Live data from Hacker News

Face ID, Touch ID, No ID, PINs and Pragmatic Security

troyhunt.com

221–230 of 314 posts

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#221

Earlier quoted context omitted.

Not trying to tell you how to live your life, but being an open book to the other isn‘t very trusting. If your trust is build around being able to spy on the other, maybe you aren‘t trusting each other that much. My wife and I both have our own separate phones and computers without each other being able to access it and I trust her not to do anything that goes against our interests and vice versa. That‘s what trust i…

I also let my spouse unlock my phone. It's not so much "being an open book" as it is "I trust her not to snoop, and sometimes it's convenient that she can open a map on my phone." That meets your definition of trust: not having to know what she does because I know she'll do the right thing.

Very fair point. In fact, my wife actually knows my phones passcode for the exact same reason. „Open book“ was definitely the wrong phrasing here, I wasn‘t trying to say that you have to keep everything secret from your spouse. Just that the exact opposite of that also strikes me as very distrusting.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#222
post #205
post #177

> ...when you do use the biometric options we're about to get into, you're still going to need [a pin] on your phone anyway. For example, every time you hard-reboot an iPhone with Touch ID you need to enter the PIN This is what has been missing from every discussion of this issue that I've seen so far. The face scan isn't "insecure" even if you're worried about border searches. Just turn off your phone when you get i…

> The face scan isn't "insecure" even if you're worried about border searches. Just turn off your phone when you get in the security line! Pin will be required on start. As far as border searches go, border officers have the authority to request your PIN just as they have the authority to request your thumbprint/faceprint/etc. If you don't give it to them, you can be detained and/or your phone confiscated [1]. Reboot…

Also, the border is 100 miles from the Mexico/Canada borders and 100 miles from the shore. So, if you're concerned it's not when you're entering or leaving the country. It's any time you're in LA, NY, DC, SF, Huston or Detroit. Or any of the other thousands of miles of border.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#223
post #217
post #177

> ...when you do use the biometric options we're about to get into, you're still going to need [a pin] on your phone anyway. For example, every time you hard-reboot an iPhone with Touch ID you need to enter the PIN This is what has been missing from every discussion of this issue that I've seen so far. The face scan isn't "insecure" even if you're worried about border searches. Just turn off your phone when you get i…

I don't want to be that 'if you've got nothing to hide then' guy but why are people so worried about what border agents in particular will see on their cell phone? I am not saying that I wouldn't mind at all if my phone was searched. But I can't think of anything in particular that I would be concerned about if it was. Sure in theory the agent could remember some personal information and come back later and use that…

Depends on how difficult it is to produce an automated system whereby one needs only plug an unlocked phone into a computer in order to hoover up all locally-stored messages, contacts, saved passwords, synced browser histories, etc. The agent themselves doesn't need to care, they can just be instructed to "unlock the phone, plug it in to this computer, wait until the progress bar finishes, hand phone back". Are you on Github? Is your Github password saved in your browser? Do you have commit access to any marginally important projects? God only knows who has commit access to those projects now. Considering this is HN, I imagine this is an attack vector that a lot of people here are particularly concerned about. Given how much code we use that's written by others, it ought to concern the rest of us as well. :)

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#224
post #217
post #177

> ...when you do use the biometric options we're about to get into, you're still going to need [a pin] on your phone anyway. For example, every time you hard-reboot an iPhone with Touch ID you need to enter the PIN This is what has been missing from every discussion of this issue that I've seen so far. The face scan isn't "insecure" even if you're worried about border searches. Just turn off your phone when you get i…

I don't want to be that 'if you've got nothing to hide then' guy but why are people so worried about what border agents in particular will see on their cell phone? I am not saying that I wouldn't mind at all if my phone was searched. But I can't think of anything in particular that I would be concerned about if it was. Sure in theory the agent could remember some personal information and come back later and use that…

What if they automate the search and copy all your data for further mining and save all that info to see if you're not "desirable" for the "people in power"?

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#225
post #180
post #177

> ...when you do use the biometric options we're about to get into, you're still going to need [a pin] on your phone anyway. For example, every time you hard-reboot an iPhone with Touch ID you need to enter the PIN This is what has been missing from every discussion of this issue that I've seen so far. The face scan isn't "insecure" even if you're worried about border searches. Just turn off your phone when you get i…

On top of this, iOS 11 introduced an emergency mode that is enabled by tapping the standby button five times rapidly. It is easy to do discretely in your pocket, and it locks your phone by requiring your passcode to be entered again.

