Live data from Hacker News

I recommend against using biometric identification

medium.freecodecamp.org

181–190 of 239 posts

Re: I recommend against using biometric identification

#181
Moral of the story, people are bad so don't store anything sensitive on a tiny little device that can be easily taken from you and broken into 100 different ways.

If you insist on storing your leaked NSA documents or whatever on your phone, then you just have to accept that you're exposing yourself to a lot more risk (real or imagined) than you would have if you didn't store that stuff on your phone.

Re: I recommend against using biometric identification

#182
post #149

Earlier quoted context omitted.

I think, at some point it gets to the Supreme court which will decide whether it's covered by the 5th amendment or not.

The answer is probably no. Requiring a person to unlock a device is not prohibited by the Fifth Amendment simply because the device contains incriminating information that would otherwise be inaccessible to police. If the police have a valid warrant to search your safe, you are generally required to unlock it for them, even if the safe contains evidence that incriminates you. If you are issued a valid subpoena to pro…

I think the safe analogy is an excellent way to illustrate the issue. Encrypting a file is essentially the same thing as locking it in a safe in what I believe is the ultimate "eyes of the law" once this gets fully tried.

Re: I recommend against using biometric identification

#183
post #67
post #65

Earlier quoted context omitted.

Android has pretty good profile support, I have my own profile, a guest one which is wiped when you logout, and one for my kids which can't buy things. Works pretty well for me, there's a little profile icon in quick settings to switch

Nice! That must be a new feature? It had no such thing, the last time I used Android. Err... I use a Windows phone, even though I'm normally a Linux user. I kinda like it.

V. 5.x. Lollipop.

Re: I recommend against using biometric identification

#185
post #58

Earlier quoted context omitted.

I am not sure why phones haven't been made with different profiles. Yesterday (?), someone here mentioned they wanted to be able to give the (presumed) cops a phone that was blank. I pointed out that was a horrible idea, but didn't really explain why. If it is a totalitarian regime, they'll just kill you. If you're ever really in such a situation, a blank phone is probably the worst thing you can give them. Instead,…

> Instead, why not a dummy profile that's complete with user activity, social media presence, and showing active harmless use? Why not multiple profiles? And where do you suppose this data will come from? Maintaining something of a plausible and active social media presence is not without it's efforts, nor is creating a profile that would stand up to some scrutiny. If people aren't really looking it won't matter much…

This is the sort of thing AI could do trivially.

Re: I recommend against using biometric identification

#186
post #108

Earlier quoted context omitted.

The OPM hack resulted in millions of people's fingerprints and names being hacked, and now are floating out on the internet for anyone to look up. Individuals who had their fingerprints stolen in that hack can now never use fingerprint readers with any reasonable confidence, since now all a hacker has to do is search that person's name and pull their fingerprint from one of aforementioned databases. > fake your finge…

People keep saying fingerprints are all over the internet but I have seen no actual proof (1) how you can steal an iPhone fingerprint record (2) how you can use this data to generate a fake fingerprint sufficient to open the iPhone or even (3) copy a fingerprint off of the outside of the phone and open the iPhone.

1) you don't, but the iphone secure enclave is not what he's talking about. He means fingerprints on the glass.

2) google "touchid hack" there's videos on YouTube.

3) not super likely as usually you'll only find rough partials, but as previous poster mentioned, there has been government hacks that have leaked biometric data.

Re: I recommend against using biometric identification

#187

Earlier quoted context omitted.

Biometrics is closer to a username.

Where would Genital ID fall on your continuum?

Perhaps I was too flippant. Point being, the “public availability/replicability” of the biometric would seem correlated to the point on the username->password continuum.

This will probably matter less once our future devices can interact with our sci-fi personal nanites, or rfid implants in the meantime.

Re: I recommend against using biometric identification

#188
post #144

Earlier quoted context omitted.

> At what point is stealing a fingerprint, retina print, or face going to be economical enough for the thief that this would be an actual valid concern in 99% of use cases? For the average person who is just securing their phone that only stores pictures of their cat, this isn't a concern, but that's far less than 99%. For pretty much anyone who is logged into their work email/VPN via their phone, or is using fingerp…

Can you please cite sources where Apple marketed TouchId this way? At most Apple was trying to get people to secure their own phones to start with.

Unfortunately I can't find any archives of Apple's website advertising TouchID when it first came out, but as I remember it was touted as "revolutionary, most secure way to protect your phone", etc. Below[1] is the keynote from 2013 when it was announced. At one point the speaker says "Your fingerprint is one of the best passwords in the world." He also says stuff like "this is the most advanced technology ever in an iPhone", refers to TouchID as "very high level of security", etc.

The FaceID marketing is the same. The iPhone X advertisement released today[2] says "your face is now your secure password". The website says "Face ID is so secure you can use it with Apple Pay". During the keynote today they actually even said up until FaceID, TouchID "was the gold standard". About FaceID they said "FaceID is the future of how we will unlock smartphones".

You'll note that nowhere in any of it's materials or even in the deep recesses of it's website does Apple acknowledge that even though Face/TouchID is great, it's still not as good as a strong passcode. The closest they come is during the key note they acknowledge "nothing is perfect, not even biometric", but you'll notice that even this statement subtly tries to imply that biometrics is the highest security available ("not even biometrics").

1: https://youtu.be/X5zt1V7H88I?t=227 2: https://youtu.be/K4wEI5zhHB0

Re: I recommend against using biometric identification

#189
post #144

Earlier quoted context omitted.

> At what point is stealing a fingerprint, retina print, or face going to be economical enough for the thief that this would be an actual valid concern in 99% of use cases? For the average person who is just securing their phone that only stores pictures of their cat, this isn't a concern, but that's far less than 99%. For pretty much anyone who is logged into their work email/VPN via their phone, or is using fingerp…

Biometrics can't be rotated. But they also can't be phished. People have been using "biometrics" to recognize people they trust since the beginning of time, and are pretty rarely fooled. They have also been using passwords since the beginning of time, and have been being compromised since the next day, when someone walked into the enemy camp by accosting a patrolling guard and demanding the password. The most importa…

> Biometrics can't be rotated. But they also can't be phished.

Sure they can. Haven't you ever seen a cop show where the detective tricks the suspect into drinking from a cup of coffee so they can lift the suspect's fingerprint from the cup?

"Hi John, nice to meet you! * shakes hand *" I now have John's fingerprints from where he touched me when he shook my hand.

"Hey John, can you send me a selfie?" I now have a picture of John's face and possibly his iris.

Hell, I bet it won't be long at all until someone finds a way to use the iPhone X's own "TrueDepth" camera to record a 3D scan of the user's face which can then be used to fool FaceID.

Re: I recommend against using biometric identification

#190
post #150

Earlier quoted context omitted.

> Francis Rawls has been in prison for two years now over refusing to decrypt a hard drive. People have got to stop martyrizing this guy. He's in jail because the prosecution got a fortuitous decision that says they can hold him as long as they want until he coughs up a password. They aren't fishing for evidence, nor have they used this trick on anyone else. If he went to trial on the evidence already in public, the…

If it's been proven beyond a reasonable doubt that the drive contains CP, then why don't they just go to trial? It seems to me that they've intentionally chosen a morally-objectionable individual upon which to build a legal precedent, as anyone who speaks in his defense can have his crime thrown back in their face. We've heard a lot about these so-called "hashes" that prove the presence of CP. It's also pretty easy t…

It's worth noting that despite the prosecutors saying "its a foregone conclusion", they have not actually even charged Reynolds with possession of child pornography. It seems to me that while their words say they already have proof, their actions say they don't have any.
Post reply on HN