Live data from Hacker News

Fingerprints are Usernames, not Passwords

blog.dustinkirkland.com

91–100 of 261 posts

Re: Fingerprints are Usernames, not Passwords

#91
post #63

Earlier quoted context omitted.

What are people going to do when, in the all-too-near future, criminals begin sharing and selling databases of stolen high resolution finger prints? One theft isn't practical? How about a million? Driven by a never-ending pursuit of monetary gain via crime; with criminals always happy to conquer the latest technology wave. There's absolutely no reason to think that criminals won't amass substantial finger print recor…

Let's say criminals manage to build a database of everybody's fingerprint. Now, I steal a phone, and have access to that database. How do I query it?

Based on a partial print from the screen or body of the phone? (It wouldn't work every time, but it might be feasible often enough to be worth trying.)

Re: Fingerprints are Usernames, not Passwords

#93

I'm not so sure. How many people are motivated to dupe your fingerprints to get into your iPhone? How many of those people could conceivably get into your iPhone through other ways? Fingerprints are a nice way to keep almost everyone out of your device. And for the rest, well, I really doubt some other locking mechanism would've kept them out.

What are people going to do when, in the all-too-near future, criminals begin sharing and selling databases of stolen high resolution finger prints? One theft isn't practical? How about a million? Driven by a never-ending pursuit of monetary gain via crime; with criminals always happy to conquer the latest technology wave. There's absolutely no reason to think that criminals won't amass substantial finger print recor…

OK, you are a criminal and got 1000 000 fingerprints. You can start collecting them right now, on every surface you have access too. Then what? You will print them all using whatever technology required to fool fingerprint scanner and try one by one? Wouldn't it be just easier to try and lift one off the device itself?

  > It's about a consumer shift to finger prints as a primary
  > security feature
No. It's about shift from zero security (no passcode lock) to some security (fingerprint). Yes it can be fooled but it is effective enough to stop casual attacks. Just like lock on the most doors — no problem for a determined robber but good enough protection from the opportunistic thief.

Re: Fingerprints are Usernames, not Passwords

#94
post #37

Earlier quoted context omitted.

s/TouchID/Face Unlock/g and back up about 2 years and you can find all the same things said about Ice Cream Sandwich. It's a cute feature. It's not going to change the world, sell another billion phones, push other companies out of the market, or save anyone from serious attacks. It's probably a good idea to enable it anyway.

Except TouchID, from what I gather, actually works. Not "works" in the sense of keeping bad people out, but "works" in the sense that when I use it my phone unlocks. I tried face unlock briefly on the Google Nexus I've got and disabled it shortly after when I found that it was unreliable. Poor lighting, too much lighting, a bad hair day, it wasn't even at 80% for successful unlocks.

does touchid have the disadvantage of keeping your friends and family unable to use your phone in cases of emergency? 95% of the time, my phone isnt next to adversaries, but trusted parties. a password or code is transferrable, fingerprint isnt.

edit; not 911emergency, but casual situations of full or dirty hands..

Re: Fingerprints are Usernames, not Passwords

#95
I don't lock my phone to keep out the NSA or the government. I suppose those organizations would be able to easily crack in regardless. I lock my phone so my child can't pick it up and mess things up. Or to hopefully deter potential robbery. Thus, I think TouchID is great even though I do agree with the OP. If I had something like my primary computer that I needed to keep very secure, I'd shy away from using my fingerprint.

Re: Fingerprints are Usernames, not Passwords

#96

Earlier quoted context omitted.

Please don't delude yourself into thinking this is any safer against the typical kind of smartphone theft. Thieves will offload the phone to someone using software explicitly designed to wipe electronics to be resold. Whether they are wiping an iphone that happens to have touch ID or not is only relevent towards the resale price once it's wiped. Clearly Apple marketing works, as it's somehow convinced a member of (I'…

An iPhone that is wiped, even in DFU mode, requires the Apple ID and password immediately after it is booted for the first time. Basically, a stolen iPhone is only worth the sum of its parts so they can be used to repair other phones.

