Beyond that, it's pathetic click-bait.
I recommend against using biometric identification
171–180 of 239 posts
Re: I recommend against using biometric identification
#172Just Realized : Face recognition unlock : Biggest Security Scare - Case 1 : Imagine crossing security check or border crossing. Guards just take your phone and point it to you : UNLOCKED . No need to resis to give passwd - Case 2 : drug the activist and point unconscious victim ! Voila ! - Case 3 : Steal the phone, and change the cover and flash it in front of the real owner ! could go on and on ...
Case 1 and 2 are covered with FaceID - you have to be actively looking at the phone, drugged/eyes closed/looking away/etc. won't cut it.
This seems extremely inconvenient for binge drinkers* that need to Uber home or call a friend.
*or light drug users
Re: I recommend against using biometric identification
#173Earlier quoted context omitted.
>If someone steals your fingerprint, you can never change your fingerprint (same with your face). At what point is stealing a fingerprint, retina print, or face going to be economical enough for the thief that this would be an actual valid concern in 99% of use cases? Both FaceID and TouchID need to read a living person with a pulse in order to authenticate. You can't just take a printout of a fingerprint and drop it…
> At what point is stealing a fingerprint, retina print, or face going to be economical enough for the thief that this would be an actual valid concern in 99% of use cases? For the average person who is just securing their phone that only stores pictures of their cat, this isn't a concern, but that's far less than 99%. For pretty much anyone who is logged into their work email/VPN via their phone, or is using fingerp…
Re: I recommend against using biometric identification
#174Earlier quoted context omitted.
>If someone steals your fingerprint, you can never change your fingerprint (same with your face). At what point is stealing a fingerprint, retina print, or face going to be economical enough for the thief that this would be an actual valid concern in 99% of use cases? Both FaceID and TouchID need to read a living person with a pulse in order to authenticate. You can't just take a printout of a fingerprint and drop it…
> Unless you're securing State Secrets or occupy rarefied enough heights that you have a Swiss bank account I don't really see anyone bothering. You're vastly underestimating how valuable access to a person's phone can be. It's not just about quickly wiring money or stealing state secrets but also about building blocks for social engineering campaigns, ad/app fraud, extorsion and all sorts of different things. And th…
Obviously past events are no guarantee of future, but still — most advisories like this frankly come across as fearmongering.
Re: I recommend against using biometric identification
#175Earlier quoted context omitted.
That man may still be in prison, but that drive is still encrypted. If you are unwilling to give something you know to someone, no amount of force can take it from you. Had that drive been encrypted using facial biometrics, they could have just knocked him out, glued his eyes open, and taken what they wanted. What works, and what has been deemed legal, as you probably already know, are not mutually exclusive.
Why do people assume that deniability results in more whacking? Technology can easily be used to encrypt a hard drive to reveal different things for different passwords. TrueCrypt does it. Plus you can have cryptographic keys stored with friends or beacons that signify you are safe. For example you hide files on your phone before a flight, and to unhide them you need your host's wifi at your destination. Until the fr…
Re: I recommend against using biometric identification
#176Never? If Jason Bourne is after you that's probably true. If you're worried about border security, that's maybe true. But for most people, the lock on their phone isn't protecting them from the government, it's protecting them from nosy relatives, a pick pocket, or the guy that finds the phone you left at the bar, or their 4 year old. None of these 'attackers' will ever be sophisticated enough to defeat the biometric…
"sophisticated" here could be as simple as buying a mass-produced 3d filter sized for the dual lens on the iPhone, installing a companion computer program, running it, uploading a video, and then pointing the phone at the screen. If I were your nosy relative, that certainly wouldn't stop me. As with any security break, the first research prototypes may sound sophisticated, but they might not be that far off from prac…
Re: I recommend against using biometric identification
#177Earlier quoted context omitted.
>If someone steals your fingerprint, you can never change your fingerprint (same with your face). At what point is stealing a fingerprint, retina print, or face going to be economical enough for the thief that this would be an actual valid concern in 99% of use cases? Both FaceID and TouchID need to read a living person with a pulse in order to authenticate. You can't just take a printout of a fingerprint and drop it…
> At what point is stealing a fingerprint, retina print, or face going to be economical enough for the thief that this would be an actual valid concern in 99% of use cases? For the average person who is just securing their phone that only stores pictures of their cat, this isn't a concern, but that's far less than 99%. For pretty much anyone who is logged into their work email/VPN via their phone, or is using fingerp…
The most important factor of authentication protecting a mobile device is just possession of the device. Fingerprint or face unlock adds what so far in practice seems to be a decent layer of security. Eventually I expect that it will be improved a lot by greater situational awareness on the part of the device: you won't just have to steal the phone and fool the 3d camera, but do both without ever letting the phone see, hear, or otherwise sense anything suspicious. Which is probably getting into mission impossible territory in most situations.
But even without that, in practice I think your corporate secrets would be considerably better defended by something like face id and device identity than by, say, a password and a regular old 2fa token that are both easily and simultaneously and remotely compromised by sending the target an email from yourcompany-itdept.com asking them to log in.
Re: I recommend against using biometric identification
#178> And to be clear, a court in the US cannot force you to give up your passcode. That passcode exists in your head, and yours alone. It is your property, and won’t be used to incriminate you or strong-arm access to your data unless you voluntarily give it up. While technically true this is false in practice. While they can't force you to provide your passcode they can force you to unlock your phone. Francis Rawls has…
> Francis Rawls has been in prison for two years now over refusing to decrypt a hard drive. People have got to stop martyrizing this guy. He's in jail because the prosecution got a fortuitous decision that says they can hold him as long as they want until he coughs up a password. They aren't fishing for evidence, nor have they used this trick on anyone else. If he went to trial on the evidence already in public, the…
It seems to me that they've intentionally chosen a morally-objectionable individual upon which to build a legal precedent, as anyone who speaks in his defense can have his crime thrown back in their face.
We've heard a lot about these so-called "hashes" that prove the presence of CP. It's also pretty easy to make a probabilistic proof about the likelihood of a hash collision between two non-identical files. I would venture that if you can show mathematically that you're 99.9999999% certain that the files are CP, that would qualify for "beyond a reasonable doubt".
It's incontrovertible that if he's committed the crime for which he's been accused, he should be jailed. If they've already proven that crime, then why isn't he already serving his sentence? Or does the prosecution's case rest upon this one piece of evidence, and if so, is he therefore required to testify against himself in order to avoid indefinite detention?
Re: I recommend against using biometric identification
#179Re: I recommend against using biometric identification
#180Earlier quoted context omitted.
I agree that convenience is the real test of each of these technologies (along with "good enough" security) that lets the majority of people to have a good experience. The biggest concerns for the iPhone (or others) then are things like viewing angle, sunlight, etc... Also, if I were an identical twin (only 0.3% of the population) I would be a bit unhappy that my brother/sister could post anything they wanted on my I…
I don't think you can have a identical twin that is a different sex.