Live data from Hacker News

Face ID and Touch ID for the Web

webkit.org

131–140 of 371 posts

Re: Face ID and Touch ID for the Web

#131
post #71
post #50

Earlier quoted context omitted.

> I would definitely stay away from any "Sign in with Apple". I would stay away from any "Sign in with.." service as a user and as a product owner. You're affectively giving away a major control of your users to a third party.

As a product owner, why wouldn't I want to piggyback on the millions of dollars of R&D + security that the big companies have put in? And as a user, why would I trust my password to the website that rolled their own authentication over the big companies?

Well one issue as a user is trying to remember which third-party auth was used when I first created the account (did I use Facebook? Google? Twitter?).

Re: Face ID and Touch ID for the Web

#132

Earlier quoted context omitted.

Biometrics fails every test for a password. 1) A password is secret 2) You don't leave copies of it lying around everywhere 3) You can change it periodically 4) If discovered, it can't be traced back to you No, biometrics can only be a username. It can never be an acceptable password.

It falls short, because biometrics passwords. As I said, biometrics == identity. Compare biometrics with identity: 1) Your identity is not secret. Your mother knows you, your entire school knows you, your neighbour knows you, when you go anywhere the police may ask for your ID at any time and knows you. Biometrics is the same. 2) You don't hide every day from the world. You don't cover your face (ok maybe before COVI…

> It falls short, because biometrics passwords. As I said, biometrics == identity.

This is just dogma, it's not based on the actual implementation details.

TouchID for the web requires: Something you are (biometric), and something you have (Your phone/ computer).

If someone "Discovers" my fingerprints, they are worthless without the phone/ computer which has the Secure Enclave I've matched them to. If my phone is stolen, I can invalidate the entire device as a method of authentication.

Re: Face ID and Touch ID for the Web

#133

I would never use this for anything sensitive. Bad actors can get your face and your fingerprint. Some of them already have it (governments, banks, Apple, Facebook, etc). And changing your face or fingerprint is practically impossible.

Getting your face (and it has to be a high resolution 3D model of your face, not just a photograph) or your fingerprint is not enough. They also have to have physical access to one of your devices.

Re: Face ID and Touch ID for the Web

#134
post #103

Earlier quoted context omitted.

You're missing the point of biometrics. Something you are is a form of authentication that only you can use. Your face, fingerprints, blood, retinas are all public but try as you might you can't make another living human with the same features. If your view of fingerprint auth is "a picture of your face is the password" then of course it sounds stupid. It's actually "a face with the correct features attached to an al…

That's trivially refutable. Fingerprints are left everywhere, and can be lifted and reproduced with common household substances (tape, glue etc). A face can be photographed, printed and presented trivially. And so far, biometrics falls far short of a 4/5 digit lock passcode. The entropy in most fingerprint sensors is a few bits. They are famously defeatable. Nothing will change the fact that you cannot keep your face…

It doesn't matter since your fingerprint isn't secret. It's not enough to have a picture of my fingerprint, you have to produce a convincing enough fake of a real human with the right fingerprint.

Take this to meatspace for a second. If you had a security guard sitting at a desk inspecting your hands and taking fingerprints you couldn't trick them with pictures. You can't hold up a picture of my face to a guard and expect that they'll suddenly think you're me. Biometric auth systems are trying to the same thing but without the human.

> They are famously defeatable.

And most locks in wide-use today are also defeatable by amateur locksmiths, that's not really the point. There are sophisticated biometric auth systems that aren't fooled by pictures. FaceID is one example.

Re: Face ID and Touch ID for the Web

#135
If passwords are the original sin, then Face ID and Touch ID are Sodom and Gomorrah.

Authentication is something you KNOW. Strong authentication is something you KNOW, and something you HAVE.

Something you ARE is great for identification, but terrible for authentication. Something you are cannot be changed like a password.

Re: Face ID and Touch ID for the Web

#136
post #33

Earlier quoted context omitted.

