Live data from Hacker News

Face ID, Touch ID, No ID, PINs and Pragmatic Security

troyhunt.com

171–180 of 314 posts

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#172

Earlier quoted context omitted.

Not everybody has fingerprints. I may be the minority here, but I look forward to not having to enter my pin each time.

There are more people who cover their face (e.g. Muslim women wearing burkas) than people who don't have fingerprints. I wish they had both TouchID and FaceID.

Well, they do.

You have to decide which type of biometrics to use when you choose your model, but that's fine for a lot of cases (such as those who wear burkas or those who have no fingerprints).

Hopefully the return period gives people enough time to be sure they've made the right choice.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#173
post #167

Earlier quoted context omitted.

If they created photorealistic masks to defeat the 3D mapping and those didn't work, I feel pretty confident in saying that photos won't work.

I think it would be really cool if it turned out that it could tell the difference between some pairs of identical twins due to seemingly imperceptible differences.

I'm sure it's not 100%, but I'd bet it's close. Certainly by young adulthood the identical twins I've been around have been relatively easy to distinguish.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#174
post #147

I really liked this write-up because it focused on the practicality of the various security mechanisms. Most articles I see usually have a blanket statement like "All biometric security mechanisms are bad!". I think this article does a good job comparing the various logins and describing the pros and cons for different people. Specifically, I appreciate the author calling out when people bring up the "What if" edge-c…

Specifically, getting more people to have better security on their devices is a very difficult User Experience problem, and Apple's pretty good at solving these kinds of problems.

TouchID moved the ball forward quite a bit, and FaceID will probably go even further.

Obviously neither provide ultimate security, but Apple is in a strategic advantage since they make the hardware and software to make the barn walls and roof super secure, but it does nothing if the front door is left open.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#175
post #94

Given that the authentication methods are "differently secure," wouldn't it be good if we were offered the option to combine them and require both for unlock? I would love to use Face ID + PIN or Touch ID + PIN for better security.

I've been wondering that too. If possible, it'd be nice to combine username, second-factor, and password, as they all perform different functions that people often ambiguate: - Your username is who you think you are. - Your second-factor (faceprint, thumbprint, keyfob) is who you claim to be. - Your password is your proof.

Setting up a new device does require three factors: Username, Password and a 2FA on an existing device.

But even with a 4 digit PIN most people didn't have PINs set up on their devices, so increasing friction will not result in more security.

If you want max security now, you can simply turn off TouchID or FaceID and us a very long alpha numeric password.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#176
post #94

Given that the authentication methods are "differently secure," wouldn't it be good if we were offered the option to combine them and require both for unlock? I would love to use Face ID + PIN or Touch ID + PIN for better security.

I've been wondering that too. If possible, it'd be nice to combine username, second-factor, and password, as they all perform different functions that people often ambiguate: - Your username is who you think you are. - Your second-factor (faceprint, thumbprint, keyfob) is who you claim to be. - Your password is your proof.

Large public systems could do away with usernames if they assigned random, unique passwords to users out of a large keyspace. Usernames allow the keyspace to be smaller and the keys have less entropy making user chosen keys possible. But then we add key minimum entropy requirements (sometimes using only length as a proxy) in order to combat the freedom given.

Would be interesting to see whether username-less public systems suffer fewer intrusions. Some users would record their passwords in unsafe places, but they couldn't reuse a password eliminating password stuffing as an attack surface.

Of course, if you allow password resets you'd still have a kind of "backup" username presuming a person's email address could be used for the reset. But that wouldn't significantly weaken the security, arguably.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#177
> ...when you do use the biometric options we're about to get into, you're still going to need [a pin] on your phone anyway. For example, every time you hard-reboot an iPhone with Touch ID you need to enter the PIN

This is what has been missing from every discussion of this issue that I've seen so far.

The face scan isn't "insecure" even if you're worried about border searches. Just turn off your phone when you get in the security line! Pin will be required on start.

Pin is also required when plugging into a new computer.

The rest of the time when you're going about your daily life, and are not worried about a government agent spoofing your face or pointing the phone at your face, you can use this nice feature.

Most people will be _less_ secure without it. They don't want to punch a pin every time they want to tap their phone to pay for coffee. So without the face scan feature, they will opt for no security at all.

The reboot/plug-in pin requirements change the discussion quite a bit, but are usually ignored, seemingly so bloggers can state the obvious "but someone can spoof your face!"

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#178

Earlier quoted context omitted.

Find My iPhone + iCloud is what you're describing. Even a DFU restore of the device won't help a thief, as the activation process will simply ask for your iCloud login and will display a "Message From Owner" that you can set at icloud.com indicating the device was stolen, making it much harder for someone to purchase and claim ignorance about the origins.

Can confirm. We ran into this problem in my company as we had contractors setup phones and turn on Find my iPhone. We ended having to do some not so great things to make it so we could use the devices again.

What not-so-great things?

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#179
post #114

Earlier quoted context omitted.

I want this, and also the ability to secure different areas of my phone. I want to be able to set touch or PINs for certain apps, so that I can have multi level security. Why is there so much emphasis on one master password/touch ID/face ID instead of having multiple security checks?

All of my banking apps, among others (e.g. password manager), include options for both pin and touchID auth. Do we not already have what you’re asking for?

Which password manager are you using? 1Password doesn't support TouchID + PIN on iOS, but I wish they would.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#180
post #177

> ...when you do use the biometric options we're about to get into, you're still going to need [a pin] on your phone anyway. For example, every time you hard-reboot an iPhone with Touch ID you need to enter the PIN This is what has been missing from every discussion of this issue that I've seen so far. The face scan isn't "insecure" even if you're worried about border searches. Just turn off your phone when you get i…

On top of this, iOS 11 introduced an emergency mode that is enabled by tapping the standby button five times rapidly. It is easy to do discretely in your pocket, and it locks your phone by requiring your passcode to be entered again.
Post reply on HN