Live data from Hacker News

I recommend against using biometric identification

medium.freecodecamp.org

141–150 of 239 posts

Re: I recommend against using biometric identification

#141

Earlier quoted context omitted.

How does it work today if you just enable fingerprint authentication (I'm asking because I don't know) ? Do you also have to set a backup passcode to use in case it can't read your fingerprint? Can you register multiple fingerprints in case you decide to put your main index finger too close to a sanding belt?

On iPhone, you can register multiple fingerprints, but if it can't read your finger within 5(?) tries, it requires a passcode. It also allows you to skip the fingerprint and just enter the passcode if you want. That's useful for when you ask someone you trust to find something on your phone for you.

Sounds very similar to Android too.

Re: I recommend against using biometric identification

#142
post #36

"And if you really want a random number, paste this into your browser’s JavaScript console..." I would suggest rolling dice instead. The PIN that produced would be truly random.

And some dice I've had were quite obviously not random. :)

Re: I recommend against using biometric identification

#143
post #107

Earlier quoted context omitted.

That man may still be in prison, but that drive is still encrypted. If you are unwilling to give something you know to someone, no amount of force can take it from you. Had that drive been encrypted using facial biometrics, they could have just knocked him out, glued his eyes open, and taken what they wanted. What works, and what has been deemed legal, as you probably already know, are not mutually exclusive.

Which is torture, so they could do that until he tells them the passcode aswell.

It's true that torturing a person is an effective way to change what that person wants. It doesn't always end with the torturer getting what they want, though.

Re: I recommend against using biometric identification

#144
post #50

Earlier quoted context omitted.

The "door lock" analogy ignores the biggest flaw with fingerprints: they're forever. If your door lock is compromised, you can change the key. If someone steals your password, you can change the password. If someone steals your fingerprint, you can never change your fingerprint (same with your face). The other stuff is dead-on: its a "good enough" security measure for phones. But as a security practitioner, the bigge…

>If someone steals your fingerprint, you can never change your fingerprint (same with your face). At what point is stealing a fingerprint, retina print, or face going to be economical enough for the thief that this would be an actual valid concern in 99% of use cases? Both FaceID and TouchID need to read a living person with a pulse in order to authenticate. You can't just take a printout of a fingerprint and drop it…

> At what point is stealing a fingerprint, retina print, or face going to be economical enough for the thief that this would be an actual valid concern in 99% of use cases?

For the average person who is just securing their phone that only stores pictures of their cat, this isn't a concern, but that's far less than 99%. For pretty much anyone who is logged into their work email/VPN via their phone, or is using fingerprint scanners to secure their work laptop, this is a very real concern that I have seen exploited a few times in the real world.

> Both FaceID and TouchID need to read a living person with a pulse in order to authenticate.

TBD with FaceID, but with TouchID this isn't the case. You can defeat TouchID with $10 worth of office supplies and some play-dough.

> Which bank accounts are taking fingerprints? Do you mean people's banking apps on their phones? In order to get to that they would need to steal both your phone AND your fingerprint.

Since your phone literally has your fingerprint left on it from when you touched it, this isn't really a difficult task.

And as I mentioned, it's even worse if you're one of the people who uses a password manager on your phone that is also locked with fingerprint. Then, every account you have is now compromised. And even if you're using 2FA, your phone is likely your 2FA device, which the thief also has.

> This often happens when someone shoves policy down people's throats without explaining themselves or getting buy-in from their clients. This is a communication skills problem, not an issue with biometrics.

No, it is undeniably an issue with biometrics (and the way they're treated). Training and awareness (communications) is one of the primary problems that any security implementation will try to tackle, but it's just made more difficult to do that when Apple is pushing falsehoods like "TouchID is the most secure thing ever!" in all of their marketing materials.

Re: I recommend against using biometric identification

#145
post #126

> And to be clear, a court in the US cannot force you to give up your passcode. That passcode exists in your head, and yours alone. It is your property, and won’t be used to incriminate you or strong-arm access to your data unless you voluntarily give it up. While technically true this is false in practice. While they can't force you to provide your passcode they can force you to unlock your phone. Francis Rawls has…

What if you just say you forgot the passcode?

Not necessarily clear, but Rawls did not use this defense. It should be effective but we are in unknown territory.

Re: I recommend against using biometric identification

#146
post #61

Earlier quoted context omitted.

Ehh... it's not the same as a username. It's more like fingerprints are door locks. Any determined thief can get around it. But it protects you from people who aren't really all that determined. And for most people door locks are sufficient. But if you are a major crime lord, protecting something extremely valuable, or just really into security then door locks are not enough.

Who you are, what you have, and what you know. Those are what we need to have good security. Fingerprints confirm who you are. What you have is the phone, in this case. What you know is the password. If you're concerned about security, use the print/face and the password.

