Live data from Hacker News

Fingerprints are Usernames, not Passwords

blog.dustinkirkland.com

161–170 of 261 posts

Re: Fingerprints are Usernames, not Passwords

#161
post #131
post #58

Earlier quoted context omitted.

Depends on scenario. If you steal a phone from a bag on the subway, you'll never be able to get that photo but can probably lift the print right off the phone itself. So maybe iOS has better-yet-still-mediocre protection against snooping yet inferiorly-mediocre guards against identity theft. Yawn. In neither case is the phone meaningfully protected against serious attack. Why must we have this argument? It's a cute f…

> but can probably lift the print right off the phone itself What utter unmitigated rubbish. It is extremely unlikely that even a fully qualified CSI would be able to lift a full print from a mobile phone, let alone one that that can be reliably reproduced in the manner CCC described.

On release, people were saying it was unhackable. Molds were made that faked it within a week. You really want to bet that no one will make this work? With a target this high profile?

My 5 year old son was quite literally dusting for fingerprints at the local science museum last weekend. We have some shockingly high fidelity prints of both our thumbs showing all the ridges. And all we had to do was squeeze a piece of plastic. Fingerprints have even less identifying detail than faces. You've been hoodwinked by Apple's marketing, and I'm willing to bet this isn't the first time.

Re: Fingerprints are Usernames, not Passwords

#162
Wiping a phone in dfu mode removes the password as well. I learned the hard way when I forgot my pin and had to wipe and restore.

It also bypasses activation lock because phones sold overseas are usually sold to countries that do not subscribe to the national blacklisted imei database and this won't block the device on their network.

Re: Fingerprints are Usernames, not Passwords

#163
post #110

Earlier quoted context omitted.

It's new in iOS 7. You'll have to explicitly wipe & reset your iPhone before selling it from now on. So if it works as advertised, stolen iPhones and iPads will only be worth the sum of their parts.

removing that wipe feature would be a nice tidy way to destroy the secondary market for iphones... did I just predict iOS8?

No.

Apple are perfectly happy with the second hand market for iPhones.

I've just ordered a 5S. It's costing me £709. My iPhone 4S 64Gb is worth about £200 second hand. Even a new 8Gb 4S, the cheapest model available new, is £349.

Anyone interested in my second hand phone was almost certainly never going to spring for a new iPhone.

The market for second hand iPhones does next to nothing to cannibalise the market for new iPhones (which Apple cares about) and strengthens the iOS ecosystem (both by bringing in new customers who might buy apps, music and movies but also keeping customers away from competing platforms).

There's more upside than downside for Apple in second hand iPhones.

Re: Fingerprints are Usernames, not Passwords

#166
About the only person I use even a pin lock around on my phone is my girlfriend, and that's just because she gets upset if I communicate with any girl. Fingerprint is fine for that purpose. Anything else I wouldn't bother locking it at all, I'd just disconnect the phone from my accounts if it is ever lost.

Re: Fingerprints are Usernames, not Passwords

#167
post #34

All these academic arguments about the security of fingerprints are interesting but completely are detached from the day-to-day use of TouchID. I've been using it for about a week or so now. It's incredibly convenient. It unlocks my phone almost instantly. It prevents random people near by phone from being unable to unlock it. If a thief got their hands on it, they'd have a few attempts to unlock it with a fake finge…

> a few attempts to unlock it with a fake fingerprint, and then they'd have to enter my code. And if they fail to enter my code 10 times, the phone is wiped.

Are you saying that random people can pick up your phone when you go to the bathroom, touch the home button 3 times, and then enter "1111" 10 times, and wipe your phone? Is there some protection against this?

Re: Fingerprints are Usernames, not Passwords

#168
post #140
post #138

Earlier quoted context omitted.

You have your phone in your pocket, I want to access your data. With touch unlock, all I need is my buddy to hold you for 3 seconds while I twist your arm and unlock the phone. With passcode unlock, getting the password out of you will take some more effort. Oh, and in this scenario, I can be a thief, or a police officer, or a borders agent, or an abusive husband, or many other things :)

> With passcode unlock, getting the password out of you will take some more effort. Given that there are two people, capable of violence, against the phone owner I'm not sure that getting the password is going to be that much trouble.

Getting a password requires consent, even if it's under duress. Getting your finger doesn't require you to agree with anything.

Re: Fingerprints are Usernames, not Passwords

#169
post #34

All these academic arguments about the security of fingerprints are interesting but completely are detached from the day-to-day use of TouchID. I've been using it for about a week or so now. It's incredibly convenient. It unlocks my phone almost instantly. It prevents random people near by phone from being unable to unlock it. If a thief got their hands on it, they'd have a few attempts to unlock it with a fake finge…

> a few attempts to unlock it with a fake fingerprint, and then they'd have to enter my code. And if they fail to enter my code 10 times, the phone is wiped. Are you saying that random people can pick up your phone when you go to the bathroom, touch the home button 3 times, and then enter "1111" 10 times, and wipe your phone? Is there some protection against this?

Protection against what ? That is the desired behaviour of most people. And if it isn't then you can simple disable the behaviour.

It's not like you will lose data since it is backed up to iCloud.

Re: Fingerprints are Usernames, not Passwords

#170

Earlier quoted context omitted.

Can't someone write an app that stays in the background on their phone and copies fingerprints of people who touch your button?

Under the assumption that the sandbox works, no.

I meant jailbroken, of course.
Post reply on HN