Live data from Hacker News

Fingerprints are Usernames, not Passwords

blog.dustinkirkland.com

191–200 of 261 posts

Re: Fingerprints are Usernames, not Passwords

#191

Earlier quoted context omitted.

Protection against what ? That is the desired behaviour of most people. And if it isn't then you can simple disable the behaviour. It's not like you will lose data since it is backed up to iCloud.

I think you misunderstood. The person entering bogus passwords is not a thief, but an otherwise trusted prankster. For example, a brother.

This has always been available as a setting on iOS and it is not the default. Most companies though will install a profile which enables this to a custom value of retry attempts if you add the company email (typically exchange ) account to your phone

Re: Fingerprints are Usernames, not Passwords

#192
post #154
post #43

"Once your fingerprint is compromised how do you change it?" This is the central question for all biometrics for me and I believe one of the hardest problems to solve. There are many people who believe they are solving this by using ever more intricate biometric identifiers, thus increasing the bar to reproduce them beyond what they believe currently feasible. But I'm yet to see that central question addressed. What…

https://news.ycombinator.com/item?id=6478343 > they'd have a few attempts to unlock it with a fake fingerprint, and then they'd have to enter my code. And if they fail to enter my code 10 times, the phone is wiped. I don't use it, but it seems there's a fallback password after __ failed attemps.

I don't mean to say "what happens if you lose a finger" rather, what happens when your biometric key has been compromised. You can only move on to so many unique body parts before you're out of key changes.

Re: Fingerprints are Usernames, not Passwords

#193
post #154
post #43

"Once your fingerprint is compromised how do you change it?" This is the central question for all biometrics for me and I believe one of the hardest problems to solve. There are many people who believe they are solving this by using ever more intricate biometric identifiers, thus increasing the bar to reproduce them beyond what they believe currently feasible. But I'm yet to see that central question addressed. What…

https://news.ycombinator.com/item?id=6478343 > they'd have a few attempts to unlock it with a fake fingerprint, and then they'd have to enter my code. And if they fail to enter my code 10 times, the phone is wiped. I don't use it, but it seems there's a fallback password after __ failed attemps.

I don't mean to say "what happens if you lose a finger" rather, what happens when your biometric key has been compromised. You can only move on to so many unique body parts before you're out of key changes.

Re: Fingerprints are Usernames, not Passwords

#194
post #151
post #108

Earlier quoted context omitted.

Fake unlock was slow and unreliable when it first came out 2 years ago but is pretty darn good nowadays, and just as fast as TouchID. No, it doesn't work in pitch dark or if you're wearing sunglasses. But I'll take "works 90% of the time" over an unlock feature that requires a hardware component that pretty much locks you into 1 form factor.

The problem is that you need to think about this when you unlock your phone. With TouchID you always unlock your phone with your finger.

"With TouchID you always unlock your phone with your finger"

With glove, dirty or too much sweat, I believe it does not work. So, it's not 'always'.

Re: Fingerprints are Usernames, not Passwords

#195
post #86

Earlier quoted context omitted.

Okay, but if you steal a phone on the subway, why would you even bother unlocking it? Just sell it on ebay as a locked phone. Some bored teenagers will buy them up, unlock them, wipe them and then resell them for a few dollars more.

If Find My iPhone is on, that locked phone is essentially a brick, it cannot be activated even if completely wiped, since its still associated with your Apple ID on the server side. You need to be able to sign in with the Apple ID to remove the association.

Heh. So you think...

I've already done that service for another, using some auto-unlocking tools. Takes all but 5 seconds, including USB negotiation. And it even gets past sim-locks.

Re: Fingerprints are Usernames, not Passwords

#196
post #34

All these academic arguments about the security of fingerprints are interesting but completely are detached from the day-to-day use of TouchID. I've been using it for about a week or so now. It's incredibly convenient. It unlocks my phone almost instantly. It prevents random people near by phone from being unable to unlock it. If a thief got their hands on it, they'd have a few attempts to unlock it with a fake finge…

> And if they fail to enter my code 10 times, the phone is wiped.

You must not have kids, because that statement scares the shit out of me.

Re: Fingerprints are Usernames, not Passwords

#198
post #34

All these academic arguments about the security of fingerprints are interesting but completely are detached from the day-to-day use of TouchID. I've been using it for about a week or so now. It's incredibly convenient. It unlocks my phone almost instantly. It prevents random people near by phone from being unable to unlock it. If a thief got their hands on it, they'd have a few attempts to unlock it with a fake finge…

I think your response raises an issue of perspective. Are we focusing on fingerprint technology from a user's point of view - or are we considering its implications over many years? This reminds me of certain U.S. Supreme Court decisions. As someone who's interested in constitutional law, I often find myself defending things that seem trivial and nitpicky. Why does it matter if the police enter one drug dealer's home…

Consider the thorny issues of courts forcing people to turn over passwords to decrypt phones to implicate themselves. Typically, it's a constitution tarpit as you should not be forced to implicate yourself.

However, your fingerprint is a username in that case because it is all over the place. The police already have it. Don't be fooled, there are certainly kits being sold to law enforcement to dupe TouchID. You're data is less protected from those that you'd probably prefer not have easy access to it now.

Re: Fingerprints are Usernames, not Passwords

#199
post #46

Earlier quoted context omitted.

Uh, no. Of course it's doesn't prevent theft. (Though the new 'wipe the phone in 10 tries' thing may deter it, separate from TouchID, I'm not sure.) The point is that with TouchID (as opposed to no passcode) the thief will not be able to send porn to my mom or read my text messages before they wipe the phone.

And with iOS7 they're going to have a harder time wiping it because phones are now locked to your Apple account. So they need your Apple account ID and password to wipe it.

I wonder how much targeted attacks to recover that go for on the black market? Would the phone thief still make a profit?
Post reply on HN