It's also worth pointing out that iOS already has an option to erase your phone when the PIN is entered incorrectly a certain number of times. A lot of companies enforce this if you receive your work email on your device (eight times in my case). So if you are in a situation where a PIN is being demanded there's still a way to keep secure.

Your phone can be easily restored from an iCloud backup once you've got access to wifi. You can always restore from another device or backup if there's data you don't want seen if somehow you can be compelled to do a restore.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#226
post #185

Re: the pushback the author got on Twitter; I believe in skepticism towards corporations and marketing claims, but the level of cynicism online towards any new tech idea or product seems a bit out of hand. There's a certain trend, on Twitter especially, of people racing to prove they're either more woke or smarter than the teams of people behind things that are yet to even be released. I mean a "wait and see" attitud…

> There's a certain trend, on Twitter especially, of people racing to prove they're either more woke or smarter than the teams of people behind things that are yet to even be released. This has been a trend of a vocal minority on the internet for as long as I've been connected to it. Remember "No wireless. Less space than a nomad. Lame"?

> Remember "No wireless. Less space than a nomad. Lame"?

I hate linking to that site but this will always be golden: Apple's New Thing (a post from 2001) [1]

[1] https://forums.macrumors.com/threads/apples-new-thing-ipod.5...

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#227
post #217
post #177

> ...when you do use the biometric options we're about to get into, you're still going to need [a pin] on your phone anyway. For example, every time you hard-reboot an iPhone with Touch ID you need to enter the PIN This is what has been missing from every discussion of this issue that I've seen so far. The face scan isn't "insecure" even if you're worried about border searches. Just turn off your phone when you get i…

I don't want to be that 'if you've got nothing to hide then' guy but why are people so worried about what border agents in particular will see on their cell phone? I am not saying that I wouldn't mind at all if my phone was searched. But I can't think of anything in particular that I would be concerned about if it was. Sure in theory the agent could remember some personal information and come back later and use that…

It’s not about agents looking at your phone; it’s about the slow erosion of our rights among other things

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#228

Earlier quoted context omitted.

Constitutionally, an individual can not be forced to enter a password for law enforcement (including customs agents).

That's the point, "constitutionally" while they lock you up for hours/days on end to obtain the warrant needed to give up your password unless you are willing to stay locked up.

Many border agents, it seems, have the “if you have nothing to hide” mentality. So if you’re refusing to unlock your phone, clearly you’re hiding something.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#229
post #201
post #194

Earlier quoted context omitted.

I'm not sure that Touch ID can come back in its current form. Phil stood on stage and told us Touch ID is 50,000 secure and Face ID is 1,000,000 secure. I think the only way for Touch ID to come back is for it to cover the whole display, so it can authenticate every touch.

Agreed. If you could make it so every single tap was scanned, you could make the phone so secure, yet so simple to use. The phone could constantly monitor both Face ID and full-screen Touch ID at the same time, and if it detects anything funky going down it can panic and lock. Would close down attacks where someone grabs your phone off you while it's unlocked and quickly disables security.

But then people you hand your phone to wouldn’t be able to use it

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#230
post #205
post #177

> ...when you do use the biometric options we're about to get into, you're still going to need [a pin] on your phone anyway. For example, every time you hard-reboot an iPhone with Touch ID you need to enter the PIN This is what has been missing from every discussion of this issue that I've seen so far. The face scan isn't "insecure" even if you're worried about border searches. Just turn off your phone when you get i…

> The face scan isn't "insecure" even if you're worried about border searches. Just turn off your phone when you get in the security line! Pin will be required on start. As far as border searches go, border officers have the authority to request your PIN just as they have the authority to request your thumbprint/faceprint/etc. If you don't give it to them, you can be detained and/or your phone confiscated [1]. Reboot…

They can request your PIN all they want, but you are not obligated to provide it. They can temporarily detain you but not indefinitely, and the EFF is challenging their authority to even do that. [0]

Personally, I would refuse to unlock my phone. My privacy and upholding civil liberties is worth being detained for a few hours (or even days).

[0] https://www.eff.org/press/releases/eff-aclu-media-conference...

Post reply on HN