Live data from Hacker News

Face ID, Touch ID, No ID, PINs and Pragmatic Security

troyhunt.com

21–30 of 314 posts

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#21
post #13
post #9

Earlier quoted context omitted.

According to the article, the phone won't unlock if you aren't attentive, i.e., looking at the phone with your eyes open with tiny imperceptible eye movements.

Not looking forward to the video services that demand that you pay attention to ads before they let you view their content, now that they have the ability to check.

Imagine if this feature gets added to PowerPoint, or Webex/Skype?

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#22
post #6

what about FaceID + pin? that would mean someone would have to know your pin as well as have access to your face. you also wouldn't have to look so paranoid while entering the pin. and pin by itself would be of little value.

For phone-based biometrics, the PIN has always been a backup for the fingerprint/face recognition, because these things aren't 100% reliable. Not even considering any security aspects here, just practicalities, like your hands are dirty or your face isn't being recognised (perhaps you've got bandages on your face or whatever). Having the PIN as a replacement is a good thing in these cases, otherwise you could be locked out of your device when you actually want to use it.

For 'extreme' security situations, you might as well just have a long secret PIN and no biometrics.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#23
There is an opposite use case which will make me consider getting an iPhone X for a long time.

Every so often, I leave my phone at home and I need my wife to get some info from it. Or my phone runs out of batteries and my wife's phone is there, and I use to to make a phone call.

With Face ID, these possibilities go away.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#24
post #23

There is an opposite use case which will make me consider getting an iPhone X for a long time. Every so often, I leave my phone at home and I need my wife to get some info from it. Or my phone runs out of batteries and my wife's phone is there, and I use to to make a phone call. With Face ID, these possibilities go away.

If it's implemented in the same way as TouchID, you can always fall back to PIN.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#25
post #7

Near-field worn devices. http://nfcring.com is an example of what I have in mind. What I'd like to see is this tied into an identity system, such that the ring (or other very-hard-to-misplace, but replaceable and discardable) token is not itself an identity, but rather an access token to an identity store which can present any given identity to any given system. That might be a consistent identity across multiple ses…

Slightly ironically the TLS is broken on that nfcring website.

Yeah. I ... had to edit the URL, as I'm used to specifying https rather than http these days.

There are a few other flags raised about that particular implementation, though the concept itself is the key point. The idea of a signet ring to authenticate, sign, access, pay, claim, and/or decrypt seems useful.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#26
post #23

There is an opposite use case which will make me consider getting an iPhone X for a long time. Every so often, I leave my phone at home and I need my wife to get some info from it. Or my phone runs out of batteries and my wife's phone is there, and I use to to make a phone call. With Face ID, these possibilities go away.

Your wife could also know your passcode and vice versa, if this is such a necessity

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#27
post #23

There is an opposite use case which will make me consider getting an iPhone X for a long time. Every so often, I leave my phone at home and I need my wife to get some info from it. Or my phone runs out of batteries and my wife's phone is there, and I use to to make a phone call. With Face ID, these possibilities go away.

With TouchID you could register multiple fingers, don't see why you couldn't register multiple faces.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#28
post #18

So, with Face ID, can you prevent someone trying to compel you to unlock your device by simply closing your eyes or looking away?

That was the way it was described in the Keynote

How do you know when to open your eyes again?

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#29
post #23

There is an opposite use case which will make me consider getting an iPhone X for a long time. Every so often, I leave my phone at home and I need my wife to get some info from it. Or my phone runs out of batteries and my wife's phone is there, and I use to to make a phone call. With Face ID, these possibilities go away.

If the face isn't recognized then you get "Enter your PIN" screen, right? Sorry, didn't read the article so this comment might be out of context.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#30

Nice article. However: > It's alarming not just because the number is so low, but because Dropbox holds such valuable information for so many people. I'd suggest that Dropbox users somewhat self select for those not as concerned about security as others. And more concerned about availability. Dropbox does not encrypt your data server side (or at the very least, can easily decrypt it). And they have proponents of warr…

> I'd suggest that Dropbox users somewhat self select for those not as concerned about security as others. And more concerned about availability.

I would rather say that Dropbox is being used by many people without tech knowledge. And while they might be concerned about security, they often just don't know how improtant 2 factor authentication is. At least that's what I can see for some friends & family.

Post reply on HN