Live data from Hacker News

Face ID and Touch ID for the Web

webkit.org

101–110 of 371 posts

Re: Face ID and Touch ID for the Web

#101
post #77

You can change a password but you can't change your fingerprint / palm / etc. Am I missing something? How is Face / Touch ID more secure that user + pass? What happens when biometric data is leaked?

Biometric data is never leaked because it never leaves the secure enclave in the device.

Re: Face ID and Touch ID for the Web

#103

Earlier quoted context omitted.

That doesn't make sense. Username + Password is a cumbersome workaround because (so far) machines couldn't use biometrics to authenticate a user. Now they can, so we can let go of that very problematic and often insecure model. Think like this, when you go to visit your grandmother and knock on her door you don't have to provide a password. You don't have to provide anything, because the human brain is capable of det…

Biometrics fails every test for a password. 1) A password is secret 2) You don't leave copies of it lying around everywhere 3) You can change it periodically 4) If discovered, it can't be traced back to you No, biometrics can only be a username. It can never be an acceptable password.

You're missing the point of biometrics. Something you are is a form of authentication that only you can use. Your face, fingerprints, blood, retinas are all public but try as you might you can't make another living human with the same features.

If your view of fingerprint auth is "a picture of your face is the password" then of course it sounds stupid. It's actually "a face with the correct features attached to an alive human" which is much harder to fake.

The whole point of biometric auth and all the advancements in the industry are about correctly identifying alive humans and the strength of any system that uses biometrics is directly related to that. You can say current systems aren't good enough at this yet for your personal thread models but it's real security, and beats the hell out of a 4/5 digit lock screen passcode.

Re: Face ID and Touch ID for the Web

#104
post #58

Has anybody ever thought about how Face ID is pretty much a backdoor into your iPhone? Think back a few years to when Apple refused to open a felon's iPhone for the US government, because "they couldn't." If that happened now, they wouldn't even have to ask Apple, given the felon has Face ID enabled. Edit: I'm kind of surprised by the downvotes, given I thought HN was pretty big on personal privacy. Just thought I'd…

The risks of forced unlocking with FaceID have been discussed, including in court: https://appleinsider.com/articles/19/01/14/face-id-touch-id-...

The main alternative to biometric ID is a PIN. Those are seldomly changed, and are relatively easily shoulder-surfed. I've seen children who can't even read yet learn their parent's iPad PINs. If you're afraid of the police, surveillance needs to be your threat model.

There's some ways to prevent being forced to use face unlock if you see it coming, by squeezing your phone: https://www.macworld.com/article/3236793/how-to-quickly-and-...

Re: Face ID and Touch ID for the Web

#106
post #58

Has anybody ever thought about how Face ID is pretty much a backdoor into your iPhone? Think back a few years to when Apple refused to open a felon's iPhone for the US government, because "they couldn't." If that happened now, they wouldn't even have to ask Apple, given the felon has Face ID enabled. Edit: I'm kind of surprised by the downvotes, given I thought HN was pretty big on personal privacy. Just thought I'd…

The fingerprint sensor found on most phones doesn't always require intent, either.

Re: Face ID and Touch ID for the Web

#108
post #77

You can change a password but you can't change your fingerprint / palm / etc. Am I missing something? How is Face / Touch ID more secure that user + pass? What happens when biometric data is leaked?

> What happens when biometric data is leaked?

Like when someone takes your picture? Nothing.

Re: Face ID and Touch ID for the Web

#109
post #33
post #13

So happy Apple decided to go with an open standard here rather than something proprietary. This is good news for the FIDO2 ecosystem and I hope this leads to far greater support for FIDO2 authenticators of all types. There is another world in which Apple just pushed 'Sign in with Apple' and created yet another federated identity provider rather than true, 'secure element'-based FIDO2 authentication.

"Sign in with Apple" requires a developer account with Apple. Having saw Epic's developer account terminated by Apple, I would definitely stay away from any "Sign in with Apple". (FWIW, the only 2fa with "Sign in with Apple", if you don't own any Apple hardware, is SMS.)

As a user I would prefer no account in most cases. As a distant second, I would prefer the convenience, security, and privacy of Sign in with Apple over Google, Facebook, or the headache of managing yet another web account.

As a developer, I use my preferences as a user to steer my choices, but recognize that the world doesn't revolve around Apple so would allow other options.

> Having saw Epic's developer account t...

Since I have zero need to deliberately violate Apple's App Story policy, I don't worry about this overmuch.

Re: Face ID and Touch ID for the Web

#110
post #50
post #33

Earlier quoted context omitted.

"Sign in with Apple" requires a developer account with Apple. Having saw Epic's developer account terminated by Apple, I would definitely stay away from any "Sign in with Apple". (FWIW, the only 2fa with "Sign in with Apple", if you don't own any Apple hardware, is SMS.)

> I would definitely stay away from any "Sign in with Apple". I would stay away from any "Sign in with.." service as a user and as a product owner. You're affectively giving away a major control of your users to a third party.

> You're affectively giving away a major control of your users to a third party.

You may also get users that you wouldn't have otherwise. It's a trade-off. Lowering friction tends to increase conversions.

Post reply on HN