Live data from Hacker News

Face ID, Touch ID, No ID, PINs and Pragmatic Security

troyhunt.com

31–40 of 314 posts

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#31
post #8

For me it's not so much the paranoia or the degree of security (which is an arguable point in itself) but the commodity of it. Touch ID lets me unlock my devices without having to re-position my upper body or move them in (practically) any way, and Face ID feels awkward (I'm typing this on the device that is likely an exception to that - a Microsoft Surface Pro - and Windows Hello's face recognition works beautifully…

> Face ID feels awkward Have you used it?

But wht was wrong with TouchID ? Were there any examples of it being weak security. What will be after Touch ID? Will Apple continue progress and built in PinchID - a tiny needle that sting you to test if you are you based on your blood/DNA?

This is a serious question. Because of there was noting wrong with Touch then why is it removed from new phone and replaced with Face ID.

Im also concerned about the data Apple will collect. I assume information about your face have to be very detailed so that this FaceID is secure. Is it really that of a push to see article in 6 months: FBI got a copy of whole Apple FaceDatabase and was able to identify and find a very dengerous criminal.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#32
It would be interesting if we could specify a particular face pattern to unlock the phone. Imagine you set up your phone to open only if you smile, now if someone picks up your phone and try to unlock it by pointing it at your face, not smiling would be easier than closing your eyes or looking away. Not even mentioning the health benefit of just smiling :)

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#33
post #23

There is an opposite use case which will make me consider getting an iPhone X for a long time. Every so often, I leave my phone at home and I need my wife to get some info from it. Or my phone runs out of batteries and my wife's phone is there, and I use to to make a phone call. With Face ID, these possibilities go away.

With TouchID you could register multiple fingers, don't see why you couldn't register multiple faces.

I'd read somewhere that specifically it's just one face

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#34

So, with Face ID, can you prevent someone trying to compel you to unlock your device by simply closing your eyes or looking away?

Yes. If you have time to do it, also press 5 times on the on/off button, it disables Face ID and forces entering the PIN. It's an iOS 11 feature, I just tried on my iPhone 6 and it disabled Touch ID.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#35
post #32

It would be interesting if we could specify a particular face pattern to unlock the phone. Imagine you set up your phone to open only if you smile, now if someone picks up your phone and try to unlock it by pointing it at your face, not smiling would be easier than closing your eyes or looking away. Not even mentioning the health benefit of just smiling :)

Isn't this already possible by smiling while training your phone?

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#36

Earlier quoted context omitted.

> Face ID feels awkward Have you used it?

But wht was wrong with TouchID ? Were there any examples of it being weak security. What will be after Touch ID? Will Apple continue progress and built in PinchID - a tiny needle that sting you to test if you are you based on your blood/DNA? This is a serious question. Because of there was noting wrong with Touch then why is it removed from new phone and replaced with Face ID. Im also concerned about the data Apple w…

TouchID was removed because it took up space on the front of the phone and Apple wanted the screen to be bigger. There's no deeper reason than that.

> Will Apple continue progress and built in PinchID - a tiny needle that sting you to test if you are you based on your blood/DNA?

I struggle to believe you when you say that's a serious question...

> Im also concerned about the data Apple will collect.

The FaceID data will be stored in the secure enclave locally on your phone, just like TouchID data was. Apple will not collect it.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#37
post #8

For me it's not so much the paranoia or the degree of security (which is an arguable point in itself) but the commodity of it. Touch ID lets me unlock my devices without having to re-position my upper body or move them in (practically) any way, and Face ID feels awkward (I'm typing this on the device that is likely an exception to that - a Microsoft Surface Pro - and Windows Hello's face recognition works beautifully…

> without having to re-position my upper body

why would you unlock your phone if you're not going to look at it? I don't understand this argument.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#38

Earlier quoted context omitted.

> Face ID feels awkward Have you used it?

But wht was wrong with TouchID ? Were there any examples of it being weak security. What will be after Touch ID? Will Apple continue progress and built in PinchID - a tiny needle that sting you to test if you are you based on your blood/DNA? This is a serious question. Because of there was noting wrong with Touch then why is it removed from new phone and replaced with Face ID. Im also concerned about the data Apple w…

The FaceDatabase as you imply is stored on the phone in a secure enclave. None of this stuff is sent to Apple.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#39
post #30

Nice article. However: > It's alarming not just because the number is so low, but because Dropbox holds such valuable information for so many people. I'd suggest that Dropbox users somewhat self select for those not as concerned about security as others. And more concerned about availability. Dropbox does not encrypt your data server side (or at the very least, can easily decrypt it). And they have proponents of warr…

> I'd suggest that Dropbox users somewhat self select for those not as concerned about security as others. And more concerned about availability. I would rather say that Dropbox is being used by many people without tech knowledge. And while they might be concerned about security, they often just don't know how improtant 2 factor authentication is. At least that's what I can see for some friends & family.

eeh, since when does u2a protect against back-end breaches?

thats just a security layer against phishing or password leaks...

don't get me wrong, i'd advice everyone to use it for anything remotely critical, because its pretty easy to setup and live with, but it really doesnt help against state actors or hackers that compromised the data servers.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#40

Earlier quoted context omitted.

With TouchID you could register multiple fingers, don't see why you couldn't register multiple faces.

I'd read somewhere that specifically it's just one face

Makes sense, most people only have one face.
Post reply on HN