"Sign in with Apple" requires a developer account with Apple. Having saw Epic's developer account terminated by Apple, I would definitely stay away from any "Sign in with Apple". (FWIW, the only 2fa with "Sign in with Apple", if you don't own any Apple hardware, is SMS.)

As a user I would prefer no account in most cases. As a distant second, I would prefer the convenience, security, and privacy of Sign in with Apple over Google, Facebook, or the headache of managing yet another web account . As a developer, I use my preferences as a user to steer my choices, but recognize that the world doesn't revolve around Apple so would allow other options. > Having saw Epic's developer account t…

I've had an issue with sign-in with Apple where using an autogenerated emails ruins certain support interactions. One of them was cancelling a subscription service that was eventually resolved (they required me to email their customer support, which I couldn't figure out how to do using the autogenerated email address created by "sign-in with Apple").

Re: Face ID and Touch ID for the Web

#137
post #33

Earlier quoted context omitted.

"Sign in with Apple" requires a developer account with Apple. Having saw Epic's developer account terminated by Apple, I would definitely stay away from any "Sign in with Apple". (FWIW, the only 2fa with "Sign in with Apple", if you don't own any Apple hardware, is SMS.)

As a user I would prefer no account in most cases. As a distant second, I would prefer the convenience, security, and privacy of Sign in with Apple over Google, Facebook, or the headache of managing yet another web account . As a developer, I use my preferences as a user to steer my choices, but recognize that the world doesn't revolve around Apple so would allow other options. > Having saw Epic's developer account t…

> Since I have zero need to deliberately violate Apple's App Story policy, I don't worry about this overmuch.

That may be true today, but their policies are a moving target. Who knows what they'll be like in a year's time?

Re: Face ID and Touch ID for the Web

#138
post #88

Earlier quoted context omitted.

It falls short, because biometrics passwords. As I said, biometrics == identity. Compare biometrics with identity: 1) Your identity is not secret. Your mother knows you, your entire school knows you, your neighbour knows you, when you go anywhere the police may ask for your ID at any time and knows you. Biometrics is the same. 2) You don't hide every day from the world. You don't cover your face (ok maybe before COVI…

I see what you’re saying about real world identity but digital identities don’t [have to] share those constraints. Digital identities can be instantiated and discarded at will.

Not if they're 'secured' by biometrics. Then they are almost trivially subvertable.

Re: Face ID and Touch ID for the Web

#139
post #33

Earlier quoted context omitted.

"Sign in with Apple" requires a developer account with Apple. Having saw Epic's developer account terminated by Apple, I would definitely stay away from any "Sign in with Apple". (FWIW, the only 2fa with "Sign in with Apple", if you don't own any Apple hardware, is SMS.)

As a user I would prefer no account in most cases. As a distant second, I would prefer the convenience, security, and privacy of Sign in with Apple over Google, Facebook, or the headache of managing yet another web account . As a developer, I use my preferences as a user to steer my choices, but recognize that the world doesn't revolve around Apple so would allow other options. > Having saw Epic's developer account t…

> or the headache of managing yet another web account.

Honestly, I find this to be the distant second behind no account. I treat my password manager as my SSO provider in some sense.

Re: Face ID and Touch ID for the Web

#140
post #134

Earlier quoted context omitted.

That's trivially refutable. Fingerprints are left everywhere, and can be lifted and reproduced with common household substances (tape, glue etc). A face can be photographed, printed and presented trivially. And so far, biometrics falls far short of a 4/5 digit lock passcode. The entropy in most fingerprint sensors is a few bits. They are famously defeatable. Nothing will change the fact that you cannot keep your face…

It doesn't matter since your fingerprint isn't secret. It's not enough to have a picture of my fingerprint, you have to produce a convincing enough fake of a real human with the right fingerprint. Take this to meatspace for a second. If you had a security guard sitting at a desk inspecting your hands and taking fingerprints you couldn't trick them with pictures. You can't hold up a picture of my face to a guard and e…

Let's suppose biometrics can be made nearly foolproof. Then somebody goes to all the effort to duplicate one. What then? Suicide I guess.
Post reply on HN