Live data from Hacker News

Fingerprints are Usernames, not Passwords

blog.dustinkirkland.com

171–180 of 261 posts

Re: Fingerprints are Usernames, not Passwords

#171
> I could see some value, perhaps, in a tablet that I share with my wife, where each of us have our own accounts, with independent configurations, apps, and settings. We could each conveniently identify ourselves by our fingerprint. But biometrics cannot, and absolutely must not, be used to authenticate an identity.

I am not seeing the distinction. What exactly is the difference between an "identification" and an "authenticated identification"? With the family tablet, the fingerprint is still acting exactly like a password, and the reason the author is okay with it is because it's a password that's not protecting anything terribly important. Why not just have profiles that are selectable without any authentication? That would probably also work for a family tablet, but the fingerprint might be preferable to protect some info from your family members (even completely innocent things like shopping for gifts). Of course your family members could easily lift your fingerprint and bypass the biometrics, but it doesn't matter.

Re: Fingerprints are Usernames, not Passwords

#172
post #34

All these academic arguments about the security of fingerprints are interesting but completely are detached from the day-to-day use of TouchID. I've been using it for about a week or so now. It's incredibly convenient. It unlocks my phone almost instantly. It prevents random people near by phone from being unable to unlock it. If a thief got their hands on it, they'd have a few attempts to unlock it with a fake finge…

> a few attempts to unlock it with a fake fingerprint, and then they'd have to enter my code. And if they fail to enter my code 10 times, the phone is wiped. Are you saying that random people can pick up your phone when you go to the bathroom, touch the home button 3 times, and then enter "1111" 10 times, and wipe your phone? Is there some protection against this?

Even without TouchID, iirc on previous iPhone models entering an invalid password 10 times would trigger a wipe. So not a new threat -- just balancing maintaining the confidentiality of your data with the DOS risk.

Re: Fingerprints are Usernames, not Passwords

#173
post #54
post #37

Earlier quoted context omitted.

s/TouchID/Face Unlock/g and back up about 2 years and you can find all the same things said about Ice Cream Sandwich. It's a cute feature. It's not going to change the world, sell another billion phones, push other companies out of the market, or save anyone from serious attacks. It's probably a good idea to enable it anyway.

It is more difficult to defeat a touch sensor than face unlock. With face unlock, I just need a photo of the phone's owner. With a fingerprint unlock, I need to go to at least a little trouble to fake the fingerprint.

> With face unlock, I just need a photo of the phone's owner.

face unlock now requires you to blink.

Re: Fingerprints are Usernames, not Passwords

#174

Earlier quoted context omitted.

Under the assumption that the sandbox works, no.

I meant jailbroken, of course.

The "sandbox" being referred to is the "Secure Enclave", which apparently is what ARM calls "TrustZone": http://infocenter.arm.com/help/topic/com.arm.doc.prd29-genc-... The data isn't accessible to even the OS. So, in theory at least, jailbreaking doesn't make it any more accessible.

Re: Fingerprints are Usernames, not Passwords

#175
post #110

Earlier quoted context omitted.

How does this work? I sold my old iphone to amazon. I never reported it "unstolen" or whatever to apple. Amazon paid me $200 for iPhone parts?

It's new in iOS 7. You'll have to explicitly wipe & reset your iPhone before selling it from now on. So if it works as advertised, stolen iPhones and iPads will only be worth the sum of their parts.

Hmm. After upgrading my ipad to iOS 7, I changed my pass code. Which I promptly forgot. I had to reset it from iTunes, on a computer which had never paired with the ipad (in fact I had to download iTunes to do this). When the ipad restarted it asked me for my Apple ID but that seemed to be for the iCloud restore. I think I could have skipped it and had a functioning ipad. But apparently not?

Re: Fingerprints are Usernames, not Passwords

#176
post #34

All these academic arguments about the security of fingerprints are interesting but completely are detached from the day-to-day use of TouchID. I've been using it for about a week or so now. It's incredibly convenient. It unlocks my phone almost instantly. It prevents random people near by phone from being unable to unlock it. If a thief got their hands on it, they'd have a few attempts to unlock it with a fake finge…

> a few attempts to unlock it with a fake fingerprint, and then they'd have to enter my code. And if they fail to enter my code 10 times, the phone is wiped. Are you saying that random people can pick up your phone when you go to the bathroom, touch the home button 3 times, and then enter "1111" 10 times, and wipe your phone? Is there some protection against this?

It starts throttling attempts before going full lockdown. But, yeah, don't leave assholes alone with your phone.

Re: Fingerprints are Usernames, not Passwords

#177

Earlier quoted context omitted.

I meant jailbroken, of course.

The "sandbox" being referred to is the "Secure Enclave", which apparently is what ARM calls "TrustZone": http://infocenter.arm.com/help/topic/com.arm.doc.prd29-genc-... The data isn't accessible to even the OS. So, in theory at least, jailbreaking doesn't make it any more accessible.

Ah, that's interesting, thanks, I didn't know about it.

Re: Fingerprints are Usernames, not Passwords

#178
post #161
post #131

Earlier quoted context omitted.

> but can probably lift the print right off the phone itself What utter unmitigated rubbish. It is extremely unlikely that even a fully qualified CSI would be able to lift a full print from a mobile phone, let alone one that that can be reliably reproduced in the manner CCC described.

On release, people were saying it was unhackable. Molds were made that faked it within a week. You really want to bet that no one will make this work? With a target this high profile? My 5 year old son was quite literally dusting for fingerprints at the local science museum last weekend. We have some shockingly high fidelity prints of both our thumbs showing all the ridges. And all we had to do was squeeze a piece of…

Yup - remember the whole "sub dermal RF fields - so it can't be a fake finger, or your finger can't be cut off - has to have a pulse and be live", from Apple's own marketing?

Yeah, not so much. The fakes didn't even pretend to be live tissue.

Re: Fingerprints are Usernames, not Passwords

#179
post #34

All these academic arguments about the security of fingerprints are interesting but completely are detached from the day-to-day use of TouchID. I've been using it for about a week or so now. It's incredibly convenient. It unlocks my phone almost instantly. It prevents random people near by phone from being unable to unlock it. If a thief got their hands on it, they'd have a few attempts to unlock it with a fake finge…

Please don't delude yourself into thinking this is any safer against the typical kind of smartphone theft. Thieves will offload the phone to someone using software explicitly designed to wipe electronics to be resold. Whether they are wiping an iphone that happens to have touch ID or not is only relevent towards the resale price once it's wiped. Clearly Apple marketing works, as it's somehow convinced a member of (I'…

I think any reference to improved protection against theft has to do with iOS 7's new feature of requiring an Apple ID even after a wipe.

Re: Fingerprints are Usernames, not Passwords

#180
post #38
post #35

Earlier quoted context omitted.

This is right. Fingerprint scanning prevents casual snooping in the same way that a PIN or face unlock does. It's lightweight authentication. It can't be used as a hard security feature (e.g. as input to a PBKDF) so it can't provide security against hard attacks like stealing the device and reading the flash. It's cute. Honestly I don't see what this adds over face unlock which is reasonably mature now and equally ya…

I haven't used face unlock but I am going to guess TouchID is much faster and easier. It unlocks almost instantly, you don't have to be in view of the camera, and it doesn't require any extra effort since your finger is already on the home button to wake up the phone.

I've used Face Unlock. It's terrible. It's slow, very inconsistent, doesn't work at all in variety of situations (low light, in pocket) and goofy.
Post reply on HN