Live data from Hacker News

Face ID, Touch ID, No ID, PINs and Pragmatic Security

troyhunt.com

111–120 of 314 posts

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#111
post #74

Earlier quoted context omitted.

TouchID was removed because it took up space on the front of the phone and Apple wanted the screen to be bigger. There's no deeper reason than that. > Will Apple continue progress and built in PinchID - a tiny needle that sting you to test if you are you based on your blood/DNA? I struggle to believe you when you say that's a serious question... > Im also concerned about the data Apple will collect. The FaceID data w…

> TouchID was removed because it took up space on the front of the phone and Apple wanted the screen to be bigger. There's no deeper reason than that. The Pixel handset has the fingerprint sensor on the back of the phone. It appears to work quite well. Much of this needless outrage could be obviated by allowing multiple simultaneous biometrics for auth; while taking the phone out of your pocket, place your finger on…

> multiple simultaneous biometrics

That's very un-Apple.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#112
post #39
post #30

Earlier quoted context omitted.

> I'd suggest that Dropbox users somewhat self select for those not as concerned about security as others. And more concerned about availability. I would rather say that Dropbox is being used by many people without tech knowledge. And while they might be concerned about security, they often just don't know how improtant 2 factor authentication is. At least that's what I can see for some friends & family.

eeh, since when does u2a protect against back-end breaches? thats just a security layer against phishing or password leaks... don't get me wrong, i'd advice everyone to use it for anything remotely critical, because its pretty easy to setup and live with, but it really doesnt help against state actors or hackers that compromised the data servers.

> since when does u2a protect against back-end breaches?

It doesn't have to. For 99.999% people, the two most realistic threats are:

* There is a keylogger on some computer where you access your Dropbox, for example at a print shop, * You use the same password on many sites, one gets compromised, and automated bots try to access your Dropbox account.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#113
post #101

Stolen iPhones should be worthless. Apple need to create a system where stolen phones can be reported to them, Apple can then contact the owner/verify they are stolen. And then add them to a stolen list and disable calling/apps on those phones. And display an overlay on the screen THIS PHONE IS STOLEN. Every iphone would come with an validate phone feature that is accessible even when locked that can authenticate the…

I'm guessing they are still useful for parts though? Screens, batteries, cameras....all of that still works even if the motherboard is disabled.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#114
post #94

Given that the authentication methods are "differently secure," wouldn't it be good if we were offered the option to combine them and require both for unlock? I would love to use Face ID + PIN or Touch ID + PIN for better security.

I want this, and also the ability to secure different areas of my phone. I want to be able to set touch or PINs for certain apps, so that I can have multi level security. Why is there so much emphasis on one master password/touch ID/face ID instead of having multiple security checks?

All of my banking apps, among others (e.g. password manager), include options for both pin and touchID auth. Do we not already have what you’re asking for?

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#115
post #95

Earlier quoted context omitted.

It would be awkward to smile/pose before/after a funeral, just because I need to call my mum or check my email... That being said, I do think that there could be a legitimate use case here. One could set up a particular "emotion" (a face pattern) associated with someone forcing them to unlock a phone using their face. I mean, if someone pulls a gun or a knife on me, I'll probably just do as they say and look at the p…

y, if someone has a knife or gun I would just give them what they want and worry about a distress call after you're safe instead of getting fancy trying to activate an 'I'm being mugged' feature. I think that could be a nice feature but would add stress to the situation when you should just be focussed on staying alive trying to remember how to do that special thing or enter an alternate code.

I'm thinking of a situation when the phone, for example, is not enough for them. What if the don't leave you alone after that? What if you're a girl and they are going to try to rape you? What I'm thinking of is not about a "fancy" help-me-I'm-being-mugged "duck-face" pose, but actually a face pattern which, simple enough, could offer assistance in a difficult situation. What if they take away the phone and I'm left with no change of calling for an ambulance?

You are right, though, that this requires some "friction" and probably some self control.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#116
1 in 1 million FAR (false acceptance rate) vs 1 in 50,000 is pretty misleading (as is Apple tradition).

Do you think someone trying to hack into your phone would shoot 1 million random pictures/3D profiles made from Facebook pictures at your phone, or do you think it's far more likely they will already start with your profile made from online pictures?

That will likely make the success rate even higher than with fingerprints, as it's significantly easier to get someone's photos than it is to get their fingerprints.

> Laughs were had, jokes were made but the underlying message was that Face ID isn't foolproof. Just like Touch ID. And PINs.

No, not "just like". There is a huge difference between most fingerprint authentication mechanisms and most face unlock mechanisms (at least so far). Most of them could be tricked with a 2D picture - including Samsung's latest. It's very annoying to see such a statement from someone like Troy Hunt. Plus, I have a hunch he'll be eating many of the words he wrote in a few weeks when Face ID will prove much easier to hack than Apple made everyone believe it will be.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#118

Near-field worn devices. http://nfcring.com is an example of what I have in mind. What I'd like to see is this tied into an identity system, such that the ring (or other very-hard-to-misplace, but replaceable and discardable) token is not itself an identity, but rather an access token to an identity store which can present any given identity to any given system. That might be a consistent identity across multiple ses…

Eh. For me having smart unlock attached to my watch works. Sure, the range is farther than with nfc, but it's acceptable to me.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#119
Would be interesting to enable voice authentication contemporaneous with face scanning to make sure the lipreading matched the utterance matches the voiceprint matches the expected face. Bonus points that a vocal channel could be used to detect duress (especially if accompanied by, say, raised eyebrows) and either require further authentication (passphrase entry) or a "false unlock" to reveal only a nearly factory fresh app and data underlying. Could also potentially send a notification to friends that your phone had just been unlocked under duress. Bonus points for in parallel hard-scrubbing the underlying true data while displaying the false boring phone interface.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#120
post #94

Given that the authentication methods are "differently secure," wouldn't it be good if we were offered the option to combine them and require both for unlock? I would love to use Face ID + PIN or Touch ID + PIN for better security.

I want this, and also the ability to secure different areas of my phone. I want to be able to set touch or PINs for certain apps, so that I can have multi level security. Why is there so much emphasis on one master password/touch ID/face ID instead of having multiple security checks?

You can do this on iPhone kinda. I have it so that I can reply to text messages from the lock screen, but to view or reply to emails I have to log in. Not perfect but that works at least.
Post reply on HN