Fingerprints do not confirm identity.

A phone is not what you have in the context of this discussion. What you have would be an NFC, for example to authenticate to the phone. A phone is only what you have, when you use the phone as evidence to authenticate into a different system.

Re: I recommend against using biometric identification

#147
It's easier to watch people entering their PINs on overhead security camera footage than it is to cheat their biometrics. Dedicated attackers have simpler, more effective options than having to hack your biometrics.

Yes, your fingerprint and faceprint are irreplaceable. They're kept device-local for more reasons than just Apple Pay. But make no mistake: It's simpler to record you entering your PIN surreptitiously than it is to hack your biometrics.

Are the attacks against it "likely" or "unlikely"? They're clearly aware of the "photograph" and "Mission Impossible" scenarios, and demonstrated visible proof of their time spent ensuring they're refused. If you're under directed and specific attack, that's the best you can hope for from technology! It's not human. It can't magically evolve defenses against humans with time, patience, and hacking powers.

Devices are only safe when a human takes care of them. Your phone, your computer, phone companies, credit bureaus. When you don't take care of technology, someone will eventually exploit it, usually for greed.

Which is more likely:

Someone makes a cool mask device that can hack faceprint, and simultaneously gets sued by Honda Robotics for violating one of their many, many patents on lifelike robotic faces. They use it to hack you, and somehow materially impact your life through hacking your device.

Or, someone hard-resets your phone while you aren't looking, videotapes you entering your PIN confusedly, and then steals it.

A dedicated malicious attacker will always take the second path, because this biometrics crap is useless when you can just get people to blindly enter their PIN as if somehow it's safe to do so anywhere.

TL;DR: Enter your PIN in a bathroom stall, or it's on the security tapes of the mall. If you do this, don't enable Touch ID or Face ID. Problem solved.

Re: I recommend against using biometric identification

#148

The suggested alternative is to use passcodes, but then there's no way to unlock your phone without making the unlock code plainly visible.

"It hurts a lot more to change your face than to change your passcode"

Yeah, but there's not much point in having a passcode if it gets compromised on every use.

Re: I recommend against using biometric identification

#149

> And to be clear, a court in the US cannot force you to give up your passcode. That passcode exists in your head, and yours alone. It is your property, and won’t be used to incriminate you or strong-arm access to your data unless you voluntarily give it up. While technically true this is false in practice. While they can't force you to provide your passcode they can force you to unlock your phone. Francis Rawls has…

I think, at some point it gets to the Supreme court which will decide whether it's covered by the 5th amendment or not.

The answer is probably no.

Requiring a person to unlock a device is not prohibited by the Fifth Amendment simply because the device contains incriminating information that would otherwise be inaccessible to police.

If the police have a valid warrant to search your safe, you are generally required to unlock it for them, even if the safe contains evidence that incriminates you. If you are issued a valid subpoena to produce certain documents in your possession, you are generally required to produce those documents, even if they incriminate you. Compelled decryption of hard drives is fundamentally no different.

It is true that the act of unlocking the safe or producing those documents is itself testimonial in the sense that you are conveying the fact that you know the combination or possess those documents. But under the "foregone conclusion" doctrine, if the state already knows that implicit testimony, then it is not protected by the Fifth Amendment. It's obvious that Rawls knows the password to the drives.

There are legitimate concerns about how search warrants should apply to electronic devices. However, these are Fourth Amendment issues, not Fifth Amendment ones.

If you're interested, Orin Kerr from the Volokh Conspiracy has written several articles about compelled decryption, including with respect to this particular case [1, 2, 3].

1: https://www.washingtonpost.com/news/volokh-conspiracy/wp/201...

2: https://www.washingtonpost.com/news/volokh-conspiracy/wp/201...

3: https://www.washingtonpost.com/news/volokh-conspiracy/wp/201...

Re: I recommend against using biometric identification

#150

> And to be clear, a court in the US cannot force you to give up your passcode. That passcode exists in your head, and yours alone. It is your property, and won’t be used to incriminate you or strong-arm access to your data unless you voluntarily give it up. While technically true this is false in practice. While they can't force you to provide your passcode they can force you to unlock your phone. Francis Rawls has…

> Francis Rawls has been in prison for two years now over refusing to decrypt a hard drive.

People have got to stop martyrizing this guy. He's in jail because the prosecution got a fortuitous decision that says they can hold him as long as they want until he coughs up a password. They aren't fishing for evidence, nor have they used this trick on anyone else. If he went to trial on the evidence already in public, the guy would hang (metaphorically). There is no significant doubt in anyone's mind that this drive contains CP.

But the principle is the important part you say? Sure. Make a principled argument. Don't cite this guy.

Post reply on HN