Live data from Hacker News

Fingerprints are Usernames, not Passwords

blog.dustinkirkland.com

101–110 of 261 posts

Re: Fingerprints are Usernames, not Passwords

#101
But wait, the alternative is 4-digit PIN. How exactly is 4-digit password with only digits secure? How easy is it to see it over the shoulder?

The answer is: pretty easy.

Both phone locking technologies are not about securely protecting data, they are about preventing the phone from casual looks when you are away for 5 minutes and left your phone. And TouchID does a better job for this case.

Re: Fingerprints are Usernames, not Passwords

#102
post #34

All these academic arguments about the security of fingerprints are interesting but completely are detached from the day-to-day use of TouchID. I've been using it for about a week or so now. It's incredibly convenient. It unlocks my phone almost instantly. It prevents random people near by phone from being unable to unlock it. If a thief got their hands on it, they'd have a few attempts to unlock it with a fake finge…

As a side note, I'd be worried that anyone can wipe my phone if they get their hands on it for a minute.

Re: Fingerprints are Usernames, not Passwords

#104
post #37
post #34

All these academic arguments about the security of fingerprints are interesting but completely are detached from the day-to-day use of TouchID. I've been using it for about a week or so now. It's incredibly convenient. It unlocks my phone almost instantly. It prevents random people near by phone from being unable to unlock it. If a thief got their hands on it, they'd have a few attempts to unlock it with a fake finge…

s/TouchID/Face Unlock/g and back up about 2 years and you can find all the same things said about Ice Cream Sandwich. It's a cute feature. It's not going to change the world, sell another billion phones, push other companies out of the market, or save anyone from serious attacks. It's probably a good idea to enable it anyway.

[deleted]

Re: Fingerprints are Usernames, not Passwords

#105
post #34

All these academic arguments about the security of fingerprints are interesting but completely are detached from the day-to-day use of TouchID. I've been using it for about a week or so now. It's incredibly convenient. It unlocks my phone almost instantly. It prevents random people near by phone from being unable to unlock it. If a thief got their hands on it, they'd have a few attempts to unlock it with a fake finge…

As a side note, I'd be worried that anyone can wipe my phone if they get their hands on it for a minute.

That's a option that you get to disable.

Re: Fingerprints are Usernames, not Passwords

#106
post #60

Earlier quoted context omitted.

I would be very surprised if it is that high now even with the early adopter skew. Reports say that last year it was around a quarter of smartphone users use passcode locks on their work phone ( http://www.welivesecurity.com/2012/02/28/sizing-up-the-byod-... ). I imagine 5S rates are higher than that, but 90% would be insanely impressive. When it comes to computer security, as usual, people's apathy is the biggest pr…

Isn't passcode required to get exchange email on iOS?

That's an option set by your IT department. Annoyingly, mine does the same thing. It doesn't have to be that way.

Re: Fingerprints are Usernames, not Passwords

#107
post #97

Earlier quoted context omitted.

does touchid have the disadvantage of keeping your friends and family unable to use your phone in cases of emergency? 95% of the time, my phone isnt next to adversaries, but trusted parties. a password or code is transferrable, fingerprint isnt. edit; not 911emergency, but casual situations of full or dirty hands..

You can add ten fingers, or you can give them your code, or they can dial 911 with a fully locked phone. So no, it's slightly easier for a relative to use in an emergency than a typical locked phone.

Mine when locked has a small touch section labeled 'emergency call'. I assume it goes through to 911 (or relevant number). I'm tempted to press it but it's not an emergency. I assumed most phones had something similar.

Edit: I went to it. I leads to a special dialer. Instead of voicemail the button leads to a special emergency contact (or list). It only shows 4 inputs on top so I am guessing that is the limit so you can't dial anything but emergency services (that are 4 numbers or shorter). Then it goes back to my lock screen.

Re: Fingerprints are Usernames, not Passwords

#108
post #37

Earlier quoted context omitted.

s/TouchID/Face Unlock/g and back up about 2 years and you can find all the same things said about Ice Cream Sandwich. It's a cute feature. It's not going to change the world, sell another billion phones, push other companies out of the market, or save anyone from serious attacks. It's probably a good idea to enable it anyway.

Except TouchID, from what I gather, actually works. Not "works" in the sense of keeping bad people out, but "works" in the sense that when I use it my phone unlocks. I tried face unlock briefly on the Google Nexus I've got and disabled it shortly after when I found that it was unreliable. Poor lighting, too much lighting, a bad hair day, it wasn't even at 80% for successful unlocks.

Fake unlock was slow and unreliable when it first came out 2 years ago but is pretty darn good nowadays, and just as fast as TouchID. No, it doesn't work in pitch dark or if you're wearing sunglasses. But I'll take "works 90% of the time" over an unlock feature that requires a hardware component that pretty much locks you into 1 form factor.

Re: Fingerprints are Usernames, not Passwords

#109

Earlier quoted context omitted.

Except TouchID, from what I gather, actually works. Not "works" in the sense of keeping bad people out, but "works" in the sense that when I use it my phone unlocks. I tried face unlock briefly on the Google Nexus I've got and disabled it shortly after when I found that it was unreliable. Poor lighting, too much lighting, a bad hair day, it wasn't even at 80% for successful unlocks.

does touchid have the disadvantage of keeping your friends and family unable to use your phone in cases of emergency? 95% of the time, my phone isnt next to adversaries, but trusted parties. a password or code is transferrable, fingerprint isnt. edit; not 911emergency, but casual situations of full or dirty hands..

You can always just use a PIN to unlock. It's probably safe to assume that Apple has thought this through (no need to remind me of the supposed chaos break-in).

Re: Fingerprints are Usernames, not Passwords

#110

Earlier quoted context omitted.

An iPhone that is wiped, even in DFU mode, requires the Apple ID and password immediately after it is booted for the first time. Basically, a stolen iPhone is only worth the sum of its parts so they can be used to repair other phones.

How does this work? I sold my old iphone to amazon. I never reported it "unstolen" or whatever to apple. Amazon paid me $200 for iPhone parts?

It's new in iOS 7. You'll have to explicitly wipe & reset your iPhone before selling it from now on.

So if it works as advertised, stolen iPhones and iPads will only be worth the sum of their parts.

Post reply on HN