Live data from Hacker News

Fingerprints are Usernames, not Passwords

blog.dustinkirkland.com

211–220 of 261 posts

Re: Fingerprints are Usernames, not Passwords

#211

Earlier quoted context omitted.

> a few attempts to unlock it with a fake fingerprint, and then they'd have to enter my code. And if they fail to enter my code 10 times, the phone is wiped. Are you saying that random people can pick up your phone when you go to the bathroom, touch the home button 3 times, and then enter "1111" 10 times, and wipe your phone? Is there some protection against this?

It starts throttling attempts before going full lockdown. But, yeah, don't leave assholes alone with your phone.

There's some aphorism about "assholes" and children which my brain thinks fits here but that same brain won't recall what it is.

Anyhow, my initial thought was, perhaps not an asshole but a child? I could see a child playing with the phone and wiping it in quite short time. But other commenters pointed out it's not the default and there's cloud back-up it doesn't seem a major problem.

Re: Fingerprints are Usernames, not Passwords

#212
post #206

Earlier quoted context omitted.

Certain Japanese cigarette vending machines had photographic age detection algorithms. Japanese children used photos of Bruce Willis to buy cigarettes. Getting a photo of your face would be much simpler than getting your prints.

You touch your iphone's screen to use it, right? Getting a latent print isn't exactly difficult.

Acquiring a high-DPI scan of a fingerprint from someone's phone, printing it to a sheet of plastic with a high-DPI laser printer, then making a copy of the print out of liquid latex doesn't sound easy unless you're in the business of pentesting. Taking a picture of someone (or lifting it from a social network) to access their device does sound relatively easy.

If I was the kind of person who was worried about someone accessing the contents of my phone, I'd simply turn off touch ID and use a long password (or spend less money on a phone that didn't have a feature I wouldn't use).

I've gone down the route of using both a long password and touch ID simply because touch ID works so reliably - I've never had to enter my password. That way someone either needs my long password or a physical copy of my fingerprint to access my device. I'd say that's much better than the 4 digit numerical code I relied on previously - which had been seen by friends and family.

Re: Fingerprints are Usernames, not Passwords

#213

I'm not so sure. How many people are motivated to dupe your fingerprints to get into your iPhone? How many of those people could conceivably get into your iPhone through other ways? Fingerprints are a nice way to keep almost everyone out of your device. And for the rest, well, I really doubt some other locking mechanism would've kept them out.

Identification via fingerprints is fine, it's the authorization to do something that can be problematic. So, unlocking your phone, not too bad, accessing your bank records, not so good. If the fingerprint is the identification that is used to then trigger decryption of securely stored data, it's a lot less secure of a mechanism than a fingerprint AND a password. There was a good recent discussion that fingerprints al…

Terminology quibble. _Authentication_ is what's tricky. Authorization is no problem.

Re: Fingerprints are Usernames, not Passwords

#214
I've been using TouchID for the past few days, although I'm going to disable it before international travel. It works amazingly well. It caused me to set my unlock timeout to 1min vs. 5min.

The biggest annoyance is I keep holding my thumb on the home button on my iPad, then get disappointed when I realize it won't work. I've probably done that 20 times so far.

I really wish I could do "per context security" -- requiring multiple discrete factors based on action and threat. That would be a huge innovation for the iPhone, which would sell the next billion phones, if integrated with Internet services and apps. In my house, maybe not require anything, or just a thumbprint. In my car, same. In a coffeeshop, normal passcode after a few minutes, unless the phone has just accelerated highly, in which case a much higher passcode. At Customs in China, a passphrase held out of country. etc.

A bigger deal than Siri, if slightly less of a deal than Retina, and something a team of 2-5 people could implement before iOS 8. I'd even be willing to work at Apple to do it.

Re: Fingerprints are Usernames, not Passwords

#215

Earlier quoted context omitted.

Consider the thorny issues of courts forcing people to turn over passwords to decrypt phones to implicate themselves. Typically, it's a constitution tarpit as you should not be forced to implicate yourself. However, your fingerprint is a username in that case because it is all over the place. The police already have it. Don't be fooled, there are certainly kits being sold to law enforcement to dupe TouchID. You're da…

This is a disadvantage only when you are on trial. That's a pretty extreme contingency, and I think most people who aren't internet privacy advocates wouldn't be particularly worried about their phones , of all things, after they've been arrested and indicted. Outside the HN bubble, this is an acceptable tradeoff. People who are concerned can continue to use passwords.

Outside technological bubbles, people don't understand the implications of technology in regards to security and privacy. You're speaking about "tradeoffs" however people don't understand the tradeoff and will think fingerprinting is secure, because look, Apple is doing it.

Therefore it is up to us to make the right choices. That we aren't doing it, choosing instead to defend flawed technological improvements and the companies doing it, is very regrettable.

> This is a disadvantage only when you are on trial. That's a pretty extreme contingency

No dude, that's not the only thing that can happen and it's in no way extreme. Many people do go on trial for trivial things (because shit, in the US at least, suing people is a way of life) and your laptop or phone contains your most secret conversations and desires, being the ultimate incrimination tool, a digital fingerprint of your own mind.