How does this work? I sold my old iphone to amazon. I never reported it "unstolen" or whatever to apple. Amazon paid me $200 for iPhone parts?

Re: Fingerprints are Usernames, not Passwords

#97

Earlier quoted context omitted.

Except TouchID, from what I gather, actually works. Not "works" in the sense of keeping bad people out, but "works" in the sense that when I use it my phone unlocks. I tried face unlock briefly on the Google Nexus I've got and disabled it shortly after when I found that it was unreliable. Poor lighting, too much lighting, a bad hair day, it wasn't even at 80% for successful unlocks.

does touchid have the disadvantage of keeping your friends and family unable to use your phone in cases of emergency? 95% of the time, my phone isnt next to adversaries, but trusted parties. a password or code is transferrable, fingerprint isnt. edit; not 911emergency, but casual situations of full or dirty hands..

You can add ten fingers, or you can give them your code, or they can dial 911 with a fully locked phone. So no, it's slightly easier for a relative to use in an emergency than a typical locked phone.

Re: Fingerprints are Usernames, not Passwords

#98
post #54
post #37

Earlier quoted context omitted.

s/TouchID/Face Unlock/g and back up about 2 years and you can find all the same things said about Ice Cream Sandwich. It's a cute feature. It's not going to change the world, sell another billion phones, push other companies out of the market, or save anyone from serious attacks. It's probably a good idea to enable it anyway.

It is more difficult to defeat a touch sensor than face unlock. With face unlock, I just need a photo of the phone's owner. With a fingerprint unlock, I need to go to at least a little trouble to fake the fingerprint.

My Samsung phone has a feature that requires you to blink in order to unlock the phone to ensure that you're not a still photo.

Of course, I don't actually use it because the face recognition is so bad, and nonexistent in the dark.

Re: Fingerprints are Usernames, not Passwords

#99
I have my password set to wipe my iphone after only 3 incorrect tries but I disagree about touchID being more convenient. You can be compelled to give LEOs access to your device if it only requires your fingerprint. I can conveniently forget my PIN if necessary.

Any good thief is going to swipe a phone and worry more about getting away and less about unlocking it which they will do later. Furthermore, unless you're jailbroken and have changed your default sudo credentials then your data isn't all that secure anyway against someone with a computer and rudimentary software. All of which can be done while the phone is off or in an area with no service. That would also serve to defeat find my iphone as well.

Re: Fingerprints are Usernames, not Passwords

#100

Earlier quoted context omitted.

but can probably lift the print right off the phone itself That doesn't seem to be the case to my knowledge. The evidence from the successful attack is that you need an excellent-quality print from one of the specific fingers that has been programmed into the phone. Some phones probably have that on them, but it appears likely that many do not.

there ll be an app for that. edit: build an app, get your colleague, significant other etc touch it on any touchscreen phone or get on camera and create a 3d printed finger. 3d printing vs touchid...maybe

I'm pretty sure the GP was talking about the likelihood of a given phone having an appropriate-quality print [1], which does seem low.

But putting that aside, your hypothetical app would -- using the demonstrated method -- 'lift' that excellent quality print, scan it at 2400 dpi, (clean up said print), print it on a transparency at 1200 dpi, mask it onto photosensitive PCB, develop/etch/clean the PCB, spray graphite and apply wood glue to the mold.

It might make for a slightly-more-plausible-than-normal gadget sequence in a Mission Impossible movie, but it's not much of a concern for the target market. [2]

[1] Despite what decades of shows like CSI might lead us to believe, this is not a simple or error-free process. And each mistake irrecoverably destroys the print.

[2] Most of that market doesn't even use a passcode today and many that do are still using surprisingly bad PINs (birthdays/anniversaries/1234)

Post reply on HN