Live data from Hacker News

I recommend against using biometric identification

medium.freecodecamp.org

221–230 of 239 posts

Re: I recommend against using biometric identification

#221
post #213

Earlier quoted context omitted.

Perhaps there could be a way to instantly delete all iphone data with a voice command. Something like "siri delete my iphone code alpha nine x." Or even an undetectable command like "silly sausages" for example. Might that stop a judge from being able to send you to prison indefinitely?

I would bet the judge would consider that destruction of evidence. Disclaimer: I never studied law

What if the authorities do not know what the self-erase command is? Like, inputting your password backwards, or adding 1 to every number.

What if it only erases a certain file or partition, so the phone still contains some personal data, but it's like TrueCrypts's plausible deniability?

Re: I recommend against using biometric identification

#222

Earlier quoted context omitted.

And many of those hackers (or even one of them) care enough to (a) steal your phone, (b) fake your fingerprints with a cast or whatever? Yeah, I'll risk it...

Ok, how about this. Imagine if MILLIONS of fingerprints are leaked, in some sort of wide net security break, and now any script kiddie can hack ~50% of phones?

I imagine it. So? How exactly is this kiddie (or any kiddie) gonna also GET my phone?

(That said I never had a phone lost or stolen. People who tend to have them so might feel differently).

Re: I recommend against using biometric identification

#223
post #189

Earlier quoted context omitted.

Biometrics can't be rotated. But they also can't be phished. People have been using "biometrics" to recognize people they trust since the beginning of time, and are pretty rarely fooled. They have also been using passwords since the beginning of time, and have been being compromised since the next day, when someone walked into the enemy camp by accosting a patrolling guard and demanding the password. The most importa…

> Biometrics can't be rotated. But they also can't be phished. Sure they can. Haven't you ever seen a cop show where the detective tricks the suspect into drinking from a cup of coffee so they can lift the suspect's fingerprint from the cup? "Hi John, nice to meet you! * shakes hand *" I now have John's fingerprints from where he touched me when he shook my hand. "Hey John, can you send me a selfie?" I now have a pic…

They can't be phished because they aren't secrets. Yes, if you think of a biometric as a password it is an awful password. But it isn't; its primary source of security is the difficulty of presentation. You should not rely on the secrecy of your biometrics.

You probably don't worry very much that your loved ones have been replaced by impostors, and the reason is not that their appearance is secret! It's just that fooling your face, voice and other "biometrics" without making you suspicious would be, depending on the situation, somewhere between technologically impossible and way more expensive than it would be worth.

A secure biometric is one for which spoofing the sensor is as difficult or expensive as compromising the device hardware some other way. I agree with you that touch ID doesn't quite meet this standard, largely because device hardware has gotten much more tamper resistant in recent years! Hopefully face ID will be better. I can easily remember when it seemed absurd that normal consumer devices would ever have a chance of resisting compromise by a sophisticated adversary that had the device in their possession!

Re: I recommend against using biometric identification

#226
post #67

Earlier quoted context omitted.

Nice! That must be a new feature? It had no such thing, the last time I used Android. Err... I use a Windows phone, even though I'm normally a Linux user. I kinda like it.

I’ve seen it on Lineage OS, but it might be tablet-only.

Its available in Lineage OS for mobile as well.

Re: I recommend against using biometric identification

#227

Earlier quoted context omitted.

I think the safe analogy is an excellent way to illustrate the issue. Encrypting a file is essentially the same thing as locking it in a safe in what I believe is the ultimate "eyes of the law" once this gets fully tried.

Encryption is nothing like locking in a safe further in a similar situation I'm pretty sure rather than going to court they just open the safe making the example even more useless.

> Encryption is nothing like locking in a safe

Sure, to technical folks like us, but notice I said "in the eyes of the law". Furthermore, police can not open a safe without a court order, so guess your reply was a bust all around?

Re: I recommend against using biometric identification

#228
post #144

Earlier quoted context omitted.

>If someone steals your fingerprint, you can never change your fingerprint (same with your face). At what point is stealing a fingerprint, retina print, or face going to be economical enough for the thief that this would be an actual valid concern in 99% of use cases? Both FaceID and TouchID need to read a living person with a pulse in order to authenticate. You can't just take a printout of a fingerprint and drop it…

> At what point is stealing a fingerprint, retina print, or face going to be economical enough for the thief that this would be an actual valid concern in 99% of use cases? For the average person who is just securing their phone that only stores pictures of their cat, this isn't a concern, but that's far less than 99%. For pretty much anyone who is logged into their work email/VPN via their phone, or is using fingerp…

>For pretty much anyone who is logged into their work email/VPN via their phone, or is using fingerprint scanners to secure their work laptop, this is a very real concern that I have seen exploited a few times in the real world.

You're conflating every fingerprint scanner with the Apple's implementation of TouchID, which is far more secure than the check-the-box-to-win-a-government-contract stuff that's been built into most laptops. If it's that important, use a biometric print AND a PIN. Easy enough no? At least way easier than requiring an absurd password requirement that people wind up writing into a post-it-note anyway.

>You can defeat TouchID with $10 worth of office supplies and some play-dough.

And by having a person physically press the correct finger onto your obvious fingerprint-stealing device. . .k But if someone has the power to compel you to do that, they have the power to compel you to just put your finger on your phone for them.

