Live data from Hacker News

I recommend against using biometric identification

medium.freecodecamp.org

81–90 of 239 posts

Re: I recommend against using biometric identification

#81
post #5

The issues raised in the article may explain why Apple just added the ability to passcode-lock your device by pressing the power button 5 times. Though people have been raising similar issues about biometric identification for years. See this article from back when TouchID was released 2013, titled Fingerprints are Usernames, not Passwords . http://blog.dustinkirkland.com/2013/10/fingerprints-are-user...

At a minimum TouchID/FaceID/Similar tech, helps users that are too lazy or technically challenged or don't consider setting a passcode due to various other reasons (for e.g:- old people who have memory/Alzheimer's etc.,) provide for a some kind of security. Its better than not having any security at all.

Re: I recommend against using biometric identification

#82
post #36

"And if you really want a random number, paste this into your browser’s JavaScript console..." I would suggest rolling dice instead. The PIN that produced would be truly random.

Especially since the script given will produce a pseudorandom number in the range [1000, 9999].

Re: I recommend against using biometric identification

#83
post #16

I don't understand why what's essentially a login (fingerprint, face, dna) is considered a password. It simply isnt. And I don't understand why I cant (on Android 7) combine fingerprint and then PIN/Pattern to unlock my device. It's mind boggling and completely stupid.

The 99% use case for having to unlock a phone with TouchID / FaceID / 4 digit passcode is to prevent people from snooping on your phone (think children, coworkers, strangers, thiefs) within a relatively short period of time. If your phone is stolen, for example, you'll probably contact Apple and remotely disable it within a day, probably sooner.

I don't think TouchID / FaceID / 4 digits are intended for the 1% use case: preventing malicious actors with long term access to the phone from getting in (think police, government agents, etc.).

As a result, most people I see have 4 digit codes on their phones, without the "10 wrong passwords erases all phone data" option enabled. That alone is probably more insecure than FaceID / TouchID over the short term. Sure, a 3D map of your face or your fingerprint is not a true password.. but for this use case, they're a perfectly fine substitute while being more convenient.

If you want long term protection, then you should use an alphanumeric password for your phone with the "10 wrong passwords" option enabled. But most people don't want or need that.

Re: I recommend against using biometric identification

#84
Never?

If Jason Bourne is after you that's probably true. If you're worried about border security, that's maybe true.

But for most people, the lock on their phone isn't protecting them from the government, it's protecting them from nosy relatives, a pick pocket, or the guy that finds the phone you left at the bar, or their 4 year old. None of these 'attackers' will ever be sophisticated enough to defeat the biometric protections on an iPhone.

I think people need to adjust their security policies to reflect the actual security threats they're likely to face, and for most people Touch ID or FaceID are more than adequate.

Re: I recommend against using biometric identification

#85

> And to be clear, a court in the US cannot force you to give up your passcode. That passcode exists in your head, and yours alone. It is your property, and won’t be used to incriminate you or strong-arm access to your data unless you voluntarily give it up. While technically true this is false in practice. While they can't force you to provide your passcode they can force you to unlock your phone. Francis Rawls has…

> The same principle applies to phones.

Do you have a reference for this?

Re: I recommend against using biometric identification

#86

> And to be clear, a court in the US cannot force you to give up your passcode. That passcode exists in your head, and yours alone. It is your property, and won’t be used to incriminate you or strong-arm access to your data unless you voluntarily give it up. While technically true this is false in practice. While they can't force you to provide your passcode they can force you to unlock your phone. Francis Rawls has…

That's F'd isn't that same as Bitcoin private keys too.

I suppose depends, criminal right thing is to help solve a crime or something I don't know.

Seems similar to using VPN in China. Is it illegal to protect/use your privacy.

Re: I recommend against using biometric identification

#87
post #84

Never? If Jason Bourne is after you that's probably true. If you're worried about border security, that's maybe true. But for most people, the lock on their phone isn't protecting them from the government, it's protecting them from nosy relatives, a pick pocket, or the guy that finds the phone you left at the bar, or their 4 year old. None of these 'attackers' will ever be sophisticated enough to defeat the biometric…

I like how easy it is to unlock my phone with my fingerprint (back-facing design instead of iphone front-facing design), I'd say the same about fingerprints(don't use it) but your fingerprints are probably all over everything that you own.

Re: I recommend against using biometric identification

#88
post #50

Earlier quoted context omitted.

The "door lock" analogy ignores the biggest flaw with fingerprints: they're forever. If your door lock is compromised, you can change the key. If someone steals your password, you can change the password. If someone steals your fingerprint, you can never change your fingerprint (same with your face). The other stuff is dead-on: its a "good enough" security measure for phones. But as a security practitioner, the bigge…

https://www.xkcd.com/538/ applies. Neither Touch ID nor passwords keep determined intruders out. If someone really wants to know what's on your phone, they will arrest/kidnap you and threaten you with prison/violence.

No security is going to keep "determined" intruders out. But the point is that you should still strive to achieve "good enough" security.

The problem is that while the actual ranking from least secure to most secure is "nothing < touchid/faceid < passcode", Apple's marketing and implementation gives people the false impression that its "nothing < passcode < touchid/faceid", which is bad for security.

Re: I recommend against using biometric identification

#89

Earlier quoted context omitted.

How does it work today if you just enable fingerprint authentication (I'm asking because I don't know) ? Do you also have to set a backup passcode to use in case it can't read your fingerprint? Can you register multiple fingerprints in case you decide to put your main index finger too close to a sanding belt?

On iPhone, you can register multiple fingerprints, but if it can't read your finger within 5(?) tries, it requires a passcode. It also allows you to skip the fingerprint and just enter the passcode if you want. That's useful for when you ask someone you trust to find something on your phone for you.

And if you reboot your phone you must enter the passcode in order to enable TouchID after that.

Re: I recommend against using biometric identification

#90
post #84

Never? If Jason Bourne is after you that's probably true. If you're worried about border security, that's maybe true. But for most people, the lock on their phone isn't protecting them from the government, it's protecting them from nosy relatives, a pick pocket, or the guy that finds the phone you left at the bar, or their 4 year old. None of these 'attackers' will ever be sophisticated enough to defeat the biometric…

The US border extends 100 miles inland around the entire perimeter. 2/3rds of the population are subject to federal overreach anywhere in that zone.
Post reply on HN