Live data from Hacker News

Fingerprints Are Usernames, Not Passwords (2013)

blog.dustinkirkland.com

91–100 of 106 posts

Re: Fingerprints Are Usernames, Not Passwords (2013)

#91
post #70

Earlier quoted context omitted.

Touch ID only works for a minute or two after your finger is cut off. Touch ID reads the blood vessels, not the fingerprint, meaning it only works for a minute or two after the finger is cut off.

I'm not really interested in being the one on whom someone learns that, though.

Very few thieves would go that far, and they would almost certainly give you an opportunity to unlock the phone for them instead. Most people would take that opportunity.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#92
post #70

Earlier quoted context omitted.

I'm not really interested in being the one on whom someone learns that, though.

Very few thieves would go that far, and they would almost certainly give you an opportunity to unlock the phone for them instead. Most people would take that opportunity.

Exactly. It doesn't matter how strong your password is when there is a gun in your face.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#93

Earlier quoted context omitted.

I think Apple are pretty aware of the limitations - they don't accept TouchID on first login after a restart, for the first purchase after a restart, if it's been 48 hours since an unlock or for resets/major config changes. For that you either need the PIN or, if you've opted for more security, the password. Overall it feels that Apple's take is for day to day login it's better than a four digit PIN and it's better t…

>they don't accept TouchID on first login after a restart That's because the hash of the print is stored on an encrypted volume of some kind, which requires your regular password to decrypt after a cold boot. Once the hash is in memory, the fingerprint can be used instead.

Is it because of that, or is it implemented that way because they wanted to ensure that TouchID couldn't be accepted after a fresh restart? I think you may have the causality backwards, since they could have easily stored things in such a way that your fingerprint worked after a fresh reboot if they wanted to.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#94
post #64

Something I feel that's always missed in these discussions is context: Who is the adversary you're attempting to protect against? Your kids screwing around with your phone? TouchID does the job. Random people screwing around with your phone if they find it? Same thing. Government gets ahold of it? Yeah.. notsomuch. Considering that the primary adversaries of an average smartphone user are other mere mortals, not dedi…

Still, I'd rather not give hardened criminals a reason to cut off my fingers.

I figure a criminal would just rather have you change and disable your password altogether, it takes much less time that way and it's easier to do rather than dealing with carrying around a bloody finger.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#95

Dustin Kirkland gets it. Simplifying his post, there are 3 reasons biometrics are terrible for authentication: 1. Every piece of biometric data is inherently public. (Fingerprints, facial geometry, hand geometry, even DNA) 2. Biometrics require an error threshold as our bodies are always changing (that's like typing a 20char password and having only 15 of them be correct. That's fine! Let them in anyways with 5 incor…

I actually like 2. I wish more things used 2.

My keys are plenty strong, but when I mistype a strong key (which is plausible seeing as I can't see what I'm typing) then I'm fine with sacrificing some strength to just accept it. My key is already well beyond practical attack anyway.

That said, if you WERE to use something like 2, you'd have to be much more diligent about enforcing good passwords, also you'd have to come up with some kinda scheme that could work with "close enough" and not reveal information about the password.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#96
post #6

In the case of Touch ID, please consider that in order to circumvent it, you not only have to be able to fool the Touch ID sensor, you also have to have physical access to the device .

Depends. If you use Touch ID on an app, you could use your own iphone and fool its scanner.

No, you couldn't. That's not how Touch ID works. Apps never get access to the fingerprint or have any way to interact with the Touch ID sensor except to ask it to authenticate the owner of the phone, ie. yourself.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#97
post #63

Something I feel that's always missed in these discussions is context: Who is the adversary you're attempting to protect against? Your kids screwing around with your phone? TouchID does the job. Random people screwing around with your phone if they find it? Same thing. Government gets ahold of it? Yeah.. notsomuch. Considering that the primary adversaries of an average smartphone user are other mere mortals, not dedi…

This a thousand times! When you think about security, you should have in mind who you are protecting against, and the same applies to passwords. Security purists love to advocate that password reuse is evil, but who in the first place is going to be your attacker and for which purpose? For example, in the context of money (online banking, paypal, ebay, etc.) I completely agree that password reuse is evil. But when it…

> Security purists love to advocate that password reuse is evil, but who in the first place is going to be your attacker and for which purpose?

You don't know, that's why password reuse is evil.

Years ago when I made my Facebook account it used the same password as all my other accounts. Now that I use Facebook as an OpenID provider for pretty much any news site I would be exposing myself and my friends to all sorts of attacks if someone found hacked a phpBB forum that I frequented years ago. You could make the argument that only important sites should have unique passwords, but you, your grandmother, and I all have a different definition of important sites.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#98

Something I feel that's always missed in these discussions is context: Who is the adversary you're attempting to protect against? Your kids screwing around with your phone? TouchID does the job. Random people screwing around with your phone if they find it? Same thing. Government gets ahold of it? Yeah.. notsomuch. Considering that the primary adversaries of an average smartphone user are other mere mortals, not dedi…

And you don't think your children will try to hack your fingerprint with a gummy bear? A fingerprint makes a poor password and even a worse ysername. So much for asking your spouse to log in and check something for you

Re: Fingerprints Are Usernames, Not Passwords (2013)

#99

Earlier quoted context omitted.

Very few thieves would go that far, and they would almost certainly give you an opportunity to unlock the phone for them instead. Most people would take that opportunity.

Exactly. It doesn't matter how strong your password is when there is a gun in your face.

Ideally, you will have one that is easy to remember.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#100
post #19

Earlier quoted context omitted.

Fingerprints can easily be acquired, if that weren't the case they wouldn't be extensively used in crime scene investigation. When fingerprints were supposed to be used as authentication, together with an ID card, in Germany, the German Chaos Computer Club acquired the fingerprint of the minister of the interior from a used glass and spoofed a reader with it by transfering the print to some adhesive tape.

I think what op means is that if you find someone's password, you can type it into their device and you are in. Total breaking in time 1h.

While that's true, you can change a broken password, you can't change a fingerprint that easily.
Post reply on HN