Live data from Hacker News

I recommend against using biometric identification

medium.freecodecamp.org

211–220 of 239 posts

Re: I recommend against using biometric identification

#211

> Today Apple announced its new FaceID technology. It’s a new way to unlock your phone through facial recognition. This line makes it sound like android hasn't had this feature for years.

I have yet to see a single Android phone where this actually functions correctly. We will see if Apple did a better job. It's not who is first, it's who makes something that works reliably.

Samsung's S8 has an iris scanner that works surprisingly well.

But I've noticed that it works well on some people and total trash on others.

Re: I recommend against using biometric identification

#212
post #199
post #111

Earlier quoted context omitted.

The big thing about TouchID and FaceID is that they are great ways of enforcing a higher level of security than nothing... Prior to these technologies many people I knew did not bother having PINs or were using 1234 because remembering a complex PIN or having to type in something long is too laborious.

They are even less convenient for lending a phone to a friend or relative though. These features are change; not a straight improvement. They have different pros and cons compared to a passcode.

You can still use a password though with Touch ID.

Re: I recommend against using biometric identification

#213

> And to be clear, a court in the US cannot force you to give up your passcode. That passcode exists in your head, and yours alone. It is your property, and won’t be used to incriminate you or strong-arm access to your data unless you voluntarily give it up. While technically true this is false in practice. While they can't force you to provide your passcode they can force you to unlock your phone. Francis Rawls has…

Perhaps there could be a way to instantly delete all iphone data with a voice command. Something like "siri delete my iphone code alpha nine x." Or even an undetectable command like "silly sausages" for example. Might that stop a judge from being able to send you to prison indefinitely?

I would bet the judge would consider that destruction of evidence.

Disclaimer: I never studied law

Re: I recommend against using biometric identification

#214

Earlier quoted context omitted.

Ideally there would be a way to use both, as a two-factor auth mechanism. CopperheadOS supported using fingerprint + passphrase/code briefly but it broke when they moved to Android 7 and they never could find the resources to fix it.

I see people saying Apple should allow fingerprint plus passcode, but I've yet to hear someone explain how it would work if it can't read your fingerprint? A longer passcode? Why not just use the longer passcode in the first place.

Fingerprint and pin to unlock, or a passcode.

Re: I recommend against using biometric identification

#215
post #14

Earlier quoted context omitted.

I mean, it's less plainly visible then your face, or even pictures of your face. I bet you there's an algorithm somewhere that can take a picture of your face and turn it into a 3d model. Then you can take that model, 3d print it, then use it to unlock your phone.

I believe this was the exact attack they were talking about preventing with the "we worked with Hollywood mask-makers" line. Also, as far as I understand, the demo videos are misleading: these systems (this and Windows Hello) are taking infrared pictures of your face, not visible-light pictures. From their perspective, you look like a (3D depth-tested) network of hot capillaries. This is 1. rather hard to recreate wi…

Obviously we do not know the exact workings of Apples FaceID, but there certainly is potential for making it very difficult to replicate. But infrared by itself does not reveal much. UV on the other hand, creates an entirely different picture, see this as an example between the two. The first picture, the right side is IR light, the second, the right is UV, and the one revealing hidden features of the face.

http://aplus.com/a/jon-simonassi-infrared-photography-freckl...

Re: I recommend against using biometric identification

#216
post #149

Earlier quoted context omitted.

The answer is probably no. Requiring a person to unlock a device is not prohibited by the Fifth Amendment simply because the device contains incriminating information that would otherwise be inaccessible to police. If the police have a valid warrant to search your safe, you are generally required to unlock it for them, even if the safe contains evidence that incriminates you. If you are issued a valid subpoena to pro…

Thanks for sharing Kerr's articles! I wasn't familiar with this issue, so I read them, and in my opinion, I think he's dead wrong (and the 3rd Circuit ruling). The argument that by disclosing his password, Doe is only admitting, "I know the password," which is a forgone conclusion, is nonsense. That statement necessarily carries with it a number of additional statements, including "Very few other people (if any) also…

With a safe, as with any encrypted document, there are a finite number of keys. I think that invalidates the idea of possession of the password being important, at least from a "purely lawful" point of view.

Read/write access is basically physical access. Anyone with enough resources could accomplish physical access.

It's possible I'm being paranoid, but it seems like most of law is based on series of assumptions. It isn't a purely logical idea, which is why we have so much fun arguing about it. It is fundamentally the hope of writing down logic in a language that doesn't, unambiguously, contain it.

Re: I recommend against using biometric identification

#217

> And to be clear, a court in the US cannot force you to give up your passcode. That passcode exists in your head, and yours alone. It is your property, and won’t be used to incriminate you or strong-arm access to your data unless you voluntarily give it up. While technically true this is false in practice. While they can't force you to provide your passcode they can force you to unlock your phone. Francis Rawls has…

Fuck, that is absolutely nauseating. What's worse is that trustworthy deniable encryption - which would solve this - is practically non-existent now that TrueCrypt is gone.

Here is another project that is quite simple and works pretty well: https://github.com/dolanor/scubed

Re: I recommend against using biometric identification

#218
post #149

Earlier quoted context omitted.

The answer is probably no. Requiring a person to unlock a device is not prohibited by the Fifth Amendment simply because the device contains incriminating information that would otherwise be inaccessible to police. If the police have a valid warrant to search your safe, you are generally required to unlock it for them, even if the safe contains evidence that incriminates you. If you are issued a valid subpoena to pro…

I think the safe analogy is an excellent way to illustrate the issue. Encrypting a file is essentially the same thing as locking it in a safe in what I believe is the ultimate "eyes of the law" once this gets fully tried.

Encryption is nothing like locking in a safe further in a similar situation I'm pretty sure rather than going to court they just open the safe making the example even more useless.

Re: I recommend against using biometric identification

#219

Earlier quoted context omitted.

Case 1 and 2 are covered with FaceID - you have to be actively looking at the phone, drugged/eyes closed/looking away/etc. won't cut it.

> drugged eyes won't cut it. This seems extremely inconvenient for binge drinkers* that need to Uber home or call a friend. *or light drug users

You can always back up to your password (at least, with TouchID).

Re: I recommend against using biometric identification

#220
post #211

Earlier quoted context omitted.

I have yet to see a single Android phone where this actually functions correctly. We will see if Apple did a better job. It's not who is first, it's who makes something that works reliably.

Samsung's S8 has an iris scanner that works surprisingly well. But I've noticed that it works well on some people and total trash on others.

Did you check the video in that article, the S8 scanner can be easily fooled.
Post reply on HN