Live data from Hacker News

Face ID, Touch ID, No ID, PINs and Pragmatic Security

troyhunt.com

121–130 of 314 posts

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#121

Earlier quoted context omitted.

TouchID was removed because it took up space on the front of the phone and Apple wanted the screen to be bigger. There's no deeper reason than that. > Will Apple continue progress and built in PinchID - a tiny needle that sting you to test if you are you based on your blood/DNA? I struggle to believe you when you say that's a serious question... > Im also concerned about the data Apple will collect. The FaceID data w…

TouchID is trivially defeated by a 6-year-old: https://www.usatoday.com/story/news/nation/2016/12/28/girl-u...

Did you read the article? Troy Hunt addressed that.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#122
post #116

1 in 1 million FAR (false acceptance rate) vs 1 in 50,000 is pretty misleading (as is Apple tradition). Do you think someone trying to hack into your phone would shoot 1 million random pictures/3D profiles made from Facebook pictures at your phone, or do you think it's far more likely they will already start with your profile made from online pictures? That will likely make the success rate even higher than with fing…

Do you have a better metric? The author suggested it wasn't the best way to measure it but I'm not sure what would be better.

"Most face unlock systems" is the point of Face ID. It's now most systems. It's supposed to fix those weaknesses.

(We'll find out for sure when it's in people's hands)

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#123
post #116

1 in 1 million FAR (false acceptance rate) vs 1 in 50,000 is pretty misleading (as is Apple tradition). Do you think someone trying to hack into your phone would shoot 1 million random pictures/3D profiles made from Facebook pictures at your phone, or do you think it's far more likely they will already start with your profile made from online pictures? That will likely make the success rate even higher than with fing…

Per Apple Face ID doesn't work with photos; TBD in real world.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#125

Nice article. However: > It's alarming not just because the number is so low, but because Dropbox holds such valuable information for so many people. I'd suggest that Dropbox users somewhat self select for those not as concerned about security as others. And more concerned about availability. Dropbox does not encrypt your data server side (or at the very least, can easily decrypt it). And they have proponents of warr…

> Dropbox does not encrypt your data server side (or at the very least, can easily decrypt it). I think claims like this need to be backed up. Now, obviously a biased source, but Dropbox itself says this: "Each file is split into discrete blocks, which are encrypted using a strong cipher. Only blocks that have been modified are synced. Each individual encrypted file block is retrieved based on its hash value, and an…

It does sound like they can easily decrypt the data, since they have the keys.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#126
post #114

Earlier quoted context omitted.

I want this, and also the ability to secure different areas of my phone. I want to be able to set touch or PINs for certain apps, so that I can have multi level security. Why is there so much emphasis on one master password/touch ID/face ID instead of having multiple security checks?

All of my banking apps, among others (e.g. password manager), include options for both pin and touchID auth. Do we not already have what you’re asking for?

I think he's requesting it on the system level. For example, if iOS allowed you to force PIN+TID when opening a specific (not necessarily secure) app for the first time after an unlock. Intended for apps that don't necessarily have security built in already.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#127

Earlier quoted context omitted.

But wht was wrong with TouchID ? Were there any examples of it being weak security. What will be after Touch ID? Will Apple continue progress and built in PinchID - a tiny needle that sting you to test if you are you based on your blood/DNA? This is a serious question. Because of there was noting wrong with Touch then why is it removed from new phone and replaced with Face ID. Im also concerned about the data Apple w…

Not everybody has fingerprints. I may be the minority here, but I look forward to not having to enter my pin each time.

There are more people who cover their face (e.g. Muslim women wearing burkas) than people who don't have fingerprints. I wish they had both TouchID and FaceID.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#128
post #116

1 in 1 million FAR (false acceptance rate) vs 1 in 50,000 is pretty misleading (as is Apple tradition). Do you think someone trying to hack into your phone would shoot 1 million random pictures/3D profiles made from Facebook pictures at your phone, or do you think it's far more likely they will already start with your profile made from online pictures? That will likely make the success rate even higher than with fing…

If you look any of the information on Face ID you'll see it has 3D mapping via a "Kinect-like"/"RealSense-like" IR dot projector.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#129
post #101

Stolen iPhones should be worthless. Apple need to create a system where stolen phones can be reported to them, Apple can then contact the owner/verify they are stolen. And then add them to a stolen list and disable calling/apps on those phones. And display an overlay on the screen THIS PHONE IS STOLEN. Every iphone would come with an validate phone feature that is accessible even when locked that can authenticate the…

Find My iPhone has a feature called Activation Lock which matches up with what you're describing: https://support.apple.com/en-us/HT201365

The phone won't do anything until the person who turned on the lock turns it off again.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#130

Earlier quoted context omitted.

I have tech knowledge, but I had absolutely no knowledge that Dropbox offered 2-factor. I don't keep confidential stuff in DB because, I know that the company effectively has access to everything. Nonetheless, 2 factor sounds interesting. So I look at this: https://www.dropbox.com/help/security/enable-two-step-verifi... Right. Now I understand why so few people have it enabled.

Explain? You read a page about two-step and say that explains why no one has enabled it? You claim to have tech knowledge, but are not able to turn on this simple security setting (or even know it exists, despite that it's listed very clearly in your Dropbox settings page)? I use two-factor/two-step verification on every single service I have, including all social media accounts, email accounts, etc. Most major servi…

> You claim to have tech knowledge, but are not able to turn on this simple security setting

GP didn't say _they_ can't enable it after reading the help page. I think they are implying that the very detailed help page looks long and complicated to a non-techie (who might not even understand the benefit of going through such a hurdle in the first place).

Post reply on HN