Live data from Hacker News

I recommend against using biometric identification

medium.freecodecamp.org

11–20 of 239 posts

Re: I recommend against using biometric identification

#11
Oh, ha! In the winter when wearing gloves or if my hands are wet, I often swipe my phone open or click to answer a call using the tip of my nose. Guess that's not what this advice is about, though I was briefly happy to think sufficiently many other people had this habit to warrant an cautionary article.

Re: I recommend against using biometric identification

#12
Why you should never unlock your phone with your face...

... basically because in less than 3 months, you will see HN article of someone posting some sort of 3-d photo of your face stuck to a watermelon, and showing you how to fool the IOS and unlock your phone anyway.

Re: I recommend against using biometric identification

#13
Obviously facial recognition and fingerprints aren't as good as a passcode. But they're better than the previous alternative, nothing. Before fingerprint/facial recognition, for the most part the only people who used a passcode were forced to because it was a company phone.

Re: I recommend against using biometric identification

#14

The suggested alternative is to use passcodes, but then there's no way to unlock your phone without making the unlock code plainly visible.

I mean, it's less plainly visible then your face, or even pictures of your face. I bet you there's an algorithm somewhere that can take a picture of your face and turn it into a 3d model. Then you can take that model, 3d print it, then use it to unlock your phone.

I believe this was the exact attack they were talking about preventing with the "we worked with Hollywood mask-makers" line.

Also, as far as I understand, the demo videos are misleading: these systems (this and Windows Hello) are taking infrared pictures of your face, not visible-light pictures. From their perspective, you look like a (3D depth-tested) network of hot capillaries. This is 1. rather hard to recreate with any amount of sculpture-work, and 2. still identifies you "through" things like foundation/concealer creams.

Re: I recommend against using biometric identification

#15

Obviously facial recognition and fingerprints aren't as good as a passcode. But they're better than the previous alternative, nothing. Before fingerprint/facial recognition, for the most part the only people who used a passcode were forced to because it was a company phone.

Ideally there would be a way to use both, as a two-factor auth mechanism. CopperheadOS supported using fingerprint + passphrase/code briefly but it broke when they moved to Android 7 and they never could find the resources to fix it.

Re: I recommend against using biometric identification

#17
Sure, maybe a 8 digit random alphanumeric is better to protect against government agencies but if you're trying to protect against friends/family/co-workers it sounds like a win for the user. Besides, you can always press that power button 5 times and boom, you've entered password only mode.

Re: I recommend against using biometric identification

#18

The suggested alternative is to use passcodes, but then there's no way to unlock your phone without making the unlock code plainly visible.

I mean, it's less plainly visible then your face, or even pictures of your face. I bet you there's an algorithm somewhere that can take a picture of your face and turn it into a 3d model. Then you can take that model, 3d print it, then use it to unlock your phone.

I'm reminded of the excellent James Mickens piece on security, where he mentions the difference between (IIRC, don't have it in front of me) securing against an angry ex, and securing against Mossad.

Sure, there are entities out there who could probably crack this if they were inclined to target you. But is that truly -- and don't be hyperbolic here -- a thing that you worry about on a day-to-day basis due to actual experience of having been personally targeted by those entities? And is it never acceptable for a consumer device to be only "secure against the angry ex" versus "secure against Mossad"?

Re: I recommend against using biometric identification

#20
Just Realized : Face recognition unlock : Biggest Security Scare

- Case 1 : Imagine crossing security check or border crossing. Guards just take your phone and point it to you : UNLOCKED . No need to resis to give passwd

- Case 2 : drug the activist and point unconscious victim ! Voila !

- Case 3 : Steal the phone, and change the cover and flash it in front of the real owner !

could go on and on ...

Post reply on HN