90 of 239 posts
Re: I recommend against using biometric identification
#82"And if you really want a random number, paste this into your browser’s JavaScript console..." I would suggest rolling dice instead. The PIN that produced would be truly random.
Re: I recommend against using biometric identification
#83I don't understand why what's essentially a login (fingerprint, face, dna) is considered a password. It simply isnt. And I don't understand why I cant (on Android 7) combine fingerprint and then PIN/Pattern to unlock my device. It's mind boggling and completely stupid.
I don't think TouchID / FaceID / 4 digits are intended for the 1% use case: preventing malicious actors with long term access to the phone from getting in (think police, government agents, etc.).
As a result, most people I see have 4 digit codes on their phones, without the "10 wrong passwords erases all phone data" option enabled. That alone is probably more insecure than FaceID / TouchID over the short term. Sure, a 3D map of your face or your fingerprint is not a true password.. but for this use case, they're a perfectly fine substitute while being more convenient.
If you want long term protection, then you should use an alphanumeric password for your phone with the "10 wrong passwords" option enabled. But most people don't want or need that.
Re: I recommend against using biometric identification
#84If Jason Bourne is after you that's probably true. If you're worried about border security, that's maybe true.
But for most people, the lock on their phone isn't protecting them from the government, it's protecting them from nosy relatives, a pick pocket, or the guy that finds the phone you left at the bar, or their 4 year old. None of these 'attackers' will ever be sophisticated enough to defeat the biometric protections on an iPhone.
I think people need to adjust their security policies to reflect the actual security threats they're likely to face, and for most people Touch ID or FaceID are more than adequate.
Re: I recommend against using biometric identification
#85> And to be clear, a court in the US cannot force you to give up your passcode. That passcode exists in your head, and yours alone. It is your property, and won’t be used to incriminate you or strong-arm access to your data unless you voluntarily give it up. While technically true this is false in practice. While they can't force you to provide your passcode they can force you to unlock your phone. Francis Rawls has…
Do you have a reference for this?
Re: I recommend against using biometric identification
#86> And to be clear, a court in the US cannot force you to give up your passcode. That passcode exists in your head, and yours alone. It is your property, and won’t be used to incriminate you or strong-arm access to your data unless you voluntarily give it up. While technically true this is false in practice. While they can't force you to provide your passcode they can force you to unlock your phone. Francis Rawls has…
I suppose depends, criminal right thing is to help solve a crime or something I don't know.
Seems similar to using VPN in China. Is it illegal to protect/use your privacy.
Re: I recommend against using biometric identification
#87Never? If Jason Bourne is after you that's probably true. If you're worried about border security, that's maybe true. But for most people, the lock on their phone isn't protecting them from the government, it's protecting them from nosy relatives, a pick pocket, or the guy that finds the phone you left at the bar, or their 4 year old. None of these 'attackers' will ever be sophisticated enough to defeat the biometric…
Re: I recommend against using biometric identification
#88Earlier quoted context omitted.
The "door lock" analogy ignores the biggest flaw with fingerprints: they're forever. If your door lock is compromised, you can change the key. If someone steals your password, you can change the password. If someone steals your fingerprint, you can never change your fingerprint (same with your face). The other stuff is dead-on: its a "good enough" security measure for phones. But as a security practitioner, the bigge…
https://www.xkcd.com/538/ applies. Neither Touch ID nor passwords keep determined intruders out. If someone really wants to know what's on your phone, they will arrest/kidnap you and threaten you with prison/violence.
The problem is that while the actual ranking from least secure to most secure is "nothing < touchid/faceid < passcode", Apple's marketing and implementation gives people the false impression that its "nothing < passcode < touchid/faceid", which is bad for security.
Re: I recommend against using biometric identification
#89Earlier quoted context omitted.
How does it work today if you just enable fingerprint authentication (I'm asking because I don't know) ? Do you also have to set a backup passcode to use in case it can't read your fingerprint? Can you register multiple fingerprints in case you decide to put your main index finger too close to a sanding belt?
On iPhone, you can register multiple fingerprints, but if it can't read your finger within 5(?) tries, it requires a passcode. It also allows you to skip the fingerprint and just enter the passcode if you want. That's useful for when you ask someone you trust to find something on your phone for you.
Re: I recommend against using biometric identification
#90Never? If Jason Bourne is after you that's probably true. If you're worried about border security, that's maybe true. But for most people, the lock on their phone isn't protecting them from the government, it's protecting them from nosy relatives, a pick pocket, or the guy that finds the phone you left at the bar, or their 4 year old. None of these 'attackers' will ever be sophisticated enough to defeat the biometric…