Live data from Hacker News

Fingerprints are Usernames, not Passwords

blog.dustinkirkland.com

131–140 of 261 posts

Re: Fingerprints are Usernames, not Passwords

#131
post #58
post #54

Earlier quoted context omitted.

It is more difficult to defeat a touch sensor than face unlock. With face unlock, I just need a photo of the phone's owner. With a fingerprint unlock, I need to go to at least a little trouble to fake the fingerprint.

Depends on scenario. If you steal a phone from a bag on the subway, you'll never be able to get that photo but can probably lift the print right off the phone itself. So maybe iOS has better-yet-still-mediocre protection against snooping yet inferiorly-mediocre guards against identity theft. Yawn. In neither case is the phone meaningfully protected against serious attack. Why must we have this argument? It's a cute f…

> but can probably lift the print right off the phone itself

What utter unmitigated rubbish. It is extremely unlikely that even a fully qualified CSI would be able to lift a full print from a mobile phone, let alone one that that can be reliably reproduced in the manner CCC described.

Re: Fingerprints are Usernames, not Passwords

#133
post #27

Earlier quoted context omitted.

It's not a username. It's a fingerprint. Usernames are how we indicate an identity to a computer. (Note "an" identity; identities do not one-to-one map to humans.) Identity is what we are trying to establish in the first place; if we simply knew you were authorized to use an identity we wouldn't need auth in the first place. Having a matching fingerprint is evidence that an authorized user is authorized to use that i…

>> Having a matching fingerprint is evidence that an authorized user is authorized to use that identity. Considering that you leave your fingerprint everywhere you touch with your bare hands, is that really true?

There is a reason I chose the word "evidence" and not the word "proof". Yes, it is evidence. No, it is not proof.

Further note that possession of a password ("something you know") is also merely evidence, not proof. Also, "something you have" is not proof either; having a token is merely evidence, not proof. We have no method of proof. If that is the standard you are looking for, then I have some bad news: It is impossible to meet that standard. If we did have a direct method of proof-of-identity, we would not have to talk about evidence. We would simply use the proof.

Yes, it is possible to fool even a three-factor authentication system, with enough work. That's why its important to understand that security is not about absolutes; it's about raising the cost of penetrating the security above the value of the thing being protected. Which is also why fingerprint protection is just fine for rather a lot of iPhone users; what's the payback for cracking a fingerprint scanner, just to get access to a metaphorical Grandma's phone? If you are concerned that the value of what is on your phone exceeds the costs of penetrating the fingerprint scanner, then use more authentication. It's about costs & benefits, not absolutes.

Would someone care to explain how the observation that fingerprints are indeed a form of auth, but usernames are not (often they are fully, intentionally public information!) is false, and therefore the entire premise of the post's title is incorrect, with something other than the downvote button? I'd really like to hear the explanation of how that's not true.

Re: Fingerprints are Usernames, not Passwords

#134
post #46

Earlier quoted context omitted.

Uh, no. Of course it's doesn't prevent theft. (Though the new 'wipe the phone in 10 tries' thing may deter it, separate from TouchID, I'm not sure.) The point is that with TouchID (as opposed to no passcode) the thief will not be able to send porn to my mom or read my text messages before they wipe the phone.

And with iOS7 they're going to have a harder time wiping it because phones are now locked to your Apple account. So they need your Apple account ID and password to wipe it.

[deleted]

Re: Fingerprints are Usernames, not Passwords

#136
post #100

Earlier quoted context omitted.

there ll be an app for that. edit: build an app, get your colleague, significant other etc touch it on any touchscreen phone or get on camera and create a 3d printed finger. 3d printing vs touchid...maybe

I'm pretty sure the GP was talking about the likelihood of a given phone having an appropriate-quality print [1], which does seem low. But putting that aside, your hypothetical app would -- using the demonstrated method -- 'lift' that excellent quality print, scan it at 2400 dpi, (clean up said print), print it on a transparency at 1200 dpi, mask it onto photosensitive PCB, develop/etch/clean the PCB, spray graphite…

I find it amazing that when faced with a general question about a "security" feature the median internet tech nerd responds with an attitude of absolute paranoia (c.f. 4096 bit RSA keys, multi-word pass phrase choices, ssh key forwarding pedantry, general NSA tinfoil hatism....)

Except when confronted with an Apple product. Then it's all "Nah bro, relax. No way could you lift a fingerprint from a glossy phone screen". :)

I'll say it for the third time. It's cute feature (like face unlock was before it). Use it and enjoy it. If you honestly think you're buying a serious security mechanism you're simply wrong.

Re: Fingerprints are Usernames, not Passwords

#137
post #81
post #55

Earlier quoted context omitted.

And I think that's the main problem with it. People think that it's actually a true replacement for a password, even though it's not.

Give me a real world scenario where this distinction matters and affects real outcomes. For real users, not people who are trying to protect themselves from the CIA.

If you use that fingerprint code, any thief that steals your phone and wants your data will have it. It offers no protection at all.

Now, if you arguee that no thief will ever want your data (and you'd be probably right), it doesn't matter if you lock your phone or not, and it won't matter how you do that. In this case, locking schemes are completely useless.

(Now, I'd be content with a fingerprint reader that recognizes a finger - any finger - and unlocks the phone. It's enough protection if my pocket can't defeat it. Unlocking only by specific fingerprints looks like a pain, nobody else will be able to unlock my phone? Thanks, but I'll pass that.)

Re: Fingerprints are Usernames, not Passwords

#138
post #81
post #55

Earlier quoted context omitted.

And I think that's the main problem with it. People think that it's actually a true replacement for a password, even though it's not.

Give me a real world scenario where this distinction matters and affects real outcomes. For real users, not people who are trying to protect themselves from the CIA.

You have your phone in your pocket, I want to access your data.

With touch unlock, all I need is my buddy to hold you for 3 seconds while I twist your arm and unlock the phone.

With passcode unlock, getting the password out of you will take some more effort.

Oh, and in this scenario, I can be a thief, or a police officer, or a borders agent, or an abusive husband, or many other things :)

Re: Fingerprints are Usernames, not Passwords

#139

Earlier quoted context omitted.

My Samsung phone has a feature that requires you to blink in order to unlock the phone to ensure that you're not a still photo. Of course, I don't actually use it because the face recognition is so bad, and nonexistent in the dark.

Apparently that can be defeated with Photoshop.

Or maybe a animated GIF image.

Re: Fingerprints are Usernames, not Passwords

#140
post #138
post #81

Earlier quoted context omitted.

Give me a real world scenario where this distinction matters and affects real outcomes. For real users, not people who are trying to protect themselves from the CIA.

You have your phone in your pocket, I want to access your data. With touch unlock, all I need is my buddy to hold you for 3 seconds while I twist your arm and unlock the phone. With passcode unlock, getting the password out of you will take some more effort. Oh, and in this scenario, I can be a thief, or a police officer, or a borders agent, or an abusive husband, or many other things :)

> With passcode unlock, getting the password out of you will take some more effort.

Given that there are two people, capable of violence, against the phone owner I'm not sure that getting the password is going to be that much trouble.

Post reply on HN