Live data from Hacker News

I recommend against using biometric identification

medium.freecodecamp.org

151–160 of 239 posts

Re: I recommend against using biometric identification

#151
post #30

Op completely misses how insecure a four digit pin is for prying eyes. If I work in the same office as you, or share any space with you at all, I can pretty much guarantee I can easily sneak a glimpse at your pin when you enter it.

1. It's 6 digits now, and not 4. 2. I can also better hide myself entering the pin 3. As mentioned in other places, unlike a fingerprint or face; you can easily change pin codes. In an ideal world, facial recognition or touch id would serve as identification in addition to the pin code.

https://www.schneier.com/blog/archives/2016/11/using_wi-fi_t...

Pins are basically useless to anyone determined, no matter how much you try to hide it. There's no real bullet-proof security except for a really long password, but how many people are going to do that realistically?

Re: I recommend against using biometric identification

#152

The suggested alternative is to use passcodes, but then there's no way to unlock your phone without making the unlock code plainly visible.

I mean, it's less plainly visible then your face, or even pictures of your face. I bet you there's an algorithm somewhere that can take a picture of your face and turn it into a 3d model. Then you can take that model, 3d print it, then use it to unlock your phone.

I think the difficulty of making that 3d model is a bigger barrier than the lower visibility of a passcode. On my Android phone, it even helpfully highlights each digit as I'm entering it on the lock screen.

Re: I recommend against using biometric identification

#153

Earlier quoted context omitted.

I mean, it's less plainly visible then your face, or even pictures of your face. I bet you there's an algorithm somewhere that can take a picture of your face and turn it into a 3d model. Then you can take that model, 3d print it, then use it to unlock your phone.

I'm reminded of the excellent James Mickens piece on security, where he mentions the difference between (IIRC, don't have it in front of me) securing against an angry ex, and securing against Mossad. Sure, there are entities out there who could probably crack this if they were inclined to target you. But is that truly -- and don't be hyperbolic here -- a thing that you worry about on a day-to-day basis due to actual…

Even worse, your ex probably knows your passcode if you've ever opened your phone in front of them.

Re: I recommend against using biometric identification

#154
post #150

> And to be clear, a court in the US cannot force you to give up your passcode. That passcode exists in your head, and yours alone. It is your property, and won’t be used to incriminate you or strong-arm access to your data unless you voluntarily give it up. While technically true this is false in practice. While they can't force you to provide your passcode they can force you to unlock your phone. Francis Rawls has…

> Francis Rawls has been in prison for two years now over refusing to decrypt a hard drive. People have got to stop martyrizing this guy. He's in jail because the prosecution got a fortuitous decision that says they can hold him as long as they want until he coughs up a password. They aren't fishing for evidence, nor have they used this trick on anyone else. If he went to trial on the evidence already in public, the…

> He's in jail because the prosecution got a fortuitous decision that says they can hold him as long as they want until he coughs up a password.

You call it a fortuitous decision, I call it precedent.

Re: I recommend against using biometric identification

#156

Earlier quoted context omitted.

I think "nothing So Touch/FaceID isn't better than a good passcode, but maybe it's better than a crappy passcode.

I could be wrong, but doesn't a passcode actually encrypt the data (for sure on password manager/banking/etc apps) whereas FaceID/TouchID/ doesn't? And what about hashing? AFAIK you can't really hash biometrics.

With Touch ID and Face ID, you are required to have a passcode. What's the point of Touch ID if it fails and doesn't have any other way into the phone? As for hashing biometrics, Apple has the Secure Enclave which is for storing the biometrics.

Re: I recommend against using biometric identification

#157

> And to be clear, a court in the US cannot force you to give up your passcode. That passcode exists in your head, and yours alone. It is your property, and won’t be used to incriminate you or strong-arm access to your data unless you voluntarily give it up. While technically true this is false in practice. While they can't force you to provide your passcode they can force you to unlock your phone. Francis Rawls has…

What if you legitimately don't know the password?

Re: I recommend against using biometric identification

#158

It's easier to watch people entering their PINs on overhead security camera footage than it is to cheat their biometrics. Dedicated attackers have simpler, more effective options than having to hack your biometrics. Yes, your fingerprint and faceprint are irreplaceable. They're kept device-local for more reasons than just Apple Pay. But make no mistake: It's simpler to record you entering your PIN surreptitiously tha…

How long does security footage last though? It takes only like 3 seconds to type in a PIN so they'd need to keep enough frames to cover that (aside from being lucky enough to have your phone visible to a camera) and I don't imagine they keep full 30fps videos around for long. Do they?

Re: I recommend against using biometric identification

#159

> Today Apple announced its new FaceID technology. It’s a new way to unlock your phone through facial recognition. This line makes it sound like android hasn't had this feature for years.

There's a funny double standard in mobile reporting. It's incredibly common to see non-Apple phones being called "iPhone clones" but I'm seeing very little mention of the iPhone X looking eerily similar to existing bezel-free-with-cut-out designs like the Essential PH-1 and Aquos S2.

Re: I recommend against using biometric identification

#160
post #104
post #84

Never? If Jason Bourne is after you that's probably true. If you're worried about border security, that's maybe true. But for most people, the lock on their phone isn't protecting them from the government, it's protecting them from nosy relatives, a pick pocket, or the guy that finds the phone you left at the bar, or their 4 year old. None of these 'attackers' will ever be sophisticated enough to defeat the biometric…

I agree that convenience is the real test of each of these technologies (along with "good enough" security) that lets the majority of people to have a good experience. The biggest concerns for the iPhone (or others) then are things like viewing angle, sunlight, etc... Also, if I were an identical twin (only 0.3% of the population) I would be a bit unhappy that my brother/sister could post anything they wanted on my I…

I don't think you can have a identical twin that is a different sex.
Post reply on HN