Live data from Hacker News

Fingerprints are Usernames, not Passwords

blog.dustinkirkland.com

51–60 of 261 posts

Re: Fingerprints are Usernames, not Passwords

#51
Not essential to the main thesis of the article, but still: "But let's just say you're okay with Apple sharing your fingerprints with the NSA, as I've already told you, they're not private at all."

Ok, they are not private but I'd still not willingly put them on anything controlled by an US corporation. Govt sending their agents to collect my fingerprints from glasses? Not feasible, too costly. Agency asking Apple to fetch the fingerprints willingly provided by the population "just in case"? Maybe not today and not tomorrow but in a few years? I wouldn't bet on them not doing it. And once there you're just one false positive away from some serious shit happening to you.

Re: Fingerprints are Usernames, not Passwords

#52
post #34

All these academic arguments about the security of fingerprints are interesting but completely are detached from the day-to-day use of TouchID. I've been using it for about a week or so now. It's incredibly convenient. It unlocks my phone almost instantly. It prevents random people near by phone from being unable to unlock it. If a thief got their hands on it, they'd have a few attempts to unlock it with a fake finge…

Please don't delude yourself into thinking this is any safer against the typical kind of smartphone theft. Thieves will offload the phone to someone using software explicitly designed to wipe electronics to be resold. Whether they are wiping an iphone that happens to have touch ID or not is only relevent towards the resale price once it's wiped. Clearly Apple marketing works, as it's somehow convinced a member of (I'…

An iPhone that is wiped, even in DFU mode, requires the Apple ID and password immediately after it is booted for the first time.

Basically, a stolen iPhone is only worth the sum of its parts so they can be used to repair other phones.

Re: Fingerprints are Usernames, not Passwords

#53
This article is missing its own point. Username+password combinations are nothing but an identification means. Fingerprints solve the same purpose.

The issue this article should be trying to shed light on is one of inadequate fingerprint scanners, not that fingerprints themselves are compromised. Make a scanner that requires epidermal prints, and go from there.

Re: Fingerprints are Usernames, not Passwords

#54
post #37
post #34

All these academic arguments about the security of fingerprints are interesting but completely are detached from the day-to-day use of TouchID. I've been using it for about a week or so now. It's incredibly convenient. It unlocks my phone almost instantly. It prevents random people near by phone from being unable to unlock it. If a thief got their hands on it, they'd have a few attempts to unlock it with a fake finge…

s/TouchID/Face Unlock/g and back up about 2 years and you can find all the same things said about Ice Cream Sandwich. It's a cute feature. It's not going to change the world, sell another billion phones, push other companies out of the market, or save anyone from serious attacks. It's probably a good idea to enable it anyway.

It is more difficult to defeat a touch sensor than face unlock. With face unlock, I just need a photo of the phone's owner.

With a fingerprint unlock, I need to go to at least a little trouble to fake the fingerprint.

Re: Fingerprints are Usernames, not Passwords

#55
post #34

All these academic arguments about the security of fingerprints are interesting but completely are detached from the day-to-day use of TouchID. I've been using it for about a week or so now. It's incredibly convenient. It unlocks my phone almost instantly. It prevents random people near by phone from being unable to unlock it. If a thief got their hands on it, they'd have a few attempts to unlock it with a fake finge…

And I think that's the main problem with it. People think that it's actually a true replacement for a password, even though it's not.

Re: Fingerprints are Usernames, not Passwords

#56
post #39
post #37

Earlier quoted context omitted.

s/TouchID/Face Unlock/g and back up about 2 years and you can find all the same things said about Ice Cream Sandwich. It's a cute feature. It's not going to change the world, sell another billion phones, push other companies out of the market, or save anyone from serious attacks. It's probably a good idea to enable it anyway.

I don't think you can call something a cute feature when it's turned on on most phones and is used to unlock them. I would guess that by far the majority of iPhone 5S's have TouchID enabled. I wouldn't be surprised if it's more than 90%. The feature is just that well executed.

I would be very surprised if it is that high now even with the early adopter skew. Reports say that last year it was around a quarter of smartphone users use passcode locks on their work phone (http://www.welivesecurity.com/2012/02/28/sizing-up-the-byod-...). I imagine 5S rates are higher than that, but 90% would be insanely impressive. When it comes to computer security, as usual, people's apathy is the biggest problem.

Re: Fingerprints are Usernames, not Passwords

#57
A phone screen unlock is not like passwords as used elsewhere. It has to be short; otherwise it is impractical. We know that short passwords don't have much entropy. We also know that we can examine the grease on the screen and make a good guess as to what the password is.

If we consider phone unlocking mechanisms to be in a different "not fully secure, but at least practical" category, then I think it's perfectly acceptable to use a fingerprint as an unlock.

Mitigation is possible too. For example, the phone could lock out and require a proper password if it detects tampering (which, AIUI from other comments, the iPhone does).

Re: Fingerprints are Usernames, not Passwords

#58
post #54
post #37

Earlier quoted context omitted.

s/TouchID/Face Unlock/g and back up about 2 years and you can find all the same things said about Ice Cream Sandwich. It's a cute feature. It's not going to change the world, sell another billion phones, push other companies out of the market, or save anyone from serious attacks. It's probably a good idea to enable it anyway.

It is more difficult to defeat a touch sensor than face unlock. With face unlock, I just need a photo of the phone's owner. With a fingerprint unlock, I need to go to at least a little trouble to fake the fingerprint.

Depends on scenario. If you steal a phone from a bag on the subway, you'll never be able to get that photo but can probably lift the print right off the phone itself. So maybe iOS has better-yet-still-mediocre protection against snooping yet inferiorly-mediocre guards against identity theft. Yawn.

In neither case is the phone meaningfully protected against serious attack. Why must we have this argument? It's a cute feature. Use it.

Re: Fingerprints are Usernames, not Passwords

#59
post #34

All these academic arguments about the security of fingerprints are interesting but completely are detached from the day-to-day use of TouchID. I've been using it for about a week or so now. It's incredibly convenient. It unlocks my phone almost instantly. It prevents random people near by phone from being unable to unlock it. If a thief got their hands on it, they'd have a few attempts to unlock it with a fake finge…

Please don't delude yourself into thinking this is any safer against the typical kind of smartphone theft. Thieves will offload the phone to someone using software explicitly designed to wipe electronics to be resold. Whether they are wiping an iphone that happens to have touch ID or not is only relevent towards the resale price once it's wiped. Clearly Apple marketing works, as it's somehow convinced a member of (I'…

I'm not protecting my phone, I'm protecting my data. It does a pretty good job of that. Don't think we're somehow deluded for thinking that the data is the more valuable part of the thing.

Re: Fingerprints are Usernames, not Passwords

#60
post #39

Earlier quoted context omitted.

I don't think you can call something a cute feature when it's turned on on most phones and is used to unlock them. I would guess that by far the majority of iPhone 5S's have TouchID enabled. I wouldn't be surprised if it's more than 90%. The feature is just that well executed.

I would be very surprised if it is that high now even with the early adopter skew. Reports say that last year it was around a quarter of smartphone users use passcode locks on their work phone ( http://www.welivesecurity.com/2012/02/28/sizing-up-the-byod-... ). I imagine 5S rates are higher than that, but 90% would be insanely impressive. When it comes to computer security, as usual, people's apathy is the biggest pr…

Isn't passcode required to get exchange email on iOS?
Post reply on HN