Live data from Hacker News

Fingerprints are Usernames, not Passwords

blog.dustinkirkland.com

221–230 of 261 posts

Re: Fingerprints are Usernames, not Passwords

#221
post #218

Earlier quoted context omitted.

This is a disadvantage only when you are on trial. That's a pretty extreme contingency, and I think most people who aren't internet privacy advocates wouldn't be particularly worried about their phones , of all things, after they've been arrested and indicted. Outside the HN bubble, this is an acceptable tradeoff. People who are concerned can continue to use passwords.

Also, configurable after a few hours it can ask the password anyway. A trial and being compelled to place your finger on the phone goes way beyond that. Or if they're going to beat you over the head with a metal pile regardless to unlock then the difference between a passcode or your fingerprint becomes meaningless.

That's too black and white. Is there nothing that you would give your life for? There is nothing worth dying for? Maybe you should think less of convienience and more about living a life worth living.

Re: Fingerprints are Usernames, not Passwords

#222
post #111

Earlier quoted context omitted.

Except TouchID, from what I gather, actually works. Not "works" in the sense of keeping bad people out, but "works" in the sense that when I use it my phone unlocks. I tried face unlock briefly on the Google Nexus I've got and disabled it shortly after when I found that it was unreliable. Poor lighting, too much lighting, a bad hair day, it wasn't even at 80% for successful unlocks.

Not to mention, by the time I am looking at the phone, I want it already unlocked. Sometimes I want it unlocked in my pocket (Siri?). TouchID allows me to do that. Face unlock does not.

When it works fast, face unlock can be rather stunning. Occasionally it would catch a glimpse of my face obliquely and unlock before I even got to position it correctly.

However like others, I turned it off because the performance was highly variable, and the failure mode consists of a many-seconds wait which can be extremely infuriating (even embarrassing, as as you stare blankly at your phone for 5 seconds at a party, trying to quickly get someone's number or something).

Re: Fingerprints are Usernames, not Passwords

#226

Earlier quoted context omitted.

It starts throttling attempts before going full lockdown. But, yeah, don't leave assholes alone with your phone.

There's some aphorism about "assholes" and children which my brain thinks fits here but that same brain won't recall what it is. Anyhow, my initial thought was, perhaps not an asshole but a child? I could see a child playing with the phone and wiping it in quite short time. But other commenters pointed out it's not the default and there's cloud back-up it doesn't seem a major problem.

My friend's 12-month old baby reset the unlock code on her mother's phone and they ended up having to wipe it completely in order to recover.

Re: Fingerprints are Usernames, not Passwords

#227
post #216

The author is a maintainer of eCryptFS. For those not familiar with it, eCryptFS is an encrypted filesystem used by several Linux distributions (including Ubuntu) to protect your home directory and/or the entire disk. It serves a similar purpose to TrueCrypt, BitLocker, FileVault, etc. For the purpose of a full-disk encryption software, fingerprints are many times weaker than a good password. The purpose of such soft…

I'm pretty sure that iPhones have encrypted their data since the 3GS. That's how they "remote wipe" it. They send a message to the phone to delete the encryption key.

Re: Fingerprints are Usernames, not Passwords

#229

Earlier quoted context omitted.

There's some aphorism about "assholes" and children which my brain thinks fits here but that same brain won't recall what it is. Anyhow, my initial thought was, perhaps not an asshole but a child? I could see a child playing with the phone and wiping it in quite short time. But other commenters pointed out it's not the default and there's cloud back-up it doesn't seem a major problem.

My friend's 12-month old baby reset the unlock code on her mother's phone and they ended up having to wipe it completely in order to recover.

This is completely unrelated, but why do people say "12 months", "18 months", and "24 months" rather than 1 year, 1.5 years, and 2 years? I don't get it. I'd understand if they're younger than a year old (eg "My son is seven months old!"), but not once the age can be expressed in years.

Re: Fingerprints are Usernames, not Passwords

#230
post #227
post #216

The author is a maintainer of eCryptFS. For those not familiar with it, eCryptFS is an encrypted filesystem used by several Linux distributions (including Ubuntu) to protect your home directory and/or the entire disk. It serves a similar purpose to TrueCrypt, BitLocker, FileVault, etc. For the purpose of a full-disk encryption software, fingerprints are many times weaker than a good password. The purpose of such soft…

I'm pretty sure that iPhones have encrypted their data since the 3GS. That's how they "remote wipe" it. They send a message to the phone to delete the encryption key.

AFAIK the encryption key is stored in plaintext unless you also set a passcode (many people don't), and even if you set a passcode, most of the time it's just a short number that would be trivial to brute-force in an offline attack.

Of course it's also possible to use eCryptFS with a four-digit passcode, but it's strongly recommended against. The main difference between FBI-proof encryption and pickpocket-proof encryption is not in the algorithms used, but in the typical use case of each.

Post reply on HN