Earlier quoted context omitted.
It sounds like fpgaminer's argument is that biometric keys can't be compromised because of "liveness tests". An argument against would have to rebut this assumption. My gut instinct tells me that this assumption is absurd, but I lack the specific knowledge of these systems to prove it.
> It sounds like fpgaminer's argument is that biometric keys can't be compromised because of "liveness tests". You're arrested, and the cops hold the phone up to your face to unlock it. That's a pretty big compromise, and there's literally nothing you can do to prevent it.
FaceID Security [pdf]
131–140 of 314 posts
Re: FaceID Security [pdf]
#132Earlier quoted context omitted.
That sounds like a cool feature, but probably applicable to 0.0001% of the population. Think of all the work app developers would need to do to make their app "duress compatible" in the very rare chance someone is being held at gunpoint and the person is asking to see their emails.
Not to mention incredibly difficult to pull off. It isn't like having two passwords, one distress password and one normal. An algorithm that needs to identify your face in any situation AND detect subtle characteristics? I don't see that being a reality with our current technology. Or at least without significant false positives. Though a two password feature would be nice and easy to implement.
Re: FaceID Security [pdf]
#133The problem I have is with the lack of TouchID. FaceID is fine. But, I don't always want to have to stop what I'm doing, loooook at the phone and then proceed. Sometimes I even unlock my phone in my pocket to sneak a look. How do you do that with FaceID when the sensor's been removed?
It's usually notifications for me and that's what I've been using my Apple Watch for a bit over a year now.
If it's not notifications, then it gets more complicated though looking at anything but notifications is pretty hard to sneak.
Re: FaceID Security [pdf]
#134Biometrics are UID's - not passcodes.
I agree with you, but features like this are often the difference have some (decent) security and none at all. Consider the iPhone prior to TouchID. A lot of people used trivial passcodes, or no passcodes at all.
I know people who consider TouchID too much of a hassle.
This doesn’t need to be a perfect solution, it just needs to be more secure than TouchID (claimed) and more secure than nothing (obviously) while being easy enough people won’t turn it off (we’ll see).
Re: FaceID Security [pdf]
#135I still wish it had an "unlock under duress" mode, where you could authenticate with a subtle difference (different gaze, alternate passcode, etc). The phone would unlock itself but then signal back to the mothership, cloud services and even apps that it's in "duress mode". Display in that mode should look totally normal, just some of the information missing (e.g. emails/messages/contacts from certain groups of conta…
> I still wish it had an "unlock under duress" mode The practical applications of this are close to nil. The government will not be fooled for one second because they can cross reference enough sources to know if you are lying. All this will do is get you slapped with a felony: https://www.popehat.com/2011/03/18/just-a-friendly-reminder-... If it is a criminal instead, well, they don't have to tiptoe around moral, et…
The idea of using them as secure devices should probably stop, at least until they are actually secure. Moreover, if you're committing crimes, maybe don't record them in a way that is recoverable. Not that you should necessarily be a criminal but, if you're going to be a criminal, you should probably be a safe criminal.
Don't text me saying you need a G for the yayo. The cops know what that means.
Re: FaceID Security [pdf]
#136Earlier quoted context omitted.
It sounds like fpgaminer's argument is that biometric keys can't be compromised because of "liveness tests". An argument against would have to rebut this assumption. My gut instinct tells me that this assumption is absurd, but I lack the specific knowledge of these systems to prove it.
> It sounds like fpgaminer's argument is that biometric keys can't be compromised because of "liveness tests". You're arrested, and the cops hold the phone up to your face to unlock it. That's a pretty big compromise, and there's literally nothing you can do to prevent it.
If you're arrested then the cops can tie you, grab the keys and unlock your door "and there's literally nothing you can do to prevent it.".
Also some guy can just make a copy your key (pretty trivial) -- heck people can even break your door bypassing the key altogether.
Re: FaceID Security [pdf]
#137Earlier quoted context omitted.
It sounds like fpgaminer's argument is that biometric keys can't be compromised because of "liveness tests". An argument against would have to rebut this assumption. My gut instinct tells me that this assumption is absurd, but I lack the specific knowledge of these systems to prove it.
> It sounds like fpgaminer's argument is that biometric keys can't be compromised because of "liveness tests". You're arrested, and the cops hold the phone up to your face to unlock it. That's a pretty big compromise, and there's literally nothing you can do to prevent it.
Re: FaceID Security [pdf]
#138I was really unhappy about FaceID last week, but if the attention sensing tech works reliably, I think it's probably better --- including under duress --- than TouchID.
Re: FaceID Security [pdf]
#139Earlier quoted context omitted.
> It sounds like fpgaminer's argument is that biometric keys can't be compromised because of "liveness tests". You're arrested, and the cops hold the phone up to your face to unlock it. That's a pretty big compromise, and there's literally nothing you can do to prevent it.
The same holds true for physical keys. If you're arrested then the cops can tie you, grab the keys and unlock your door "and there's literally nothing you can do to prevent it.". Also some guy can just make a copy your key (pretty trivial) -- heck people can even break your door bypassing the key altogether.
Nobody's saying that home security is good. The point the parent was making is that, even with a "liveness test", compared to other biometric identification, this is a regression from fingerprint-based authentication for the iPhone.
Re: FaceID Security [pdf]
#140I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…