Live data from Hacker News

Face ID, Touch ID, No ID, PINs and Pragmatic Security

troyhunt.com

151–160 of 314 posts

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#151
post #58
post #6

what about FaceID + pin? that would mean someone would have to know your pin as well as have access to your face. you also wouldn't have to look so paranoid while entering the pin. and pin by itself would be of little value.

The author started off saying how less than 1% of Dropbox users use two-factor authentication. What good is such a scheme when nobody is going to use it?

Heck there are a lot of people who don't use TouchID on iPhones. There are a lot of people who don't use ANYTHING.

I think you're right that the number of people who would use such a system is trivial (compared to sales).

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#153
post #107

Earlier quoted context omitted.

I've actually never seen anyone doing that. I don't think that's a valid argument against Face ID. It's still faster than a PIN code and (seems) more secure than touch ID.

You've never seen someone unlocking their phone while they're taking it out ? It's fast, you might have missed it.

as fast as Face ID probably. I know I've seen people unlocking their phone by mistake in their pockets for sure.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#154
The only secure thing is a thing that only you know and only you can verify even if you are freely observed.

That is, shared secrets between you and your trusted device (meaning passwords) are the singular thing that provide authentication securely. Your password cannot be extracted from your head (yet).

That being said, if your risks are mundane then the benefits of biometric authentication far outweigh constant password input, not to mention that constantly entering your password exposes you to other side-channel attacks.

Biometrics for simple access, passwords for changes, modifies and access to sensitive information.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#155
post #39
post #30

Earlier quoted context omitted.

> I'd suggest that Dropbox users somewhat self select for those not as concerned about security as others. And more concerned about availability. I would rather say that Dropbox is being used by many people without tech knowledge. And while they might be concerned about security, they often just don't know how improtant 2 factor authentication is. At least that's what I can see for some friends & family.

eeh, since when does u2a protect against back-end breaches? thats just a security layer against phishing or password leaks... don't get me wrong, i'd advice everyone to use it for anything remotely critical, because its pretty easy to setup and live with, but it really doesnt help against state actors or hackers that compromised the data servers.

A Dropbox hack is nothing most users have to protect themselves against. Same as with a google breach where GMail data gets leaked.

As a personal user of no special interest, no one would use a potential Dropbox vulnerability to just get your data. If you secure your end you'll be fine. That's different for big corporations or people with a public profile (e.g. politicians). In this case you have to ensure that malicious actors with a lot of money and knowledge cannot gain access. But then again, self hosting is likely less secure than Dropbox or Google.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#156

The only secure thing is a thing that only you know and only you can verify even if you are freely observed. That is, shared secrets between you and your trusted device (meaning passwords) are the singular thing that provide authentication securely. Your password cannot be extracted from your head (yet). That being said, if your risks are mundane then the benefits of biometric authentication far outweigh constant pas…

I know several techniques that would be highly efficient in extracting my password from my head. Some don’t even require physical access. (This is a cryptic way of saying that credible threats of violence or actual violence would compel me pretty quickly to tell my PIN.)

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#157

The only secure thing is a thing that only you know and only you can verify even if you are freely observed. That is, shared secrets between you and your trusted device (meaning passwords) are the singular thing that provide authentication securely. Your password cannot be extracted from your head (yet). That being said, if your risks are mundane then the benefits of biometric authentication far outweigh constant pas…

The ease and quality of video surveillance from cell phones makes me think passwords are not that secure if other people or devices can observe you entering them.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#158
post #105
post #43

Earlier quoted context omitted.

my phone is currently sat on my desk, about 10 inches from my right arm. I can, and do, check messages on it, by only repositioning my arm to unlock it. I easily read any messages by glancing at the phone, never coming into any decent imaging range.

If you have a mac you can use Messages to check your message on your laptop directly.

Pretty much everyone at your standard 9-5 office job has their personal phone with them all the time and their personal computer with them none of the time.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#159

The only secure thing is a thing that only you know and only you can verify even if you are freely observed. That is, shared secrets between you and your trusted device (meaning passwords) are the singular thing that provide authentication securely. Your password cannot be extracted from your head (yet). That being said, if your risks are mundane then the benefits of biometric authentication far outweigh constant pas…

I wonder if you could hack a person's password from their mind by forcing them to go through the alphabet and monitoring their heart rate / brain activity for each letter of their password. There must be a way to detect based on their reaction when you're on the right character, like a lie detector.

I mean, I guess at that point you could just torture it out of them, but I wonder if this could work as a method that wouldn't count as torture.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#160
post #8

For me it's not so much the paranoia or the degree of security (which is an arguable point in itself) but the commodity of it. Touch ID lets me unlock my devices without having to re-position my upper body or move them in (practically) any way, and Face ID feels awkward (I'm typing this on the device that is likely an exception to that - a Microsoft Surface Pro - and Windows Hello's face recognition works beautifully…

I wonder if you can Face ID to work with your butt or other body parts, similar to how people got Touch ID to work for certain "non-thumb" parts of the body.
Post reply on HN