Live data from Hacker News

I recommend against using biometric identification

medium.freecodecamp.org

111–120 of 239 posts

Re: I recommend against using biometric identification

#111
post #84

Never? If Jason Bourne is after you that's probably true. If you're worried about border security, that's maybe true. But for most people, the lock on their phone isn't protecting them from the government, it's protecting them from nosy relatives, a pick pocket, or the guy that finds the phone you left at the bar, or their 4 year old. None of these 'attackers' will ever be sophisticated enough to defeat the biometric…

The big thing about TouchID and FaceID is that they are great ways of enforcing a higher level of security than nothing... Prior to these technologies many people I knew did not bother having PINs or were using 1234 because remembering a complex PIN or having to type in something long is too laborious.

Re: I recommend against using biometric identification

#112
post #67
post #65

Earlier quoted context omitted.

Android has pretty good profile support, I have my own profile, a guest one which is wiped when you logout, and one for my kids which can't buy things. Works pretty well for me, there's a little profile icon in quick settings to switch

Nice! That must be a new feature? It had no such thing, the last time I used Android. Err... I use a Windows phone, even though I'm normally a Linux user. I kinda like it.

I’ve seen it on Lineage OS, but it might be tablet-only.

Re: I recommend against using biometric identification

#114

> And to be clear, a court in the US cannot force you to give up your passcode. That passcode exists in your head, and yours alone. It is your property, and won’t be used to incriminate you or strong-arm access to your data unless you voluntarily give it up. While technically true this is false in practice. While they can't force you to provide your passcode they can force you to unlock your phone. Francis Rawls has…

I think, at some point it gets to the Supreme court which will decide whether it's covered by the 5th amendment or not.

It's likely Rawls' case will make it to the Supreme Court. Let's hope it's sooner rather than later.

Re: I recommend against using biometric identification

#115
post #42

> And to be clear, a court in the US cannot force you to give up your passcode. That passcode exists in your head, and yours alone. It is your property, and won’t be used to incriminate you or strong-arm access to your data unless you voluntarily give it up. While technically true this is false in practice. While they can't force you to provide your passcode they can force you to unlock your phone. Francis Rawls has…

To add more examples to this, Florida courts have also ruled that you can be imprisoned for not giving police access to your phone.[1] The "police can't force you to give up your passcode" misconception stems from a case in Virginia from 2014 [2], and while that may still be the case in Virginia, it does not mean you can just say "my phone is locked with a passcode, fuck off cop" in every other jurisdiction. 1: https…

Hmm, I guess I could just not carry a phone. Or just have it factory reset every morning automatically and not put any personal data on it. I hardly store anything on my phone anyway and use it pretty rarely so it wouldn't make much difference. What a world we live in.

Re: I recommend against using biometric identification

#116
post #58

I would personally like to have groups of things that can be unlocked - that I can define - Nothing - essential what's on lock (weather, maybe news headlines) - Face - basic stuff - games, calculator, News apps - Fingerprint - mail, calendar, text message, browser - Pass code - banking, settings A one all seems backward - there are something things I don't want to protect at all (don't care if someone can access) on…

I am not sure why phones haven't been made with different profiles. Yesterday (?), someone here mentioned they wanted to be able to give the (presumed) cops a phone that was blank. I pointed out that was a horrible idea, but didn't really explain why. If it is a totalitarian regime, they'll just kill you. If you're ever really in such a situation, a blank phone is probably the worst thing you can give them. Instead,…

> Instead, why not a dummy profile that's complete with user activity, social media presence, and showing active harmless use? Why not multiple profiles?

And where do you suppose this data will come from? Maintaining something of a plausible and active social media presence is not without it's efforts, nor is creating a profile that would stand up to some scrutiny.

If people aren't really looking it won't matter much, but if they are and getting something that seems fake it might end getting you in much more trouble.

Re: I recommend against using biometric identification

#117

> And to be clear, a court in the US cannot force you to give up your passcode. That passcode exists in your head, and yours alone. It is your property, and won’t be used to incriminate you or strong-arm access to your data unless you voluntarily give it up. While technically true this is false in practice. While they can't force you to provide your passcode they can force you to unlock your phone. Francis Rawls has…

Fuck, that is absolutely nauseating.

What's worse is that trustworthy deniable encryption - which would solve this - is practically non-existent now that TrueCrypt is gone.

Re: I recommend against using biometric identification

#118
I agree but keep in mind that this same principal applies to TouchID, which is what FaceID is replacing. FaceID is so much better than TouchID in so many aspects. Less false positives, it works even if your fingers are wet, and it's a natural behavior to look at the screen.

Both TouchID and FaceID is trying to protect from complete stranger. I know that with FaceID (if it does exactly what the video suggests) it will be a harder challenge to unlock.

Re: I recommend against using biometric identification

#119
post #30

Op completely misses how insecure a four digit pin is for prying eyes. If I work in the same office as you, or share any space with you at all, I can pretty much guarantee I can easily sneak a glimpse at your pin when you enter it.

1. It's 6 digits now, and not 4.

2. I can also better hide myself entering the pin

3. As mentioned in other places, unlike a fingerprint or face; you can easily change pin codes.

In an ideal world, facial recognition or touch id would serve as identification in addition to the pin code.

Re: I recommend against using biometric identification

#120
post #84

Never? If Jason Bourne is after you that's probably true. If you're worried about border security, that's maybe true. But for most people, the lock on their phone isn't protecting them from the government, it's protecting them from nosy relatives, a pick pocket, or the guy that finds the phone you left at the bar, or their 4 year old. None of these 'attackers' will ever be sophisticated enough to defeat the biometric…

> I think people need to adjust their security policies to reflect the actual security threats they're likely to face, and for most people Touch ID or FaceID are more than adequate. Sounds like you work for Equifax. (= Look, real security threats are out there -- even if you don't want to acknowledge them. Phones have too much sensitive data, photos, bank accounts -- now the ability to pay via text message. It's just…

Sure, but has there been a single case of someone's bank account being robbed because they lost their phone, and someone went through the effort to collect and impersonate their fingerprint to unlock it?

You could be shot at random too, but I'm betting you didn't wear a bullet proof vest today, unless you have cause to think someone is determined to harm you.

And don't I wish that my credit info requires a fingerprint to access. That'd be a big step up!

Post reply on HN