Live data from Hacker News

Face ID, Touch ID, No ID, PINs and Pragmatic Security

troyhunt.com

41–50 of 314 posts

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#41
post #37
post #8

For me it's not so much the paranoia or the degree of security (which is an arguable point in itself) but the commodity of it. Touch ID lets me unlock my devices without having to re-position my upper body or move them in (practically) any way, and Face ID feels awkward (I'm typing this on the device that is likely an exception to that - a Microsoft Surface Pro - and Windows Hello's face recognition works beautifully…

> without having to re-position my upper body why would you unlock your phone if you're not going to look at it? I don't understand this argument.

I unlock the phone while it's still in my pocket, by the time it reaches eye level, it's already unlocked. And with a few muscles memory tricks, there's even a chance I have opened the right app without even looking in the fraction of a second it took me to take the phone out of my pocket.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#42
post #30

Nice article. However: > It's alarming not just because the number is so low, but because Dropbox holds such valuable information for so many people. I'd suggest that Dropbox users somewhat self select for those not as concerned about security as others. And more concerned about availability. Dropbox does not encrypt your data server side (or at the very least, can easily decrypt it). And they have proponents of warr…

> I'd suggest that Dropbox users somewhat self select for those not as concerned about security as others. And more concerned about availability. I would rather say that Dropbox is being used by many people without tech knowledge. And while they might be concerned about security, they often just don't know how improtant 2 factor authentication is. At least that's what I can see for some friends & family.

I have tech knowledge, but I had absolutely no knowledge that Dropbox offered 2-factor.

I don't keep confidential stuff in DB because, I know that the company effectively has access to everything. Nonetheless, 2 factor sounds interesting. So I look at this:

https://www.dropbox.com/help/security/enable-two-step-verifi...

Right. Now I understand why so few people have it enabled.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#43
post #37
post #8

For me it's not so much the paranoia or the degree of security (which is an arguable point in itself) but the commodity of it. Touch ID lets me unlock my devices without having to re-position my upper body or move them in (practically) any way, and Face ID feels awkward (I'm typing this on the device that is likely an exception to that - a Microsoft Surface Pro - and Windows Hello's face recognition works beautifully…

> without having to re-position my upper body why would you unlock your phone if you're not going to look at it? I don't understand this argument.

my phone is currently sat on my desk, about 10 inches from my right arm. I can, and do, check messages on it, by only repositioning my arm to unlock it.

I easily read any messages by glancing at the phone, never coming into any decent imaging range.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#44
post #23

There is an opposite use case which will make me consider getting an iPhone X for a long time. Every so often, I leave my phone at home and I need my wife to get some info from it. Or my phone runs out of batteries and my wife's phone is there, and I use to to make a phone call. With Face ID, these possibilities go away.

I presume you can enroll multiple faces, no?

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#45
post #6

what about FaceID + pin? that would mean someone would have to know your pin as well as have access to your face. you also wouldn't have to look so paranoid while entering the pin. and pin by itself would be of little value.

For phone-based biometrics, the PIN has always been a backup for the fingerprint/face recognition, because these things aren't 100% reliable. Not even considering any security aspects here, just practicalities, like your hands are dirty or your face isn't being recognised (perhaps you've got bandages on your face or whatever). Having the PIN as a replacement is a good thing in these cases, otherwise you could be lock…

FaceID + shortpin = unlock

longpin = unlock

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#46

Nice article. However: > It's alarming not just because the number is so low, but because Dropbox holds such valuable information for so many people. I'd suggest that Dropbox users somewhat self select for those not as concerned about security as others. And more concerned about availability. Dropbox does not encrypt your data server side (or at the very least, can easily decrypt it). And they have proponents of warr…

My problem with dropbox alternatives is that they are either far more expensive or don't run on linux (with syncing).

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#47
post #23

There is an opposite use case which will make me consider getting an iPhone X for a long time. Every so often, I leave my phone at home and I need my wife to get some info from it. Or my phone runs out of batteries and my wife's phone is there, and I use to to make a phone call. With Face ID, these possibilities go away.

I presume you can enroll multiple faces, no?

FaceID currently only supports one face.

Source: https://twitter.com/reneritchie/status/907724254652784640

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#48
post #35
post #32

It would be interesting if we could specify a particular face pattern to unlock the phone. Imagine you set up your phone to open only if you smile, now if someone picks up your phone and try to unlock it by pointing it at your face, not smiling would be easier than closing your eyes or looking away. Not even mentioning the health benefit of just smiling :)

Isn't this already possible by smiling while training your phone?

I am not sure but I think that if you smiled while training your phone you'd still be able to unlock it with any other facial expression

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#49

Earlier quoted context omitted.

But wht was wrong with TouchID ? Were there any examples of it being weak security. What will be after Touch ID? Will Apple continue progress and built in PinchID - a tiny needle that sting you to test if you are you based on your blood/DNA? This is a serious question. Because of there was noting wrong with Touch then why is it removed from new phone and replaced with Face ID. Im also concerned about the data Apple w…

TouchID was removed because it took up space on the front of the phone and Apple wanted the screen to be bigger. There's no deeper reason than that. > Will Apple continue progress and built in PinchID - a tiny needle that sting you to test if you are you based on your blood/DNA? I struggle to believe you when you say that's a serious question... > Im also concerned about the data Apple will collect. The FaceID data w…

Second, facial features are more unique than fingerprints - according to apple's own presentation, there's a 1 in 10.000 chance that prints from different people would unlock it. With face ID, this becomes 1 in 50.000 (iirc).

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#50

Earlier quoted context omitted.

> Face ID feels awkward Have you used it?

But wht was wrong with TouchID ? Were there any examples of it being weak security. What will be after Touch ID? Will Apple continue progress and built in PinchID - a tiny needle that sting you to test if you are you based on your blood/DNA? This is a serious question. Because of there was noting wrong with Touch then why is it removed from new phone and replaced with Face ID. Im also concerned about the data Apple w…

TouchID also is problematic if you're wearing gloves, which people who don't live in San Francisco do during non-trivial portions of the year.
Post reply on HN