>Since your phone literally has your fingerprint left on it from when you touched it, this isn't really a difficult task.

This is even more involved. This involves having to lift the print with a high fidelity scanner and create a latex mold of it. What are you securing on your phone where this is a concern? And what do you think they're going to do when there is a face-scanner or retina scanner? I suppose they could just clone you, wait however many years for the clone to mature, and then use it.

> it's even worse if you're one of the people who uses a password manager on your phone that is also locked with fingerprint.

Maybe if fewer services forced people into using inane and impossible-to-remember passwords and just relied on biometric authentication instead folks wouldn’t need password managers that are so easy to unlock. Not everything needs the level of security of my bank-account, and when ever service a person interacts with wants to pretend they're a bank or credit card then it makes people take their bank or credit card's information less seriously than they need to out of sheer fatigue.

Security should be about fostering secure behaviors and culture in your users, not just ramming the most technically secure set of rules at people regardless of the context. That just makes people behave in insecure ways, like what you're talking about, because you haven't bought them into the importance of the big picture.

>it's just made more difficult to do that when Apple is pushing falsehoods like "TouchID is the most secure thing ever!" in all of their marketing materials.

I don't understand how you derived THAT from this: >Much of our digital lives is stored on our Apple devices, and we recommend that you always use a passcode or password to help protect this important information and your privacy. Using Touch ID on your iPhone, iPad, and MacBook Pro is an easy way to use your fingerprint instead of a password for many common operations.

Re: I recommend against using biometric identification

#229
post #144

Earlier quoted context omitted.

> At what point is stealing a fingerprint, retina print, or face going to be economical enough for the thief that this would be an actual valid concern in 99% of use cases? For the average person who is just securing their phone that only stores pictures of their cat, this isn't a concern, but that's far less than 99%. For pretty much anyone who is logged into their work email/VPN via their phone, or is using fingerp…

>For pretty much anyone who is logged into their work email/VPN via their phone, or is using fingerprint scanners to secure their work laptop, this is a very real concern that I have seen exploited a few times in the real world. You're conflating every fingerprint scanner with the Apple's implementation of TouchID, which is far more secure than the check-the-box-to-win-a-government-contract stuff that's been built in…

> You're conflating every fingerprint scanner with the Apple's implementation of TouchID, which is far more secure than the check-the-box-to-win-a-government-contract stuff that's been built into most laptops.

No, I'm not. TouchID is the most popular implementation, and because it's present on every iPhone (which is the most common device to be a work phone, and thus also connected to work email and work networks), and because TouchID is also insecure, thus arises the problem.

> If it's that important, use a biometric print AND a PIN.

This is not possible on the iPhone, and wouldn't solve the problem anyway: consumers are under the false impression that fingerprints are the best security available, and they become frustrated to learn that Apple has been lying to them when corporate IT tells them fingerprints actually suck and they can't use fingerprint locks (or have to use fingerprint + something else) if they also use their phone for work stuff.

> And by having a person physically press the correct finger onto your obvious fingerprint-stealing device. . .k But if someone has the power to compel you to do that, they have the power to compel you to just put your finger on your phone for them.

What? No, you don't. You're just making stuff up now. You can steal someone's fingerprint by simply having access to something they touched, and then you can duplicate it with $10 worth of office supplies.

> This is even more involved. This involves having to lift the print with a high fidelity scanner and create a latex mold of it. What are you securing on your phone where this is a concern?

Network access to a corporate environment that has millions of SSNs, credit card numbers, etc. You think that a few hours of fiddling around with a latex mold is "too much work" for this? Think again.

> Maybe if fewer services forced people into using inane and impossible-to-remember passwords and just relied on biometric authentication instead folks wouldn’t need password managers that are so easy to unlock.

You miss the point. This wouldn't solve the issue at all, and would actually worsen it. Fingerprints are inherently insecure. Using fingerprints for more accounts is, thus, more insecure.

> I don't understand how you derived THAT from this:

I "derived" it from years of experience working as a cybersecurity consultant where at every company someone complains that "Apple says it's secure, so you must be wrong". Watch the keynote. Apple refers to TouchID as "the gold standard", "one of the most powerful passwords in the world", says "it is the most advanced technology", calls it "very high security".

Re: I recommend against using biometric identification

#230

Earlier quoted context omitted.

>If someone steals your fingerprint, you can never change your fingerprint (same with your face). At what point is stealing a fingerprint, retina print, or face going to be economical enough for the thief that this would be an actual valid concern in 99% of use cases? Both FaceID and TouchID need to read a living person with a pulse in order to authenticate. You can't just take a printout of a fingerprint and drop it…

> Unless you're securing State Secrets or occupy rarefied enough heights that you have a Swiss bank account I don't really see anyone bothering. You're vastly underestimating how valuable access to a person's phone can be. It's not just about quickly wiring money or stealing state secrets but also about building blocks for social engineering campaigns, ad/app fraud, extorsion and all sorts of different things. And th…

>And the petty thief who steals your phone doesn't need to have the tools to spoof the biometrics. There just needs to be some criminal organization that does and that's willing to pay petty thieves for stolen phones.

And have a pipeline that can buy and move stolen phones fast enough to crack them before the owners can remotely wipe them.

Amazon would kill for that kind of logistical capacity.

Post reply on HN