Earlier quoted context omitted.
s/TouchID/Face Unlock/g and back up about 2 years and you can find all the same things said about Ice Cream Sandwich. It's a cute feature. It's not going to change the world, sell another billion phones, push other companies out of the market, or save anyone from serious attacks. It's probably a good idea to enable it anyway.
Except TouchID, from what I gather, actually works. Not "works" in the sense of keeping bad people out, but "works" in the sense that when I use it my phone unlocks. I tried face unlock briefly on the Google Nexus I've got and disabled it shortly after when I found that it was unreliable. Poor lighting, too much lighting, a bad hair day, it wasn't even at 80% for successful unlocks.
Fingerprints are Usernames, not Passwords
111–120 of 261 posts
Re: Fingerprints are Usernames, not Passwords
#112Earlier quoted context omitted.
This is right. Fingerprint scanning prevents casual snooping in the same way that a PIN or face unlock does. It's lightweight authentication. It can't be used as a hard security feature (e.g. as input to a PBKDF) so it can't provide security against hard attacks like stealing the device and reading the flash. It's cute. Honestly I don't see what this adds over face unlock which is reasonably mature now and equally ya…
I haven't used face unlock but I am going to guess TouchID is much faster and easier. It unlocks almost instantly, you don't have to be in view of the camera, and it doesn't require any extra effort since your finger is already on the home button to wake up the phone.
Re: Fingerprints are Usernames, not Passwords
#1134 digits pin codes aren't passwords either. Sometimes good enough is good enough.
They have all the essential features of passwords, they are just weak passwords.
Fingerprints can't be changed if compromised, and so they don't have the essential features of passwords.
There is a difference between a weak password and not-a-password.
Re: Fingerprints are Usernames, not Passwords
#114I'm not so sure. How many people are motivated to dupe your fingerprints to get into your iPhone? How many of those people could conceivably get into your iPhone through other ways? Fingerprints are a nice way to keep almost everyone out of your device. And for the rest, well, I really doubt some other locking mechanism would've kept them out.
What I think he is saying is that because it is now on iPhone, more devices/services/whatever may be likely to use finger prints for auth. This is dangerous because you can't change your fingerprint in the unlikely case someone dupes your print. If more and more things rely on finger prints, the value of duping goes up, right? What happens when your prints are duped once?
Most of us don't live in a James Bond movie.
(1) If someone has my fingerprints they still need my phone to do anything.
(2) Even with my phone there's a good chance it's worthless unless they also have my pin.
(3) Stealing my phone has also become worth much less unless you have my prints and the followthrough to make fake ones and again they'll want my pin in most cases because you only get 5 failed attempts with your fake prints.
(4) All of that takes time, during which I may be able to remote wipe my phone, making the whole exercise worth even less. And it takes money, again lowering potential returns.
It's easy to imagine (numbers pulled out of ass) that a thief could get a few hundred bucks for a 5C (no touch id) but say half that for the more expensive 5S. Maybe that won't hold up for various reasons (hey thieves will work hard to make those stolen 5s's worth more) but the principle behind multi-factor is sound.
Re: Fingerprints are Usernames, not Passwords
#115I'm not so sure. How many people are motivated to dupe your fingerprints to get into your iPhone? How many of those people could conceivably get into your iPhone through other ways? Fingerprints are a nice way to keep almost everyone out of your device. And for the rest, well, I really doubt some other locking mechanism would've kept them out.
What I think he is saying is that because it is now on iPhone, more devices/services/whatever may be likely to use finger prints for auth. This is dangerous because you can't change your fingerprint in the unlikely case someone dupes your print. If more and more things rely on finger prints, the value of duping goes up, right? What happens when your prints are duped once?
Re: Fingerprints are Usernames, not Passwords
#116Earlier quoted context omitted.
If your objective is to sell a stolen iPhone then you still have to know the owners Apple ID and password due to activation lock. Being able to bypass Touch ID isn't going to help you.
Nope. If it's not a hardware lock, it will be bypassed.
Keep in mind that if these criminals can't figure it out by googling it, they will give up and move on. The typical phone thief isn't a security expert with the knowledge to invent a previously unknown exploit.
Re: Fingerprints are Usernames, not Passwords
#117Earlier quoted context omitted.
This is right. Fingerprint scanning prevents casual snooping in the same way that a PIN or face unlock does. It's lightweight authentication. It can't be used as a hard security feature (e.g. as input to a PBKDF) so it can't provide security against hard attacks like stealing the device and reading the flash. It's cute. Honestly I don't see what this adds over face unlock which is reasonably mature now and equally ya…
Can you buy content with Face Unlock?
Re: Fingerprints are Usernames, not Passwords
#118All security is based on either something you know, something you have, something you are, or a combination of the three. - A username is something you know. - A password is something you know. - A pinpad is something you have. - A finger print is something you have.
Re: Fingerprints are Usernames, not Passwords
#1194 digits pin codes aren't passwords either. Sometimes good enough is good enough.
> 4 digits pin codes aren't passwords either. They have all the essential features of passwords, they are just weak passwords. Fingerprints can't be changed if compromised, and so they don't have the essential features of passwords. There is a difference between a weak password and not-a-password.
Sure they can, it's just really, really painful ;)
Re: Fingerprints are Usernames, not Passwords
#120Earlier quoted context omitted.
This is right. Fingerprint scanning prevents casual snooping in the same way that a PIN or face unlock does. It's lightweight authentication. It can't be used as a hard security feature (e.g. as input to a PBKDF) so it can't provide security against hard attacks like stealing the device and reading the flash. It's cute. Honestly I don't see what this adds over face unlock which is reasonably mature now and equally ya…
I haven't used face unlock but I am going to guess TouchID is much faster and easier. It unlocks almost instantly, you don't have to be in view of the camera, and it doesn't require any extra effort since your finger is already on the home button to wake up the phone.
Face unlock is very fast - generally I turn device towards me to start using it and face unlock has unlocked it before I even realise it was locked (less than half a second).
When it fails to recognise you, you can enter a pin/password/pattern. There is a menu option to 'Improve Matches' so it can pick up whatever is different this time. Every release has improved dramatically. After my most recent Android reinstall I recall only ever improving matches once.
It doesn't work in low light which fingerprints will.