Earlier quoted context omitted.
Touch ID only works for a minute or two after your finger is cut off. Touch ID reads the blood vessels, not the fingerprint, meaning it only works for a minute or two after the finger is cut off.
I'm not really interested in being the one on whom someone learns that, though.
Fingerprints Are Usernames, Not Passwords (2013)
91–100 of 106 posts
Re: Fingerprints Are Usernames, Not Passwords (2013)
#92Earlier quoted context omitted.
I'm not really interested in being the one on whom someone learns that, though.
Very few thieves would go that far, and they would almost certainly give you an opportunity to unlock the phone for them instead. Most people would take that opportunity.
Re: Fingerprints Are Usernames, Not Passwords (2013)
#93Earlier quoted context omitted.
I think Apple are pretty aware of the limitations - they don't accept TouchID on first login after a restart, for the first purchase after a restart, if it's been 48 hours since an unlock or for resets/major config changes. For that you either need the PIN or, if you've opted for more security, the password. Overall it feels that Apple's take is for day to day login it's better than a four digit PIN and it's better t…
>they don't accept TouchID on first login after a restart That's because the hash of the print is stored on an encrypted volume of some kind, which requires your regular password to decrypt after a cold boot. Once the hash is in memory, the fingerprint can be used instead.
Re: Fingerprints Are Usernames, Not Passwords (2013)
#94Something I feel that's always missed in these discussions is context: Who is the adversary you're attempting to protect against? Your kids screwing around with your phone? TouchID does the job. Random people screwing around with your phone if they find it? Same thing. Government gets ahold of it? Yeah.. notsomuch. Considering that the primary adversaries of an average smartphone user are other mere mortals, not dedi…
Still, I'd rather not give hardened criminals a reason to cut off my fingers.
Re: Fingerprints Are Usernames, Not Passwords (2013)
#95Dustin Kirkland gets it. Simplifying his post, there are 3 reasons biometrics are terrible for authentication: 1. Every piece of biometric data is inherently public. (Fingerprints, facial geometry, hand geometry, even DNA) 2. Biometrics require an error threshold as our bodies are always changing (that's like typing a 20char password and having only 15 of them be correct. That's fine! Let them in anyways with 5 incor…
My keys are plenty strong, but when I mistype a strong key (which is plausible seeing as I can't see what I'm typing) then I'm fine with sacrificing some strength to just accept it. My key is already well beyond practical attack anyway.
That said, if you WERE to use something like 2, you'd have to be much more diligent about enforcing good passwords, also you'd have to come up with some kinda scheme that could work with "close enough" and not reveal information about the password.
Re: Fingerprints Are Usernames, Not Passwords (2013)
#96In the case of Touch ID, please consider that in order to circumvent it, you not only have to be able to fool the Touch ID sensor, you also have to have physical access to the device .
Depends. If you use Touch ID on an app, you could use your own iphone and fool its scanner.
Re: Fingerprints Are Usernames, Not Passwords (2013)
#97Something I feel that's always missed in these discussions is context: Who is the adversary you're attempting to protect against? Your kids screwing around with your phone? TouchID does the job. Random people screwing around with your phone if they find it? Same thing. Government gets ahold of it? Yeah.. notsomuch. Considering that the primary adversaries of an average smartphone user are other mere mortals, not dedi…
This a thousand times! When you think about security, you should have in mind who you are protecting against, and the same applies to passwords. Security purists love to advocate that password reuse is evil, but who in the first place is going to be your attacker and for which purpose? For example, in the context of money (online banking, paypal, ebay, etc.) I completely agree that password reuse is evil. But when it…
You don't know, that's why password reuse is evil.
Years ago when I made my Facebook account it used the same password as all my other accounts. Now that I use Facebook as an OpenID provider for pretty much any news site I would be exposing myself and my friends to all sorts of attacks if someone found hacked a phpBB forum that I frequented years ago. You could make the argument that only important sites should have unique passwords, but you, your grandmother, and I all have a different definition of important sites.
Re: Fingerprints Are Usernames, Not Passwords (2013)
#98Something I feel that's always missed in these discussions is context: Who is the adversary you're attempting to protect against? Your kids screwing around with your phone? TouchID does the job. Random people screwing around with your phone if they find it? Same thing. Government gets ahold of it? Yeah.. notsomuch. Considering that the primary adversaries of an average smartphone user are other mere mortals, not dedi…
Re: Fingerprints Are Usernames, Not Passwords (2013)
#99Earlier quoted context omitted.
Very few thieves would go that far, and they would almost certainly give you an opportunity to unlock the phone for them instead. Most people would take that opportunity.
Exactly. It doesn't matter how strong your password is when there is a gun in your face.
Re: Fingerprints Are Usernames, Not Passwords (2013)
#100Earlier quoted context omitted.
Fingerprints can easily be acquired, if that weren't the case they wouldn't be extensively used in crime scene investigation. When fingerprints were supposed to be used as authentication, together with an ID card, in Germany, the German Chaos Computer Club acquired the fingerprint of the minister of the interior from a used glass and spoofed a reader with it by transfering the print to some adhesive tape.
I think what op means is that if you find someone's password, you can type it into their device and you are in. Total breaking in time 1h.