Given that the authentication methods are "differently secure," wouldn't it be good if we were offered the option to combine them and require both for unlock? I would love to use Face ID + PIN or Touch ID + PIN for better security.
Face ID, Touch ID, No ID, PINs and Pragmatic Security
131–140 of 314 posts
Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security
#132Much appreciated to the original author - it takes a good deal of time and effort to write something that lucid. Thanks.
Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security
#133Stolen iPhones should be worthless. Apple need to create a system where stolen phones can be reported to them, Apple can then contact the owner/verify they are stolen. And then add them to a stolen list and disable calling/apps on those phones. And display an overlay on the screen THIS PHONE IS STOLEN. Every iphone would come with an validate phone feature that is accessible even when locked that can authenticate the…
Even a DFU restore of the device won't help a thief, as the activation process will simply ask for your iCloud login and will display a "Message From Owner" that you can set at icloud.com indicating the device was stolen, making it much harder for someone to purchase and claim ignorance about the origins.
Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security
#134Near-field worn devices. http://nfcring.com is an example of what I have in mind. What I'd like to see is this tied into an identity system, such that the ring (or other very-hard-to-misplace, but replaceable and discardable) token is not itself an identity, but rather an access token to an identity store which can present any given identity to any given system. That might be a consistent identity across multiple ses…
The way I'm envisioning it:
1. Physically touch the object you want to authenticate to. (E.g. Computer, payment terminal, smart lock, etc.) Watch uses capacitive coupling to bootstrap a Bluetooth connection to that device.
2. Device requests authentication & authorization from Watch.
3. Watch either authenticates you instantly (for lower security applications), or requests you to confirm the transaction with your fingerprint/face/PIN (higher security applications)
This method would also enable a lot of other neat tricks to further increase security, like checking your heart rate and refusing to authenticate if you're asleep or the watch isn't strapped to your wrist anymore, requiring additional authentication methods to unlock your watch after you take it off, displaying the dollar amount for monetary transactions on your watch when asking for approval, etc.
Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security
#135Given that the authentication methods are "differently secure," wouldn't it be good if we were offered the option to combine them and require both for unlock? I would love to use Face ID + PIN or Touch ID + PIN for better security.
There still must be another mechanism to access it like a password. What if the camera fails? What if you get punched in the face that day?
Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security
#1361 in 1 million FAR (false acceptance rate) vs 1 in 50,000 is pretty misleading (as is Apple tradition). Do you think someone trying to hack into your phone would shoot 1 million random pictures/3D profiles made from Facebook pictures at your phone, or do you think it's far more likely they will already start with your profile made from online pictures? That will likely make the success rate even higher than with fing…
Regarding the false acceptance rate, they would not specify and compare to the already-known Touch ID FAR just for no reason. Logic behind the number is not that someone would actually try one million times (IIRC - just 5 failures will wipe keying material and force passphrase entry), but rather, they're saying derived data for Touch ID had 50,000 possibilities, and there are 1,000,000 possibilities for the Face ID derived data.
Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security
#137This article doesn't really say much of anything. Troy pretty much just summarized a few slides from the Apple event and then ended the article saying he was going to buy an iPhone X and is interested to see how Face ID turns out. I really gained nothing from reading this.
The other arguments people are making tend to be very fanciful scenarios that don't apply to normal people (state actors, high quality makeup shops with a perfect face mold of your face, etc).
It may not be perfect but like TouchID it's probably way better than the alternative.
Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security
#138Nice article. However: > It's alarming not just because the number is so low, but because Dropbox holds such valuable information for so many people. I'd suggest that Dropbox users somewhat self select for those not as concerned about security as others. And more concerned about availability. Dropbox does not encrypt your data server side (or at the very least, can easily decrypt it). And they have proponents of warr…
> Dropbox does not encrypt your data server side (or at the very least, can easily decrypt it). I think claims like this need to be backed up. Now, obviously a biased source, but Dropbox itself says this: "Each file is split into discrete blocks, which are encrypted using a strong cipher. Only blocks that have been modified are synced. Each individual encrypted file block is retrieved based on its hash value, and an…
The issue with Dropbox is that they also have access to your encryption keys, which means they can easily decrypt and access your files, at their discretion.
According to Drew Houston (Dropbox CEO), they need access to your files to offer features like search, to be able to better understand how you're using the service, ability to integrate with third-parties, and for law enforcement. Some of these "trade-offs" are mentioned by Mr. Houston himself in this interview when responding to criticism from Edward Snowden a few years ago: https://techcrunch.com/2014/11/04/dropboxs-drew-houston-resp...
More to the point, giving Dropbox (and their affiliates and trusted third-parties) permission to access to your files is a key provision of the Dropbox terms of service:
Our Services also provide you with features like photo thumbnails, document previews, commenting, easy sorting, editing, sharing and searching. These and other features may require our systems to access, store and scan Your Stuff. You give us permission to do those things, and this permission extends to our affiliates and trusted third parties we work with.
As Mr. Houston said in the article referenced above, if you want better encryption there are alternatives.
Disclaimer: I work at Sync.com
Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security
#139Earlier quoted context omitted.
I unlock the phone while it's still in my pocket, by the time it reaches eye level, it's already unlocked. And with a few muscles memory tricks, there's even a chance I have opened the right app without even looking in the fraction of a second it took me to take the phone out of my pocket.
I've actually never seen anyone doing that. I don't think that's a valid argument against Face ID. It's still faster than a PIN code and (seems) more secure than touch ID.
Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security
#140Stolen iPhones should be worthless. Apple need to create a system where stolen phones can be reported to them, Apple can then contact the owner/verify they are stolen. And then add them to a stolen list and disable calling/apps on those phones. And display an overlay on the screen THIS PHONE IS STOLEN. Every iphone would come with an validate phone feature that is accessible even when locked that can authenticate the…
I'm guessing they are still useful for parts though? Screens, batteries, cameras....all of that still works even if the motherboard is disabled.