Earlier quoted context omitted.
And many of those hackers (or even one of them) care enough to (a) steal your phone, (b) fake your fingerprints with a cast or whatever? Yeah, I'll risk it...
The OPM hack resulted in millions of people's fingerprints and names being hacked, and now are floating out on the internet for anyone to look up. Individuals who had their fingerprints stolen in that hack can now never use fingerprint readers with any reasonable confidence, since now all a hacker has to do is search that person's name and pull their fingerprint from one of aforementioned databases. > fake your finge…
I recommend against using biometric identification
161–170 of 239 posts
Re: I recommend against using biometric identification
#162https://www.youtube.com/watch?v=nah_3vO0uhM
"That's a very nice hat."
Re: I recommend against using biometric identification
#163> And to be clear, a court in the US cannot force you to give up your passcode. That passcode exists in your head, and yours alone. It is your property, and won’t be used to incriminate you or strong-arm access to your data unless you voluntarily give it up. While technically true this is false in practice. While they can't force you to provide your passcode they can force you to unlock your phone. Francis Rawls has…
That man may still be in prison, but that drive is still encrypted. If you are unwilling to give something you know to someone, no amount of force can take it from you. Had that drive been encrypted using facial biometrics, they could have just knocked him out, glued his eyes open, and taken what they wanted. What works, and what has been deemed legal, as you probably already know, are not mutually exclusive.
Technology can easily be used to encrypt a hard drive to reveal different things for different passwords. TrueCrypt does it.
Plus you can have cryptographic keys stored with friends or beacons that signify you are safe. For example you hide files on your phone before a flight, and to unhide them you need your host's wifi at your destination.
Until the friend or beacon gives the ok, you can either have your phone LOCKED or have all sorts of files that are encrypted and HIDDEN. The computer can be unlocked but won't show those files.
Why isn't this technology widespread? YOU CANT WHACK EVERYONE!
Re: I recommend against using biometric identification
#164> Today Apple announced its new FaceID technology. It’s a new way to unlock your phone through facial recognition. This line makes it sound like android hasn't had this feature for years.
Re: I recommend against using biometric identification
#165Earlier quoted context omitted.
To add more examples to this, Florida courts have also ruled that you can be imprisoned for not giving police access to your phone.[1] The "police can't force you to give up your passcode" misconception stems from a case in Virginia from 2014 [2], and while that may still be the case in Virginia, it does not mean you can just say "my phone is locked with a passcode, fuck off cop" in every other jurisdiction. 1: https…
Hmm, I guess I could just not carry a phone. Or just have it factory reset every morning automatically and not put any personal data on it. I hardly store anything on my phone anyway and use it pretty rarely so it wouldn't make much difference. What a world we live in.
s/world/country/ fixed that for you.
Re: I recommend against using biometric identification
#166Earlier quoted context omitted.
The "door lock" analogy ignores the biggest flaw with fingerprints: they're forever. If your door lock is compromised, you can change the key. If someone steals your password, you can change the password. If someone steals your fingerprint, you can never change your fingerprint (same with your face). The other stuff is dead-on: its a "good enough" security measure for phones. But as a security practitioner, the bigge…
>If someone steals your fingerprint, you can never change your fingerprint (same with your face). At what point is stealing a fingerprint, retina print, or face going to be economical enough for the thief that this would be an actual valid concern in 99% of use cases? Both FaceID and TouchID need to read a living person with a pulse in order to authenticate. You can't just take a printout of a fingerprint and drop it…
You're vastly underestimating how valuable access to a person's phone can be. It's not just about quickly wiring money or stealing state secrets but also about building blocks for social engineering campaigns, ad/app fraud, extorsion and all sorts of different things.
And the petty thief who steals your phone doesn't need to have the tools to spoof the biometrics. There just needs to be some criminal organization that does and that's willing to pay petty thieves for stolen phones.
Re: I recommend against using biometric identification
#167Just Realized : Face recognition unlock : Biggest Security Scare - Case 1 : Imagine crossing security check or border crossing. Guards just take your phone and point it to you : UNLOCKED . No need to resis to give passwd - Case 2 : drug the activist and point unconscious victim ! Voila ! - Case 3 : Steal the phone, and change the cover and flash it in front of the real owner ! could go on and on ...
For case 1 - you can disable faceID prior to crossing borders.
Re: I recommend against using biometric identification
#168Earlier quoted context omitted.
The "door lock" analogy ignores the biggest flaw with fingerprints: they're forever. If your door lock is compromised, you can change the key. If someone steals your password, you can change the password. If someone steals your fingerprint, you can never change your fingerprint (same with your face). The other stuff is dead-on: its a "good enough" security measure for phones. But as a security practitioner, the bigge…
https://www.xkcd.com/538/ applies. Neither Touch ID nor passwords keep determined intruders out. If someone really wants to know what's on your phone, they will arrest/kidnap you and threaten you with prison/violence.
Re: I recommend against using biometric identification
#169Earlier quoted context omitted.
No security is going to keep "determined" intruders out. But the point is that you should still strive to achieve "good enough" security. The problem is that while the actual ranking from least secure to most secure is "nothing < touchid/faceid < passcode", Apple's marketing and implementation gives people the false impression that its "nothing < passcode < touchid/faceid", which is bad for security.
I think "nothing So Touch/FaceID isn't better than a good passcode, but maybe it's better than a crappy passcode.
I noticed a distinct improvement in the speed of the TouchID unlock going from an iPhone 6 to a 7, which pretty much reduced all friction to me using it. Apple's marketing fluff suggests FaceID will be "twice as fast" as TouchID.
Re: I recommend against using biometric identification
#170Earlier quoted context omitted.
I think, at some point it gets to the Supreme court which will decide whether it's covered by the 5th amendment or not.
The answer is probably no. Requiring a person to unlock a device is not prohibited by the Fifth Amendment simply because the device contains incriminating information that would otherwise be inaccessible to police. If the police have a valid warrant to search your safe, you are generally required to unlock it for them, even if the safe contains evidence that incriminates you. If you are issued a valid subpoena to pro…