Live data from Hacker News

Fingerprints are Usernames, not Passwords

blog.dustinkirkland.com

201–210 of 261 posts

Re: Fingerprints are Usernames, not Passwords

#201

Earlier quoted context omitted.

I think your response raises an issue of perspective. Are we focusing on fingerprint technology from a user's point of view - or are we considering its implications over many years? This reminds me of certain U.S. Supreme Court decisions. As someone who's interested in constitutional law, I often find myself defending things that seem trivial and nitpicky. Why does it matter if the police enter one drug dealer's home…

Consider the thorny issues of courts forcing people to turn over passwords to decrypt phones to implicate themselves. Typically, it's a constitution tarpit as you should not be forced to implicate yourself. However, your fingerprint is a username in that case because it is all over the place. The police already have it. Don't be fooled, there are certainly kits being sold to law enforcement to dupe TouchID. You're da…

This is a disadvantage only when you are on trial. That's a pretty extreme contingency, and I think most people who aren't internet privacy advocates wouldn't be particularly worried about their phones, of all things, after they've been arrested and indicted.

Outside the HN bubble, this is an acceptable tradeoff. People who are concerned can continue to use passwords.

Re: Fingerprints are Usernames, not Passwords

#202
post #180
post #38

Earlier quoted context omitted.

I haven't used face unlock but I am going to guess TouchID is much faster and easier. It unlocks almost instantly, you don't have to be in view of the camera, and it doesn't require any extra effort since your finger is already on the home button to wake up the phone.

I've used Face Unlock. It's terrible. It's slow, very inconsistent, doesn't work at all in variety of situations (low light, in pocket) and goofy.

I imagine it wouldn't work very well at all in your pocket. How do you get your face in there anyway?

Re: Fingerprints are Usernames, not Passwords

#203
post #37
post #34

All these academic arguments about the security of fingerprints are interesting but completely are detached from the day-to-day use of TouchID. I've been using it for about a week or so now. It's incredibly convenient. It unlocks my phone almost instantly. It prevents random people near by phone from being unable to unlock it. If a thief got their hands on it, they'd have a few attempts to unlock it with a fake finge…

s/TouchID/Face Unlock/g and back up about 2 years and you can find all the same things said about Ice Cream Sandwich. It's a cute feature. It's not going to change the world, sell another billion phones, push other companies out of the market, or save anyone from serious attacks. It's probably a good idea to enable it anyway.

Certain Japanese cigarette vending machines had photographic age detection algorithms. Japanese children used photos of Bruce Willis to buy cigarettes. Getting a photo of your face would be much simpler than getting your prints.

Re: Fingerprints are Usernames, not Passwords

#204
Most of the comments seem to assume TouchID as implemented today will remain the same in future. Here are a few scenarios that I imagine it may evolve to:

1) Unlock using multiple fingers; 2) Unlock using the same finger repeatedly, but with different pauses between taps, e.g. two short taps, followed by one long tap; 3) Unlock using finger gesture, for example press your thumb, then move clockwise 45 degree; 4) Unlock using a single finger, the iPhone sends a passcode to your iWatch with which you can use to enter.

Such uses of fingerprint would be much more secured, yet still relatively convenient. Losing your fingerprints wouldn't really be a big problem. You only need to change the sequence.

To further the idea, iOS may offer multiple accounts. Family members may have access to a "guest" section, whereas the phone owner has full access. Fingerprints can be used to unlock the appropriate accounts.

Re: Fingerprints are Usernames, not Passwords

#205

Earlier quoted context omitted.

Consider the thorny issues of courts forcing people to turn over passwords to decrypt phones to implicate themselves. Typically, it's a constitution tarpit as you should not be forced to implicate yourself. However, your fingerprint is a username in that case because it is all over the place. The police already have it. Don't be fooled, there are certainly kits being sold to law enforcement to dupe TouchID. You're da…

This is a disadvantage only when you are on trial. That's a pretty extreme contingency, and I think most people who aren't internet privacy advocates wouldn't be particularly worried about their phones , of all things, after they've been arrested and indicted. Outside the HN bubble, this is an acceptable tradeoff. People who are concerned can continue to use passwords.

>Outside the HN bubble, this is an acceptable tradeoff.

I'm glad you have been deemed worthy enough to make that decision for the rest of the population that doesn't understand the implications of what they are getting into.

