Earlier quoted context omitted.
> It doesn't activate unless you look at the lock screen, so you can just refuse to look at it? Have you ever been detained? As far as I'm concerned, "refuse to look at it" is useful as a prevention tactic as not having any lock at all.
By that metric it is just as useful as "I won't give you my password" and "I won't touch the phone" https://xkcd.com/538/
FaceID Security [pdf]
171–180 of 314 posts
Re: FaceID Security [pdf]
#172Earlier quoted context omitted.
You can't replace your face. Are you suggesting that people turn it off until it's secure again meaning, like, plastic surgery?
You can't!? Wow, thanks for teaching me that. Did you even read what I wrote? You would turn off FaceID and revert back to a passcode/passphrase until it is fixed in software.
Re: FaceID Security [pdf]
#173Earlier quoted context omitted.
It all depends on your threat model. Police are perfectly capable of breaking into my home, but it doesn't matter, because if they do it without a warrant everything they find is inadmissible in court. Whereas with FaceID, if I'm arrested and they point my phone at my face to unlock it against my will, anything they find is now admissible as evidence.
I keep hoping that FaceID will also get FacePassword, where you have to show one or more expressions in order. Then it becomes a password, and the police can't force you to change your expression.
Re: FaceID Security [pdf]
#174I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…
It all depends on your threat model. Police are perfectly capable of breaking into my home, but it doesn't matter, because if they do it without a warrant everything they find is inadmissible in court. Whereas with FaceID, if I'm arrested and they point my phone at my face to unlock it against my will, anything they find is now admissible as evidence.
How often do you get arrested where that edge case is a legitimate concern?
If being arrested were a legitimate concern, why would you keep data on your phone that would implicate you in a crime?
If you were in a higher risk group (i.e. a drug dealer,) why not disable Face ID? Use a six digit pin and be done with it.
I am not particularly worried about cops, I am worried about losing my phone and having some jackass using my data to fill his bank account.
Re: FaceID Security [pdf]
#175Earlier quoted context omitted.
By that metric it is just as useful as "I won't give you my password" and "I won't touch the phone" https://xkcd.com/538/
[deleted]
Re: FaceID Security [pdf]
#176I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…
And you can't build a remote identity verification with this data, because there's no way for the user to change it and revoke it (let alone it's very privacy sensitive).
The biometric access control systems (the one "in the movies", palm recognition, retina scanners...) implicitly assume that the connection between the sensor and the central server is secure, and that the user authorized it's data to be in the database. This model doesn't apply to "general users" and "internet companies".
Research in biometric security aims at finding functions of your biometric data that can be revoked and it's not privacy sensitive.
Edit: with "revoke" I don't mean remove it. I mean revoke one and set another one, like you can do for a password/pin, or for a phone number/hw device.
Re: FaceID Security [pdf]
#177Earlier quoted context omitted.
That sounds like a cool feature, but probably applicable to 0.0001% of the population. Think of all the work app developers would need to do to make their app "duress compatible" in the very rare chance someone is being held at gunpoint and the person is asking to see their emails.
If the phone allowed multiple users that might be one way to do it. Just log in to another user.
This should also be available to fingerprint readers, as the suggest "gesture" would be even easier: just use a different fingerprint (you can set the fingerprint that everyone expects you to use as the "other fingerprint", and use some other fingerprint as your default one).
It should also work with passwords, etc.
Re: FaceID Security [pdf]
#178I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…
The problem with biometrics is not username vs password, biometrics are password. The problem is that these are client-side protections, and there's no data sent to a server that can verify the identity. And you can't build a remote identity verification with this data, because there's no way for the user to change it and revoke it (let alone it's very privacy sensitive). The biometric access control systems (the one…
Re: FaceID Security [pdf]
#179I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…
Houses and cars are 1000% not secure, you can always break a window and get access. That's why they have ARMORED cars and bank VAULTS or safes.
However, if you break a window, or drill a hole in a safe, there is "visible sign of forced entry".
https://en.wikipedia.org/wiki/Forcible_entry
When you see a broken window by your front door, when you see a broken window on your car, when you see a hole cut through sheetrock next to your door, or you see your door blasted off it's hinges, you know that the security of the device has been compromised.
That's truly what's missing on device security nowadays: "Signs of Forced Entry" ... number of incorrect password attempts, number of incorrect FaceID / TouchID attempts, etc.
And if your device is rooted or untrusted, then there's often not a good, trusted, visible way to see that security has been actually compromised (as opposed to attempted to be compromised).
Re: FaceID Security [pdf]
#180Earlier quoted context omitted.
They could have put the fingerprint sensor on the back, as several Android phones do.
And they could also install a hardware keyboard. Neither of which is going to happen. Just because you can do something doesn't mean you should.
A physical keyboard on the other hand makes a phone at least twice as thick, twice as heavy, and twice as ugly (although the last one is more subjective).