Live data from Hacker News

Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

techcrunch.com

31–40 of 46 posts

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#32
post #19

I find it annoying that we're innovating different ways of doing the exact same thing: switching from completely locked to completely unlocked. I want near-instant access to a notepad for jotting down thoughts. I want more locking for reading existing notes. Still more for accessing email. I want a strong lock protecting apps related to finances. The simple lock (just to prevent pocket-dialing) should be like a slide…

One of my absolute favorite iOS features in iOS5 before I switched to Android was the new "take a photo from the lock screen" button. I felt understood when they added that.

That's one of the things I loved about my N900 when I first got it. When you slide open the shutter, you're instantly in camera mode. No waiting, no unlocking.

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#33
post #24

Serious question: why aren't we using biometrics, e.g., fingerprints or iris detection? I want authentication that: (1) identifies me, not a key-holder, and (2) requires only things that I will always have with me.

Because biometrics is the least secure and easiest to copy method of security. There are three types: What you know, what you have, and what you are. What you know is the most secure in theory, but suffers from the limitation on human memory. But it can not be stolen from someone without them knowing. (Yes I know it can be stolen from a device, but that a problem in implementation and not fundamental.) What you have…

This is completely counterintuitive to me. How are you going to remotely copy my fingerprint or iris?

Isn't the fact that scanned fingerprints are still used by immigration control and criminal investigators evidence against this?

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#34
post #23

Serious question: why aren't we using biometrics, e.g., fingerprints or iris detection? I want authentication that: (1) identifies me, not a key-holder, and (2) requires only things that I will always have with me.

I'm curious too. Japan has had fingerprint scanners on phones for a while. E.g. http://www.nfcrumors.com/11-15-2011/fujitsu-launches-nfc-pho... Would be a great feature to have on my iPhone. At least in Apple's case, perhaps the problem is the added cost of the scanner combined with Apple's one-size-fits-all model (as opposed to offering different models, so fingerprint scanners only for those who need the extra secu…

This is why I asked this question. Fingerprint scanning in Japan is so convenient.

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#35
post #18

Serious question: why aren't we using biometrics, e.g., fingerprints or iris detection? I want authentication that: (1) identifies me, not a key-holder, and (2) requires only things that I will always have with me.

You can't change biometrics, so once someone forges your identity they will always have access to anything that requires only biometric identification.

How does one forge biometrics? (Notice that I'm not asking how to spoof biometric readers with insecure designs, e.g., the one mythbusters busted).

Anyway, this is already the case – fingerprints are used as evidence of criminal liability. If someone forges my fingerprints, they could get me into a huge amount of trouble, in theory.

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#36
post #24

Earlier quoted context omitted.

Because biometrics is the least secure and easiest to copy method of security. There are three types: What you know, what you have, and what you are. What you know is the most secure in theory, but suffers from the limitation on human memory. But it can not be stolen from someone without them knowing. (Yes I know it can be stolen from a device, but that a problem in implementation and not fundamental.) What you have…

This is completely counterintuitive to me. How are you going to remotely copy my fingerprint or iris? Isn't the fact that scanned fingerprints are still used by immigration control and criminal investigators evidence against this?

Lets say someone took your fingerprints off a glass or a light-switch or your car, is there any reasonable way to prevent this?

Lets also say that you somehow become aware of them having a copy of your fingerprints and you remember that your phone requires your fingerprints to unlock; what do you do?

It's the fact that you can't permanently change your fingerprints nor restrict access to them which make them bad for authentication. Those two qualities also make them good for forensics.

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#37
post #27

A question that bugs me about these kind of locked phones: What about emergency calls? I don't have a smartphone so I don't know how it works, but it seems from what I've seen that modern cellphones prevent people from using them for emergency calls unless they know the swipe/unlock code. Is that correct? edit: just googled, looks like android and iphone have an 'emergency call' button on the lock screen. Fair enough…

It should be mentioned that this creates problems of its own. Toronto Police recently released their numbers, and 18% of the calls to 911 were pocket dials created by those "emergency call" buttons. We're talking hundreds of thousands of calls clogging 911 each year, each requiring the operator listen to the whole pocket dial, attempt to make contact, call back, and if no contact is possible, send a squad car to inve…

The Android "emergency call" button just brings up a dial pad. I can't imagine that causing many pocket dials.

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#38
post #24

Earlier quoted context omitted.

Because biometrics is the least secure and easiest to copy method of security. There are three types: What you know, what you have, and what you are. What you know is the most secure in theory, but suffers from the limitation on human memory. But it can not be stolen from someone without them knowing. (Yes I know it can be stolen from a device, but that a problem in implementation and not fundamental.) What you have…

This is completely counterintuitive to me. How are you going to remotely copy my fingerprint or iris? Isn't the fact that scanned fingerprints are still used by immigration control and criminal investigators evidence against this?

> Isn't the fact that scanned fingerprints are still used by immigration control and criminal investigators evidence against this?

Not at all - they use it for identification not authentication.

It's a completely different application.

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#39
post #18

Earlier quoted context omitted.

You can't change biometrics, so once someone forges your identity they will always have access to anything that requires only biometric identification.

How does one forge biometrics? (Notice that I'm not asking how to spoof biometric readers with insecure designs, e.g., the one mythbusters busted). Anyway, this is already the case – fingerprints are used as evidence of criminal liability. If someone forges my fingerprints, they could get me into a huge amount of trouble, in theory.

> How does one forge biometrics?

At the end of the day a finger or an iris is a physical object you can make. Since it's impossible to keep the "key" secret, you can always copy it and make one - how hard you have to work to make it depends on how good the design is, but fundamentally there is no secret and without a secret it's useless for authentication.

> If someone forges my fingerprints, they could get me into a huge amount of trouble, in theory.

Yes, they can, and sometimes they do. But it's not common enough for police to worry about it.

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#40
post #38

Earlier quoted context omitted.

This is completely counterintuitive to me. How are you going to remotely copy my fingerprint or iris? Isn't the fact that scanned fingerprints are still used by immigration control and criminal investigators evidence against this?

> Isn't the fact that scanned fingerprints are still used by immigration control and criminal investigators evidence against this? Not at all - they use it for identification not authentication. It's a completely different application.

Forgive me if this seems ignorant, but how is verifying a person's identity at immigration control different from verifying their identity when logging into their phone?
Post reply on HN