Live data from Hacker News

I recommend against using biometric identification

medium.freecodecamp.org

121–130 of 239 posts

Re: I recommend against using biometric identification

#121
post #91

>And if you want really go all out, most phones — including iPhone — support 5 or even 6 digit passcodes. iphone supports arbitrary-length alphanumeric passwords.

If memory serves, you can actually set a longer numeric PIN and it will still give you the number pad for longer, but quick to enter passwords. Alphanumeric are obviously more secure but noticeably slower to enter and IMO it's nice there's a middle ground.

yes, this is true. My PIN is ~9 characters, digits only.

Re: I recommend against using biometric identification

#122

> And to be clear, a court in the US cannot force you to give up your passcode. That passcode exists in your head, and yours alone. It is your property, and won’t be used to incriminate you or strong-arm access to your data unless you voluntarily give it up. While technically true this is false in practice. While they can't force you to provide your passcode they can force you to unlock your phone. Francis Rawls has…

Fuck, that is absolutely nauseating. What's worse is that trustworthy deniable encryption - which would solve this - is practically non-existent now that TrueCrypt is gone.

You can get this from VeraCrypt (https://www.veracrypt.fr/en/Home.html)

Re: I recommend against using biometric identification

#123

> And to be clear, a court in the US cannot force you to give up your passcode. That passcode exists in your head, and yours alone. It is your property, and won’t be used to incriminate you or strong-arm access to your data unless you voluntarily give it up. While technically true this is false in practice. While they can't force you to provide your passcode they can force you to unlock your phone. Francis Rawls has…

Fuck, that is absolutely nauseating. What's worse is that trustworthy deniable encryption - which would solve this - is practically non-existent now that TrueCrypt is gone.

Isn't TrueCrypt 7.1a still reliable?

Re: I recommend against using biometric identification

#124
post #120

Earlier quoted context omitted.

> I think people need to adjust their security policies to reflect the actual security threats they're likely to face, and for most people Touch ID or FaceID are more than adequate. Sounds like you work for Equifax. (= Look, real security threats are out there -- even if you don't want to acknowledge them. Phones have too much sensitive data, photos, bank accounts -- now the ability to pay via text message. It's just…

Sure, but has there been a single case of someone's bank account being robbed because they lost their phone, and someone went through the effort to collect and impersonate their fingerprint to unlock it? You could be shot at random too, but I'm betting you didn't wear a bullet proof vest today, unless you have cause to think someone is determined to harm you. And don't I wish that my credit info requires a fingerprin…

Certainly there have been people with devices that had poor security that were remotely accessed and then robbed.

TeamViewer accounts with weak passwords were being hacked en masse with scripts trying to visit paypal.con and transfering funds. If you had passwords auto-saved in your browser they could get in to make the transfer.

FaceID is better than 99.9% of what humans actually do in the real world.

Re: I recommend against using biometric identification

#125
post #123

Earlier quoted context omitted.

Fuck, that is absolutely nauseating. What's worse is that trustworthy deniable encryption - which would solve this - is practically non-existent now that TrueCrypt is gone.

Isn't TrueCrypt 7.1a still reliable?

Yeah, it works well enough - some pain, have to deactivate it to do the major updates and such on Win10, but it does work.

Re: I recommend against using biometric identification

#126

> And to be clear, a court in the US cannot force you to give up your passcode. That passcode exists in your head, and yours alone. It is your property, and won’t be used to incriminate you or strong-arm access to your data unless you voluntarily give it up. While technically true this is false in practice. While they can't force you to provide your passcode they can force you to unlock your phone. Francis Rawls has…

What if you just say you forgot the passcode?

Re: I recommend against using biometric identification

#127
post #122

Earlier quoted context omitted.

Fuck, that is absolutely nauseating. What's worse is that trustworthy deniable encryption - which would solve this - is practically non-existent now that TrueCrypt is gone.

You can get this from VeraCrypt ( https://www.veracrypt.fr/en/Home.html )

I got the impression that VeraCrypt was not being run very well and that the developers didn't have much security experience based on the audit report that came out. I didn't consider it a trustworthy project. Has anything changed that?

Re: I recommend against using biometric identification

#128
post #50

Earlier quoted context omitted.

Ehh... it's not the same as a username. It's more like fingerprints are door locks. Any determined thief can get around it. But it protects you from people who aren't really all that determined. And for most people door locks are sufficient. But if you are a major crime lord, protecting something extremely valuable, or just really into security then door locks are not enough.

The "door lock" analogy ignores the biggest flaw with fingerprints: they're forever. If your door lock is compromised, you can change the key. If someone steals your password, you can change the password. If someone steals your fingerprint, you can never change your fingerprint (same with your face). The other stuff is dead-on: its a "good enough" security measure for phones. But as a security practitioner, the bigge…

>If someone steals your fingerprint, you can never change your fingerprint (same with your face).

At what point is stealing a fingerprint, retina print, or face going to be economical enough for the thief that this would be an actual valid concern in 99% of use cases? Both FaceID and TouchID need to read a living person with a pulse in order to authenticate. You can't just take a printout of a fingerprint and drop it in. This is a really heavy lift to try to jack some random person's phone. Unless you're securing State Secrets or occupy rarefied enough heights that you have a Swiss bank account I don't really see anyone bothering.

>and so consumers buy into this and then also use fingerprints to secure things like their bank accounts, work logins, password vaults

Which bank accounts are taking fingerprints? Do you mean people's banking apps on their phones? In order to get to that they would need to steal both your phone AND your fingerprint. If a thief is this enterprising your info. is lost anyway. And again, they would need an extremely high fidelity reading of your fingerprint and the ability to reskin a living finger with it. And they would have to execute all this before you get to an Apple Store or a PC to remotely shut it down.

>Then we get yelled at by people from the company because "Apple says fingerprints are the best for security, why aren't you letting us use them?" It's a pain.

This often happens when someone shoves policy down people's throats without explaining themselves or getting buy-in from their clients. This is a communication skills problem, not an issue with biometrics.

Re: I recommend against using biometric identification

#129

Earlier quoted context omitted.

Case 1 and 2 are covered with FaceID - you have to be actively looking at the phone, drugged/eyes closed/looking away/etc. won't cut it.

Case 1: "Look at the phone straight-ahead with your eyes or we'll beat you with the rubber-hose again" Case 2: Hold open the eyelids with tape. Even if the eyes have rolled-back in their sockets they can be re-positioned with some manual adjustment enough to get the system to work.

Case3: Give me you password or I beat you again.

How is this different?

Post reply on HN