Re: Fingerprints are Usernames, not Passwords

#206
post #37

Earlier quoted context omitted.

s/TouchID/Face Unlock/g and back up about 2 years and you can find all the same things said about Ice Cream Sandwich. It's a cute feature. It's not going to change the world, sell another billion phones, push other companies out of the market, or save anyone from serious attacks. It's probably a good idea to enable it anyway.

Certain Japanese cigarette vending machines had photographic age detection algorithms. Japanese children used photos of Bruce Willis to buy cigarettes. Getting a photo of your face would be much simpler than getting your prints.

You touch your iphone's screen to use it, right? Getting a latent print isn't exactly difficult.

Re: Fingerprints are Usernames, not Passwords

#207
post #38

Earlier quoted context omitted.

I haven't used face unlock but I am going to guess TouchID is much faster and easier. It unlocks almost instantly, you don't have to be in view of the camera, and it doesn't require any extra effort since your finger is already on the home button to wake up the phone.

> I haven't used face unlock Face unlock is very fast - generally I turn device towards me to start using it and face unlock has unlocked it before I even realise it was locked (less than half a second). When it fails to recognise you, you can enter a pin/password/pattern. There is a menu option to 'Improve Matches' so it can pick up whatever is different this time. Every release has improved dramatically. After my m…

The answer is probably no, but does it work if you've got sunglasses on??

I know that Picasa's face detection works even if I am wearing sunglasses... thats the only reason I ask.

Re: Fingerprints are Usernames, not Passwords

#208
post #60

Earlier quoted context omitted.

I would be very surprised if it is that high now even with the early adopter skew. Reports say that last year it was around a quarter of smartphone users use passcode locks on their work phone ( http://www.welivesecurity.com/2012/02/28/sizing-up-the-byod-... ). I imagine 5S rates are higher than that, but 90% would be insanely impressive. When it comes to computer security, as usual, people's apathy is the biggest pr…

Isn't passcode required to get exchange email on iOS?

At my work they have allowed the TouchID to be used with our security policy. I just haven't shelled out the money to buy a new phone.

Re: Fingerprints are Usernames, not Passwords

#209
I can't help but think that there's a whole segment of HN readers who are thinking as single men. In the context of a family with kids this is a very different thing. My kids have access to my phone and my wife's --which are not locked in any way. I have access to my kid's iphones, ipods and ipads. Having devices locked to fingerprints in any way would be a nightmare. If you have really young kids, its a logistical mess.

I can see it working just fine from the context of a single and otherwise unattached individual. That'd be OK.

...until you have an accident and someone needs to figure out who to contact...but they can't get into your phone.

...or, until you lose your phone and whoever finds it actually wants to figure out who you are in order to return it.

...or any number of other scenarios where you actually want other people to access the device.

There's also the angle of trust. What's your significant other going to think when he/she can't get into your phone without your fingerprint?

Again, I can see it being a really convenient tool for some people. Not sure it is a universally useful thing.

Re: Fingerprints are Usernames, not Passwords

#210
post #136

Earlier quoted context omitted.

I find it amazing that when faced with a general question about a "security" feature the median internet tech nerd responds with an attitude of absolute paranoia (c.f. 4096 bit RSA keys, multi-word pass phrase choices, ssh key forwarding pedantry, general NSA tinfoil hatism....) Except when confronted with an Apple product. Then it's all "Nah bro, relax. No way could you lift a fingerprint from a glossy phone screen"…

It's not at all clear that the absolute paranoiacs and the people saying that it's unlikely that any but a vanishingly small number of regular people will ever have Touch ID hacked are from the same set. When you say it's not "a serious security mechanism", it sounds as if that's defined in some absolute terms. But if the effort to hack it is hundreds of times more difficult than the possible payoff from hacking it (…

> When you say it's not "a serious security mechanism", it sounds as if that's defined in some absolute terms.

You have to understand that the practice of cryptography has always had a military basis; the commercial/private use is ancillary.

So, what's "a serious security mechanism?" Presume you're a military commander during active war, whose battle plans are intercepted by an opposing nation. What is the likelihood, given the opposing nation believes your plan will lead to their complete destruction, that they'll be able to break the security in time to execute a counter-operation? A serious security mechanism is anything that reduces that likelihood.

Post reply on HN