Live data from Hacker News

I recommend against using biometric identification

medium.freecodecamp.org

161–170 of 239 posts

Re: I recommend against using biometric identification

#161
post #108

Earlier quoted context omitted.

And many of those hackers (or even one of them) care enough to (a) steal your phone, (b) fake your fingerprints with a cast or whatever? Yeah, I'll risk it...

The OPM hack resulted in millions of people's fingerprints and names being hacked, and now are floating out on the internet for anyone to look up. Individuals who had their fingerprints stolen in that hack can now never use fingerprint readers with any reasonable confidence, since now all a hacker has to do is search that person's name and pull their fingerprint from one of aforementioned databases. > fake your finge…

People keep saying fingerprints are all over the internet but I have seen no actual proof (1) how you can steal an iPhone fingerprint record (2) how you can use this data to generate a fake fingerprint sufficient to open the iPhone or even (3) copy a fingerprint off of the outside of the phone and open the iPhone.

Re: I recommend against using biometric identification

#163
post #107

> And to be clear, a court in the US cannot force you to give up your passcode. That passcode exists in your head, and yours alone. It is your property, and won’t be used to incriminate you or strong-arm access to your data unless you voluntarily give it up. While technically true this is false in practice. While they can't force you to provide your passcode they can force you to unlock your phone. Francis Rawls has…

That man may still be in prison, but that drive is still encrypted. If you are unwilling to give something you know to someone, no amount of force can take it from you. Had that drive been encrypted using facial biometrics, they could have just knocked him out, glued his eyes open, and taken what they wanted. What works, and what has been deemed legal, as you probably already know, are not mutually exclusive.

Why do people assume that deniability results in more whacking?

Technology can easily be used to encrypt a hard drive to reveal different things for different passwords. TrueCrypt does it.

Plus you can have cryptographic keys stored with friends or beacons that signify you are safe. For example you hide files on your phone before a flight, and to unhide them you need your host's wifi at your destination.

Until the friend or beacon gives the ok, you can either have your phone LOCKED or have all sorts of files that are encrypted and HIDDEN. The computer can be unlocked but won't show those files.

Why isn't this technology widespread? YOU CANT WHACK EVERYONE!

Re: I recommend against using biometric identification

#164

> Today Apple announced its new FaceID technology. It’s a new way to unlock your phone through facial recognition. This line makes it sound like android hasn't had this feature for years.

I have yet to see a single Android phone where this actually functions correctly. We will see if Apple did a better job. It's not who is first, it's who makes something that works reliably.

Re: I recommend against using biometric identification

#165
post #115
post #42

Earlier quoted context omitted.

To add more examples to this, Florida courts have also ruled that you can be imprisoned for not giving police access to your phone.[1] The "police can't force you to give up your passcode" misconception stems from a case in Virginia from 2014 [2], and while that may still be the case in Virginia, it does not mean you can just say "my phone is locked with a passcode, fuck off cop" in every other jurisdiction. 1: https…

Hmm, I guess I could just not carry a phone. Or just have it factory reset every morning automatically and not put any personal data on it. I hardly store anything on my phone anyway and use it pretty rarely so it wouldn't make much difference. What a world we live in.

> What a world we live in.

s/world/country/ fixed that for you.

Re: I recommend against using biometric identification

#166
post #50

Earlier quoted context omitted.

The "door lock" analogy ignores the biggest flaw with fingerprints: they're forever. If your door lock is compromised, you can change the key. If someone steals your password, you can change the password. If someone steals your fingerprint, you can never change your fingerprint (same with your face). The other stuff is dead-on: its a "good enough" security measure for phones. But as a security practitioner, the bigge…

>If someone steals your fingerprint, you can never change your fingerprint (same with your face). At what point is stealing a fingerprint, retina print, or face going to be economical enough for the thief that this would be an actual valid concern in 99% of use cases? Both FaceID and TouchID need to read a living person with a pulse in order to authenticate. You can't just take a printout of a fingerprint and drop it…

> Unless you're securing State Secrets or occupy rarefied enough heights that you have a Swiss bank account I don't really see anyone bothering.

You're vastly underestimating how valuable access to a person's phone can be. It's not just about quickly wiring money or stealing state secrets but also about building blocks for social engineering campaigns, ad/app fraud, extorsion and all sorts of different things.

And the petty thief who steals your phone doesn't need to have the tools to spoof the biometrics. There just needs to be some criminal organization that does and that's willing to pay petty thieves for stolen phones.

Re: I recommend against using biometric identification

#167

Just Realized : Face recognition unlock : Biggest Security Scare - Case 1 : Imagine crossing security check or border crossing. Guards just take your phone and point it to you : UNLOCKED . No need to resis to give passwd - Case 2 : drug the activist and point unconscious victim ! Voila ! - Case 3 : Steal the phone, and change the cover and flash it in front of the real owner ! could go on and on ...

For case 2 - I believe your eyes need to be open for this to work.

For case 1 - you can disable faceID prior to crossing borders.

Re: I recommend against using biometric identification

#168
post #50

Earlier quoted context omitted.

The "door lock" analogy ignores the biggest flaw with fingerprints: they're forever. If your door lock is compromised, you can change the key. If someone steals your password, you can change the password. If someone steals your fingerprint, you can never change your fingerprint (same with your face). The other stuff is dead-on: its a "good enough" security measure for phones. But as a security practitioner, the bigge…

https://www.xkcd.com/538/ applies. Neither Touch ID nor passwords keep determined intruders out. If someone really wants to know what's on your phone, they will arrest/kidnap you and threaten you with prison/violence.

Isn't there a danger of providing 10 wrong passwords and thus trigger the data deletion builtin ?

Re: I recommend against using biometric identification

#169
post #88

Earlier quoted context omitted.

No security is going to keep "determined" intruders out. But the point is that you should still strive to achieve "good enough" security. The problem is that while the actual ranking from least secure to most secure is "nothing < touchid/faceid < passcode", Apple's marketing and implementation gives people the false impression that its "nothing < passcode < touchid/faceid", which is bad for security.

I think "nothing So Touch/FaceID isn't better than a good passcode, but maybe it's better than a crappy passcode.

And TouchID/FaceID that people use is way better than passcodes they do not because they're a pain in the arse.

I noticed a distinct improvement in the speed of the TouchID unlock going from an iPhone 6 to a 7, which pretty much reduced all friction to me using it. Apple's marketing fluff suggests FaceID will be "twice as fast" as TouchID.

Re: I recommend against using biometric identification

#170
post #149

Earlier quoted context omitted.

I think, at some point it gets to the Supreme court which will decide whether it's covered by the 5th amendment or not.

The answer is probably no. Requiring a person to unlock a device is not prohibited by the Fifth Amendment simply because the device contains incriminating information that would otherwise be inaccessible to police. If the police have a valid warrant to search your safe, you are generally required to unlock it for them, even if the safe contains evidence that incriminates you. If you are issued a valid subpoena to pro…

Thanks for sharing Kerr's articles! I wasn't familiar with this issue, so I read them, and in my opinion, I think he's dead wrong (and the 3rd Circuit ruling). The argument that by disclosing his password, Doe is only admitting, "I know the password," which is a forgone conclusion, is nonsense. That statement necessarily carries with it a number of additional statements, including "Very few other people (if any) also have this password" by virtue of what a password is, and "I have read/write access to this hard drive," which when coupled with the previous statement, leads to the conclusion "I wrote the material on this hard drive to this hard drive." Kerr's argument is basically "Doe is only admitting to the premise" while ignoring that an entire chain of reasoning necessarily follows from the premise.
Post reply on HN