Live data from Hacker News

Face ID, Touch ID, No ID, PINs and Pragmatic Security

troyhunt.com

1–10 of 314 posts

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#5
Near-field worn devices.

http://nfcring.com is an example of what I have in mind.

What I'd like to see is this tied into an identity system, such that the ring (or other very-hard-to-misplace, but replaceable and discardable) token is not itself an identity, but rather an access token to an identity store which can present any given identity to any given system.

That might be a consistent identity across multiple sessions or unique identities on each session. The identity might be tied to some central certifying agency (e.g., a motor vehicles department or national pensions fund), or not.

There are several elements of this which I'd like to see developed further, including how keys might be reconstructed or recovered using a quorum system of trusted sources (divide your key into pieces, share those amongst friends, family, or some local authority, such that key loss need not equal data loss), and possibly via law enforcement.

I'm also looking at the possibility of a public ledger system which might allow for both workfactor requirements and public disclosure of keys being revealed. This may be a viable application of crypto, though I'm not entirely sure of this.

(The feature might also be optional -- you could take the risk of key loss, or allow for recovery. But the present situation with PKI of losing access to all previously-encrypted data in the event of key loss would be mitigated.)

There's also the requirement for devices to have support for near-field readers. I'm told this is alreadly largely a reality, though my reading of specs for various mobile devices suggests otherwise.

The biggest challenges through all of this are not the technology itself, but the adoption, requirement, and enforcement of standards, including availability of tokens at low or no end-user price. Trust of the information ecosystem overall might be a suitable incentive for this to happen.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#7

Near-field worn devices. http://nfcring.com is an example of what I have in mind. What I'd like to see is this tied into an identity system, such that the ring (or other very-hard-to-misplace, but replaceable and discardable) token is not itself an identity, but rather an access token to an identity store which can present any given identity to any given system. That might be a consistent identity across multiple ses…

Slightly ironically the TLS is broken on that nfcring website.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#8
For me it's not so much the paranoia or the degree of security (which is an arguable point in itself) but the commodity of it. Touch ID lets me unlock my devices without having to re-position my upper body or move them in (practically) any way, and Face ID feels awkward (I'm typing this on the device that is likely an exception to that - a Microsoft Surface Pro - and Windows Hello's face recognition works beautifully, but I am _always_ facing it when I need it to unlock, so...)

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#10
post #8

For me it's not so much the paranoia or the degree of security (which is an arguable point in itself) but the commodity of it. Touch ID lets me unlock my devices without having to re-position my upper body or move them in (practically) any way, and Face ID feels awkward (I'm typing this on the device that is likely an exception to that - a Microsoft Surface Pro - and Windows Hello's face recognition works beautifully…

> Face ID feels awkward

Have you used it?

Post reply on HN