And you don't have to be on any trial. You don't even have to be a suspect in an investigation. It can happen and has happened for laptops or phones to be seized for inspection during routine filters, like by the airport security.

Also, in the US you may live under the rule of the law. What about countries where oligarchies rule, countries where corruption is the norm? What about countries like Rusia, China, India or Brazil?

Just today I read about a story about this traffic cop from my own country that had the bad inspiration of doing his job by fining his own boss for ignoring a red light and exceeding the speed limits. He was later accused of all sort of bullshit and had to fight it in a court of law for 2 years before he was exonerated.

And technology evolves and our devices are gradually becoming our stored memory. What do you think these corrupt officials or organized crime syndicates could do with your own mind, 10 years from now? A lot dude ;-)

Re: Fingerprints are Usernames, not Passwords

#216
The author is a maintainer of eCryptFS. For those not familiar with it, eCryptFS is an encrypted filesystem used by several Linux distributions (including Ubuntu) to protect your home directory and/or the entire disk. It serves a similar purpose to TrueCrypt, BitLocker, FileVault, etc.

For the purpose of a full-disk encryption software, fingerprints are many times weaker than a good password. The purpose of such software is to prevent a thief, the cops, the NSA, or anyone else who takes possession of your computer, from viewing the contents of your hard drive. A fingerprint won't protect you from the cops, since your prints are already all over the place and they can probably force you to provide a fresh copy anyway. In that case, fingerprint logins would only give the user an illusion of security. So it's understandable that the author doesn't want to enable fingerprint logins to his software.

For the purpose unlocking a phone, on the other hand, a fingerprint is probably good enough. The contents of the phone usually aren't encrypted, so a determined attacker will just turn the phone off, pull out the SD card and/or the internal Flash memory, and read everything off of it. Or if you're NSA, forget the phone and get the data straight from Apple. TouchID is not for NSA-proofing your phone, it's for deterring common thieves and pranksters.

tl;dr: I agree with the author that fingerprints are not a good fit for full-disk encryption software. But I don't agree that fingerprints are completely useless. It all depends on the type of attack you're trying to defend against.

Re: Fingerprints are Usernames, not Passwords

#217

Earlier quoted context omitted.

Animated gifs would today work. What if the camera focused on something behind you first and then the face? Would that bypass a 2D method?

On a camera with effectively infinite depth of field? Probably not.

Couldn't the camera even just focus on a face and then the neck as a point of depth? Honestly, all of these quick-check systems have countless flaws.

I'm ready to have a chip in my arm now.

Re: Fingerprints are Usernames, not Passwords

#218

Earlier quoted context omitted.

Consider the thorny issues of courts forcing people to turn over passwords to decrypt phones to implicate themselves. Typically, it's a constitution tarpit as you should not be forced to implicate yourself. However, your fingerprint is a username in that case because it is all over the place. The police already have it. Don't be fooled, there are certainly kits being sold to law enforcement to dupe TouchID. You're da…

This is a disadvantage only when you are on trial. That's a pretty extreme contingency, and I think most people who aren't internet privacy advocates wouldn't be particularly worried about their phones , of all things, after they've been arrested and indicted. Outside the HN bubble, this is an acceptable tradeoff. People who are concerned can continue to use passwords.

Also, configurable after a few hours it can ask the password anyway. A trial and being compelled to place your finger on the phone goes way beyond that. Or if they're going to beat you over the head with a metal pile regardless to unlock then the difference between a passcode or your fingerprint becomes meaningless.

Re: Fingerprints are Usernames, not Passwords

#219

Earlier quoted context omitted.

It starts throttling attempts before going full lockdown. But, yeah, don't leave assholes alone with your phone.

There's some aphorism about "assholes" and children which my brain thinks fits here but that same brain won't recall what it is. Anyhow, my initial thought was, perhaps not an asshole but a child? I could see a child playing with the phone and wiping it in quite short time. But other commenters pointed out it's not the default and there's cloud back-up it doesn't seem a major problem.

The attempts go up quickly. First try, wait a minute. Then 5, then 10, then 30 mins, then an hour, 3 hours, a day, a week etc.

Re: Fingerprints are Usernames, not Passwords

#220
post #110

Earlier quoted context omitted.

It's new in iOS 7. You'll have to explicitly wipe & reset your iPhone before selling it from now on. So if it works as advertised, stolen iPhones and iPads will only be worth the sum of their parts.

Hmm. After upgrading my ipad to iOS 7, I changed my pass code. Which I promptly forgot. I had to reset it from iTunes, on a computer which had never paired with the ipad (in fact I had to download iTunes to do this). When the ipad restarted it asked me for my Apple ID but that seemed to be for the iCloud restore. I think I could have skipped it and had a functioning ipad. But apparently not?

Nope. The Apple ID is necessary to restore in iOS 7.
Post reply on HN