Live data from Hacker News

Face ID, Touch ID, No ID, PINs and Pragmatic Security

troyhunt.com

81–90 of 314 posts

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#81
post #50

Earlier quoted context omitted.

But wht was wrong with TouchID ? Were there any examples of it being weak security. What will be after Touch ID? Will Apple continue progress and built in PinchID - a tiny needle that sting you to test if you are you based on your blood/DNA? This is a serious question. Because of there was noting wrong with Touch then why is it removed from new phone and replaced with Face ID. Im also concerned about the data Apple w…

TouchID also is problematic if you're wearing gloves, which people who don't live in San Francisco do during non-trivial portions of the year.

> TouchID also is problematic if you're wearing gloves

And the touchscreen?

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#83
post #73

Earlier quoted context omitted.

Which is why it's nice that none of the biometric auths can be used without also having a PIN for backup auth. And also why it's nice that you can disable biometrics entirely.

The comment was aimed at the Snowden example. If Snowden thought his pin was compromised he could always change his pin, but once his face is compromised what does he doe?

not use faceID?

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#84

you can change your pin. you can't change your face.

That breaks both ways: only a fairly advanced attacker could "change their face" to access your phone. So Face ID still covers the 99% of cases Troy talks about. For the rest, I'm not sure a PIN works, either, so they'd have to use a password.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#85
post #32

It would be interesting if we could specify a particular face pattern to unlock the phone. Imagine you set up your phone to open only if you smile, now if someone picks up your phone and try to unlock it by pointing it at your face, not smiling would be easier than closing your eyes or looking away. Not even mentioning the health benefit of just smiling :)

They mentioned that it won't unlock if your eyes are closed or you are looking away. Doesn't help in a carjacking scenario, I guess.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#88
post #50

Earlier quoted context omitted.

TouchID also is problematic if you're wearing gloves, which people who don't live in San Francisco do during non-trivial portions of the year.

> TouchID also is problematic if you're wearing gloves And the touchscreen?

There are plenty of gloves designed to work with capacitative touchscreens (small wire mesh in the fingertips) but none that let you use TouchID.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#89

Earlier quoted context omitted.

> Face ID feels awkward Have you used it?

But wht was wrong with TouchID ? Were there any examples of it being weak security. What will be after Touch ID? Will Apple continue progress and built in PinchID - a tiny needle that sting you to test if you are you based on your blood/DNA? This is a serious question. Because of there was noting wrong with Touch then why is it removed from new phone and replaced with Face ID. Im also concerned about the data Apple w…

Not everybody has fingerprints. I may be the minority here, but I look forward to not having to enter my pin each time.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#90
post #73

Earlier quoted context omitted.

Which is why it's nice that none of the biometric auths can be used without also having a PIN for backup auth. And also why it's nice that you can disable biometrics entirely.

The comment was aimed at the Snowden example. If Snowden thought his pin was compromised he could always change his pin, but once his face is compromised what does he doe?

This entire article was explicitly written to address this line of thinking, and IMO does so very well.
Post reply on HN