You can change a password but you can't change your fingerprint / palm / etc. Am I missing something? How is Face / Touch ID more secure that user + pass? What happens when biometric data is leaked?
Face ID and Touch ID for the Web
101–110 of 371 posts
Re: Face ID and Touch ID for the Web
#102Re: Face ID and Touch ID for the Web
#103Earlier quoted context omitted.
That doesn't make sense. Username + Password is a cumbersome workaround because (so far) machines couldn't use biometrics to authenticate a user. Now they can, so we can let go of that very problematic and often insecure model. Think like this, when you go to visit your grandmother and knock on her door you don't have to provide a password. You don't have to provide anything, because the human brain is capable of det…
Biometrics fails every test for a password. 1) A password is secret 2) You don't leave copies of it lying around everywhere 3) You can change it periodically 4) If discovered, it can't be traced back to you No, biometrics can only be a username. It can never be an acceptable password.
If your view of fingerprint auth is "a picture of your face is the password" then of course it sounds stupid. It's actually "a face with the correct features attached to an alive human" which is much harder to fake.
The whole point of biometric auth and all the advancements in the industry are about correctly identifying alive humans and the strength of any system that uses biometrics is directly related to that. You can say current systems aren't good enough at this yet for your personal thread models but it's real security, and beats the hell out of a 4/5 digit lock screen passcode.
Re: Face ID and Touch ID for the Web
#104Has anybody ever thought about how Face ID is pretty much a backdoor into your iPhone? Think back a few years to when Apple refused to open a felon's iPhone for the US government, because "they couldn't." If that happened now, they wouldn't even have to ask Apple, given the felon has Face ID enabled. Edit: I'm kind of surprised by the downvotes, given I thought HN was pretty big on personal privacy. Just thought I'd…
The main alternative to biometric ID is a PIN. Those are seldomly changed, and are relatively easily shoulder-surfed. I've seen children who can't even read yet learn their parent's iPad PINs. If you're afraid of the police, surveillance needs to be your threat model.
There's some ways to prevent being forced to use face unlock if you see it coming, by squeezing your phone: https://www.macworld.com/article/3236793/how-to-quickly-and-...
Re: Face ID and Touch ID for the Web
#105It's not supported by mobile or desktop Safari?
Re: Face ID and Touch ID for the Web
#106Has anybody ever thought about how Face ID is pretty much a backdoor into your iPhone? Think back a few years to when Apple refused to open a felon's iPhone for the US government, because "they couldn't." If that happened now, they wouldn't even have to ask Apple, given the felon has Face ID enabled. Edit: I'm kind of surprised by the downvotes, given I thought HN was pretty big on personal privacy. Just thought I'd…
Re: Face ID and Touch ID for the Web
#107Re: Face ID and Touch ID for the Web
#108You can change a password but you can't change your fingerprint / palm / etc. Am I missing something? How is Face / Touch ID more secure that user + pass? What happens when biometric data is leaked?
Like when someone takes your picture? Nothing.
Re: Face ID and Touch ID for the Web
#109So happy Apple decided to go with an open standard here rather than something proprietary. This is good news for the FIDO2 ecosystem and I hope this leads to far greater support for FIDO2 authenticators of all types. There is another world in which Apple just pushed 'Sign in with Apple' and created yet another federated identity provider rather than true, 'secure element'-based FIDO2 authentication.
"Sign in with Apple" requires a developer account with Apple. Having saw Epic's developer account terminated by Apple, I would definitely stay away from any "Sign in with Apple". (FWIW, the only 2fa with "Sign in with Apple", if you don't own any Apple hardware, is SMS.)
As a developer, I use my preferences as a user to steer my choices, but recognize that the world doesn't revolve around Apple so would allow other options.
> Having saw Epic's developer account t...
Since I have zero need to deliberately violate Apple's App Story policy, I don't worry about this overmuch.
Re: Face ID and Touch ID for the Web
#110Earlier quoted context omitted.
"Sign in with Apple" requires a developer account with Apple. Having saw Epic's developer account terminated by Apple, I would definitely stay away from any "Sign in with Apple". (FWIW, the only 2fa with "Sign in with Apple", if you don't own any Apple hardware, is SMS.)
> I would definitely stay away from any "Sign in with Apple". I would stay away from any "Sign in with.." service as a user and as a product owner. You're affectively giving away a major control of your users to a third party.
You may also get users that you wouldn't have otherwise. It's a trade-off. Lowering friction tends to increase conversions.