Earlier quoted context omitted.
Please don't delude yourself into thinking this is any safer against the typical kind of smartphone theft. Thieves will offload the phone to someone using software explicitly designed to wipe electronics to be resold. Whether they are wiping an iphone that happens to have touch ID or not is only relevent towards the resale price once it's wiped. Clearly Apple marketing works, as it's somehow convinced a member of (I'…
Uh, no. Of course it's doesn't prevent theft. (Though the new 'wipe the phone in 10 tries' thing may deter it, separate from TouchID, I'm not sure.) The point is that with TouchID (as opposed to no passcode) the thief will not be able to send porn to my mom or read my text messages before they wipe the phone.
Fingerprints are Usernames, not Passwords
121–130 of 261 posts
Re: Fingerprints are Usernames, not Passwords
#122Earlier quoted context omitted.
It is more difficult to defeat a touch sensor than face unlock. With face unlock, I just need a photo of the phone's owner. With a fingerprint unlock, I need to go to at least a little trouble to fake the fingerprint.
My Samsung phone has a feature that requires you to blink in order to unlock the phone to ensure that you're not a still photo. Of course, I don't actually use it because the face recognition is so bad, and nonexistent in the dark.
Re: Fingerprints are Usernames, not Passwords
#123I'm not so sure. How many people are motivated to dupe your fingerprints to get into your iPhone? How many of those people could conceivably get into your iPhone through other ways? Fingerprints are a nice way to keep almost everyone out of your device. And for the rest, well, I really doubt some other locking mechanism would've kept them out.
I agree that the touchID shouldn't be used for authentication with everything and I think Apple agrees, which is why they haven't opened it up to 3rd party developers.
Re: Fingerprints are Usernames, not Passwords
#124I'm not so sure. How many people are motivated to dupe your fingerprints to get into your iPhone? How many of those people could conceivably get into your iPhone through other ways? Fingerprints are a nice way to keep almost everyone out of your device. And for the rest, well, I really doubt some other locking mechanism would've kept them out.
What are people going to do when, in the all-too-near future, criminals begin sharing and selling databases of stolen high resolution finger prints? One theft isn't practical? How about a million? Driven by a never-ending pursuit of monetary gain via crime; with criminals always happy to conquer the latest technology wave. There's absolutely no reason to think that criminals won't amass substantial finger print recor…
The CCC could have used a stray fingerprint (say on a glass or the phone itself) but didn't. I suspect they would have demo'd that if they could have made it work reliably or even at all.
Your slippery slope argument seems faith-based and doesn't answer the big questions I posed above. I don't see Samsung or Moto going fingerprints anytime soon - and if they do, Apple is there with patented tech waiting to sue them if it's at all similar. Widely varying implementations of the same thing with possibly different exploit angles - does that seem like a security epidemic to you?
Re: Fingerprints are Usernames, not Passwords
#125Not essential to the main thesis of the article, but still: "But let's just say you're okay with Apple sharing your fingerprints with the NSA, as I've already told you, they're not private at all." Ok, they are not private but I'd still not willingly put them on anything controlled by an US corporation. Govt sending their agents to collect my fingerprints from glasses? Not feasible, too costly. Agency asking Apple to…
The US Govt probably has 3-4 sets of my fingerprints in various data stores across several agencies...and I'm no one special.
Re: Fingerprints are Usernames, not Passwords
#126Earlier quoted context omitted.
An iPhone that is wiped, even in DFU mode, requires the Apple ID and password immediately after it is booted for the first time. Basically, a stolen iPhone is only worth the sum of its parts so they can be used to repair other phones.
How does this work? I sold my old iphone to amazon. I never reported it "unstolen" or whatever to apple. Amazon paid me $200 for iPhone parts?
Re: Fingerprints are Usernames, not Passwords
#127All these academic arguments about the security of fingerprints are interesting but completely are detached from the day-to-day use of TouchID. I've been using it for about a week or so now. It's incredibly convenient. It unlocks my phone almost instantly. It prevents random people near by phone from being unable to unlock it. If a thief got their hands on it, they'd have a few attempts to unlock it with a fake finge…
s/TouchID/Face Unlock/g and back up about 2 years and you can find all the same things said about Ice Cream Sandwich. It's a cute feature. It's not going to change the world, sell another billion phones, push other companies out of the market, or save anyone from serious attacks. It's probably a good idea to enable it anyway.
The big enterprise market is an awesome place to get a foothold in - they are not really price-sensitive and hate change. Not that Apple has any problems in that segment, but extra lock-in doesn't hurt.
Where this becomes semi-dangerous is in assuming that now your phone is ironclad and you can store whatever on it totally unprotected. The best route to safety is to make informed decisions based on your own risk-tolerance and not be a lemming.
Re: Fingerprints are Usernames, not Passwords
#128Not essential to the main thesis of the article, but still: "But let's just say you're okay with Apple sharing your fingerprints with the NSA, as I've already told you, they're not private at all." Ok, they are not private but I'd still not willingly put them on anything controlled by an US corporation. Govt sending their agents to collect my fingerprints from glasses? Not feasible, too costly. Agency asking Apple to…
As others have joked: Imagine how much people would freak out if Apple devices had a microphone or a camera capable of recording you surreptitiously! If you're worried that Apple will roll over for the NSA, and that the NSA will, at some point, be out to get you, the quantity of information they could gather through backdoors on your phone is so astounding that it's hard to understand why hashed fingerprint feature a…
Re: Fingerprints are Usernames, not Passwords
#129Earlier quoted context omitted.
Please don't delude yourself into thinking this is any safer against the typical kind of smartphone theft. Thieves will offload the phone to someone using software explicitly designed to wipe electronics to be resold. Whether they are wiping an iphone that happens to have touch ID or not is only relevent towards the resale price once it's wiped. Clearly Apple marketing works, as it's somehow convinced a member of (I'…
I'm not protecting my phone , I'm protecting my data . It does a pretty good job of that. Don't think we're somehow deluded for thinking that the data is the more valuable part of the thing.
Re: Fingerprints are Usernames, not Passwords
#130Earlier quoted context omitted.
Can you buy content with Face Unlock?
The point the parent is making is that you shouldn't be able to buy content with a fingerprint.
He asks: "I don't see what this adds over face unlock."
I answer: "You can use Touch ID to buy things."