Live data from Hacker News

Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

techcrunch.com

21–30 of 46 posts

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#21
post #18

Serious question: why aren't we using biometrics, e.g., fingerprints or iris detection? I want authentication that: (1) identifies me, not a key-holder, and (2) requires only things that I will always have with me.

You can't change biometrics, so once someone forges your identity they will always have access to anything that requires only biometric identification.

[deleted]

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#22

Serious question: why aren't we using biometrics, e.g., fingerprints or iris detection? I want authentication that: (1) identifies me, not a key-holder, and (2) requires only things that I will always have with me.

Due to the limitations on mobile devices. Currently they have few hardware buttons, touch screen, microphone and maybe camera. Right now the options are bounded by these limitations.

Fingerprint or iris recognition would require additional hardware. Most of the customer probably would not be willing to pay extra for these. Also they might be difficult to implement well on mobile device. And the unlocking must be very easy to use and reliable.

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#23

Serious question: why aren't we using biometrics, e.g., fingerprints or iris detection? I want authentication that: (1) identifies me, not a key-holder, and (2) requires only things that I will always have with me.

I'm curious too.

Japan has had fingerprint scanners on phones for a while. E.g. http://www.nfcrumors.com/11-15-2011/fujitsu-launches-nfc-pho...

Would be a great feature to have on my iPhone.

At least in Apple's case, perhaps the problem is the added cost of the scanner combined with Apple's one-size-fits-all model (as opposed to offering different models, so fingerprint scanners only for those who need the extra security and don't mind the added cost).

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#24

Serious question: why aren't we using biometrics, e.g., fingerprints or iris detection? I want authentication that: (1) identifies me, not a key-holder, and (2) requires only things that I will always have with me.

Because biometrics is the least secure and easiest to copy method of security.

There are three types: What you know, what you have, and what you are.

What you know is the most secure in theory, but suffers from the limitation on human memory. But it can not be stolen from someone without them knowing. (Yes I know it can be stolen from a device, but that a problem in implementation and not fundamental.)

What you have is very secure - except that it's possible for it to be lost or stolen, and possibly without the person even realizing (at least not at first).

What you are is the least secure - all the detected features can be copied remotely without the person even knowing that someone copied them, and can not be changed once copied.

Biometrics sounds very secure - but is actually very very insecure.

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#25

Earlier quoted context omitted.

>Can people really not remember one secure password? Answer: No - and then you're asking to get fully compromised when the (good and secure!) password gets revealed from some service somewhere not following best practices.

No service should ever have your secure password. It should unlock your personal system, which can then remember all the (different, random, and secure) passwords or keys for any other service you use.

Your assuming the average users machine is secure. I don't think that's necessarily true. For most people, a list of common passwords stored under their keyboard is probably more secure than an encrypted file on their HDD.

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#26
post #25

Earlier quoted context omitted.

No service should ever have your secure password. It should unlock your personal system, which can then remember all the (different, random, and secure) passwords or keys for any other service you use.

Your assuming the average users machine is secure. I don't think that's necessarily true. For most people, a list of common passwords stored under their keyboard is probably more secure than an encrypted file on their HDD.

If you don't have a secure machine to enter passwords in, it doesn't matter where you store them.

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#27
A question that bugs me about these kind of locked phones: What about emergency calls?

I don't have a smartphone so I don't know how it works, but it seems from what I've seen that modern cellphones prevent people from using them for emergency calls unless they know the swipe/unlock code. Is that correct?

edit: just googled, looks like android and iphone have an 'emergency call' button on the lock screen. Fair enough.

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#28
post #27

A question that bugs me about these kind of locked phones: What about emergency calls? I don't have a smartphone so I don't know how it works, but it seems from what I've seen that modern cellphones prevent people from using them for emergency calls unless they know the swipe/unlock code. Is that correct? edit: just googled, looks like android and iphone have an 'emergency call' button on the lock screen. Fair enough…

It should be mentioned that this creates problems of its own. Toronto Police recently released their numbers, and 18% of the calls to 911 were pocket dials created by those "emergency call" buttons. We're talking hundreds of thousands of calls clogging 911 each year, each requiring the operator listen to the whole pocket dial, attempt to make contact, call back, and if no contact is possible, send a squad car to investigate.

What we've got isn't working.

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#29
post #19

I find it annoying that we're innovating different ways of doing the exact same thing: switching from completely locked to completely unlocked. I want near-instant access to a notepad for jotting down thoughts. I want more locking for reading existing notes. Still more for accessing email. I want a strong lock protecting apps related to finances. The simple lock (just to prevent pocket-dialing) should be like a slide…

One of my absolute favorite iOS features in iOS5 before I switched to Android was the new "take a photo from the lock screen" button. I felt understood when they added that.

It's something they borrowed from Windows Phone 7, which has allowed you instant access to the camera (albeit via a mandated hardware button) while the phone is locked.

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#30
post #19

I find it annoying that we're innovating different ways of doing the exact same thing: switching from completely locked to completely unlocked. I want near-instant access to a notepad for jotting down thoughts. I want more locking for reading existing notes. Still more for accessing email. I want a strong lock protecting apps related to finances. The simple lock (just to prevent pocket-dialing) should be like a slide…

One of my absolute favorite iOS features in iOS5 before I switched to Android was the new "take a photo from the lock screen" button. I felt understood when they added that.

Is it just me that press the home button three times everytime I want the camera icon to appear? The first press is because that's how I do it all the time and then I remind myself that it actually takes two presses to make the icon appear. By the time I actually manage to make the camera appear whatever I wanted to shoot is usually gone. I really want an hardware camera button like on Lumia.
Post reply on HN