Live data from Hacker News

Face ID, Touch ID, No ID, PINs and Pragmatic Security

troyhunt.com

271–280 of 314 posts

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#271
post #197

Earlier quoted context omitted.

Before TouchID, I set my passcode to 0000 with a four-hour window where I didn't have to reenter it. I only had one set at all because Find My Friends refused to keep me logged in unless I had a passcode set. With TouchID, I have a complex passcode that I have to enter a couple times a week. It's less secure than some hypothetical setup where I have a complex passcode I have to enter every time I unlock the phone, bu…

My android phone forces me to re-enter my passcode every 24 hours. I think that strikes a nice security median. If someone does get procession of my phone, I only need to stall for less than 24 hours. The rest of the time, the fingerprint scanner works near perfectly. It's actually faster to use the fingerprint scanner than the standard slide to unlock, which is all I ever had setup on my previous phones.

iOS does the same after 48 hours of not being unlocked or re-authorized. I agree that this seems like a decent security compromise. Anyone with physical access to your phone for more than 48 hours has other vectors to pursue that are far easier than just trying to guess your password.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#272
post #181

Earlier quoted context omitted.

I'm sure it's not 100%, but I'd bet it's close. Certainly by young adulthood the identical twins I've been around have been relatively easy to distinguish.

That's sort of my theory. But I wonder how much of people's ability to distinguish identical twins is based on physical differences vs more subtle things like how they carry themselves/interact with the world.

Some twins I've known deliberately create physical differences like different hairstyle so other people can recognize them easily without interactions.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#273
post #217
post #177

> ...when you do use the biometric options we're about to get into, you're still going to need [a pin] on your phone anyway. For example, every time you hard-reboot an iPhone with Touch ID you need to enter the PIN This is what has been missing from every discussion of this issue that I've seen so far. The face scan isn't "insecure" even if you're worried about border searches. Just turn off your phone when you get i…

I don't want to be that 'if you've got nothing to hide then' guy but why are people so worried about what border agents in particular will see on their cell phone? I am not saying that I wouldn't mind at all if my phone was searched. But I can't think of anything in particular that I would be concerned about if it was. Sure in theory the agent could remember some personal information and come back later and use that…

There's lots of stuff I'd rather not be seen by strangers. Love notes to/from my wife, love notes to/from my mistress, photos of myself or others that I'd rather not be seen by strangers, financial information (through online banking apps, etc), just to name a few.

How do I know the agent isn't downloading the naked pictures of my wife? (There are lots of reasons to not keep such pictures on my phone, but "Because border agents may see them" should not be one of them)

And there's just the futility of it -- if I really had something to hide from the government, I wouldn't keep it on my phone (or if I did, I'd keep it hidden).

the actual harm is more mental in nature.

That doesn't make it any less real - the government should not make me feel violated.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#274
post #263

Earlier quoted context omitted.

Customs can do that anyway if you have a password.

> Customs can do that anyway if you have a password. Allow me to repeat myself, If you can't lock yourself out, it's not secure. For example, some banks have time locks. Nobody gets into the vault, unless it is in a certain window of time.

>If you can't lock yourself out, it's not secure.

It's not secure if you can lock yourself out either.

A court could hold you in contempt for failing to unlock or intently locking.

And a state actor or even mugger could just hurt you or even kill you, in frustration if you don't open it for them.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#275
post #217
post #177

> ...when you do use the biometric options we're about to get into, you're still going to need [a pin] on your phone anyway. For example, every time you hard-reboot an iPhone with Touch ID you need to enter the PIN This is what has been missing from every discussion of this issue that I've seen so far. The face scan isn't "insecure" even if you're worried about border searches. Just turn off your phone when you get i…

I don't want to be that 'if you've got nothing to hide then' guy but why are people so worried about what border agents in particular will see on their cell phone? I am not saying that I wouldn't mind at all if my phone was searched. But I can't think of anything in particular that I would be concerned about if it was. Sure in theory the agent could remember some personal information and come back later and use that…

What I worry about is Google Authenticator codes for several financial institutions, getting vacuumed out of the phone with everything else and stored on some insufficiently-secured database.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#276

Earlier quoted context omitted.

Customs can do that anyway if you have a password.

Constitutionally, an individual can not be forced to enter a password for law enforcement (including customs agents).

That would be comforting if both (a) and (b) were true:

(a) the world was only US citizens.

(b) nothing unconstitutional ever happened to the first group.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#277

Earlier quoted context omitted.

That's the point, "constitutionally" while they lock you up for hours/days on end to obtain the warrant needed to give up your password unless you are willing to stay locked up.

Get that sweet settlement for wrongful imprisonment.

Or, you know, no settlement, and not even a "sorry, oops" either.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#278
post #205
post #177

> ...when you do use the biometric options we're about to get into, you're still going to need [a pin] on your phone anyway. For example, every time you hard-reboot an iPhone with Touch ID you need to enter the PIN This is what has been missing from every discussion of this issue that I've seen so far. The face scan isn't "insecure" even if you're worried about border searches. Just turn off your phone when you get i…

> The face scan isn't "insecure" even if you're worried about border searches. Just turn off your phone when you get in the security line! Pin will be required on start. As far as border searches go, border officers have the authority to request your PIN just as they have the authority to request your thumbprint/faceprint/etc. If you don't give it to them, you can be detained and/or your phone confiscated [1]. Reboot…

You know what would be really neat? A different, restricted/camouflaged unlock when you make a slight facial expression that would probably go unnoticed.

regular face: regular unlock right eyebrow raised a tiny bit: hide my sensitive stuff from a casual search*

*and after a few minutes, if I don't deactivate it, start deleting.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#279
post #217
post #177

> ...when you do use the biometric options we're about to get into, you're still going to need [a pin] on your phone anyway. For example, every time you hard-reboot an iPhone with Touch ID you need to enter the PIN This is what has been missing from every discussion of this issue that I've seen so far. The face scan isn't "insecure" even if you're worried about border searches. Just turn off your phone when you get i…

I don't want to be that 'if you've got nothing to hide then' guy but why are people so worried about what border agents in particular will see on their cell phone? I am not saying that I wouldn't mind at all if my phone was searched. But I can't think of anything in particular that I would be concerned about if it was. Sure in theory the agent could remember some personal information and come back later and use that…

Do you have any work data or email on your device? What is your employer's policy about granting 3rd parties access to such data? Could you be fired for doing so?

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#280
post #194

Earlier quoted context omitted.

I'm calling it that Touch ID will make a comeback: https://twitter.com/ernsheong/status/908018119595003904 How bout: Touch ID + Face ID. Hahaa

I'm not sure that Touch ID can come back in its current form. Phil stood on stage and told us Touch ID is 50,000 secure and Face ID is 1,000,000 secure. I think the only way for Touch ID to come back is for it to cover the whole display, so it can authenticate every touch.

> I think the only way for Touch ID to come back is for it to cover the whole display, so it can authenticate every touch.

Touch ID only works on the first try about half the time for me, I would love to bring that experience to all my interactions with my phone.

Post reply on HN