Live data from Hacker News

Face ID, Touch ID, No ID, PINs and Pragmatic Security

troyhunt.com

281–290 of 314 posts

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#281
post #177

> ...when you do use the biometric options we're about to get into, you're still going to need [a pin] on your phone anyway. For example, every time you hard-reboot an iPhone with Touch ID you need to enter the PIN This is what has been missing from every discussion of this issue that I've seen so far. The face scan isn't "insecure" even if you're worried about border searches. Just turn off your phone when you get i…

[deleted]

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#282
post #101

Stolen iPhones should be worthless. Apple need to create a system where stolen phones can be reported to them, Apple can then contact the owner/verify they are stolen. And then add them to a stolen list and disable calling/apps on those phones. And display an overlay on the screen THIS PHONE IS STOLEN. Every iphone would come with an validate phone feature that is accessible even when locked that can authenticate the…

Find My iPhone + iCloud is what you're describing. Even a DFU restore of the device won't help a thief, as the activation process will simply ask for your iCloud login and will display a "Message From Owner" that you can set at icloud.com indicating the device was stolen, making it much harder for someone to purchase and claim ignorance about the origins.

y, that's true but I feel like Apple could do more so criminals don't even want to take iPhones, Apple could put things in place where they aren't worth anything on the secondary market. Basically unusable and could lead the cops to your house.

This way if you're on the subway you can have your phone out without worrying about getting robbed.

It your house gets robbed they would leave your phones because they can't be sold or reused.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#283
post #265
post #260

Earlier quoted context omitted.

Local encrypted backups via itunes are an option too, if you are traveling with a laptop.

Is that still going to work? I have the impression that Apple is simplifying iTunes and removing everything but audio and video.

I haven't tried since installing itunes 12.7 (the version that removes the App Store etc), but reports I've read suggest it still backs up everything with the notable exception of apps. These have to re-download from the appstore on the phone iteself presumably now. I'm assuming though that all app data is preserved (one would hope so!). Happy to be corrected if this proves not the case.

From macdailynews:

"iTunes backups are still there for iOS devices, but performing a restore won’t transfer your apps from your Mac, but will instead download them over the Internet from Apple, which is, of course, likely to be slower."

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#284

Near-field worn devices. http://nfcring.com is an example of what I have in mind. What I'd like to see is this tied into an identity system, such that the ring (or other very-hard-to-misplace, but replaceable and discardable) token is not itself an identity, but rather an access token to an identity store which can present any given identity to any given system. That might be a consistent identity across multiple ses…

Personally, I'd like to see identity tied to my smartwatch, with authentication happening via capacitive coupling + Bluetooth. The way I'm envisioning it: 1. Physically touch the object you want to authenticate to. (E.g. Computer, payment terminal, smart lock, etc.) Watch uses capacitive coupling to bootstrap a Bluetooth connection to that device. 2. Device requests authentication & authorization from Watch. 3. Watch…

A watch or bracelet could also work, of course. Even a neck pendant if that's your thing. The point is physical, on your person, and crypto based on near field.

The problem with longer ranges, even just a few cm, is the prospect for snooping or triggerring unintended authentications. My preference would be mm range.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#285

Earlier quoted context omitted.

So, someone steals the NFC ring and then own the phone? Ring + heat detection of PIN tap pattern will end up giving a false sense of 2FA. (not sure how the ring auths on being worn, didnt see it on the website).

Or cutting off a finger or hand?

Difficult to arrange by a phishing email, website, or trojan.

Possible to countermeasure as well.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#286
post #222

Earlier quoted context omitted.

Also, the border is 100 miles from the Mexico/Canada borders and 100 miles from the shore. So, if you're concerned it's not when you're entering or leaving the country. It's any time you're in LA, NY, DC, SF, Huston or Detroit. Or any of the other thousands of miles of border.

Common misconception: If you have crossed the boarder, then within 100 miles of it they can search you. Of course, how you prove you didn't cross the boarder is an open question. But you can in fact refuse the search on that claim. I suppose they may detain you then.

There are inland checkpoints, even on the Canadian border that search people who've been in the country for a while: http://www.washingtonexaminer.com/border-patrol-checkpoint-i....

They can even nab American citizens for drug possession:

"One of the people arrested was a U.S. citizen who fled the checkpoint and led the police on a five-mile chase. The unnamed man was arrested and charged with three felonies, including reckless driving, possessing a controlled substance, and endangering the welfare of a minor."

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#287

Repeat after me. iPhone X is less secure than the iPhone 8. Why? iPhone X: Chances of someone unlocking while you are asleep is 1 in 1 iPhone 8: Chances of someone unlocking while you are asleep is 1 in 200,000 I certainly prefer the latter odds.

Your eyes need to be open for it to unlock. Also someone can't touch your fingertips when you are asleep?

Some people sleep with their eyes open.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#288
post #180

Earlier quoted context omitted.

On top of this, iOS 11 introduced an emergency mode that is enabled by tapping the standby button five times rapidly. It is easy to do discretely in your pocket, and it locks your phone by requiring your passcode to be entered again.

You can achieve the same effect on some Android devices by exploiting the password lock from scanning the wrong finger repeatedly.

You've always been able to do this on iOS as well, but it risks an obstruction of justice charge.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#289
post #183
post #147

I really liked this write-up because it focused on the practicality of the various security mechanisms. Most articles I see usually have a blanket statement like "All biometric security mechanisms are bad!". I think this article does a good job comparing the various logins and describing the pros and cons for different people. Specifically, I appreciate the author calling out when people bring up the "What if" edge-c…

>All biometric security mechanisms are bad They are though, if bad == insecure. Customs can make you unlock with fingerprint or face. If you can't lock yourself out, it's not secure.

Biometric security mechanisms are the best security mechanisms.

Because they fall in the category of "will be used" as opposed to perfect security, which almost always falls in the category "won't be used"

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#290
post #217
post #177

> ...when you do use the biometric options we're about to get into, you're still going to need [a pin] on your phone anyway. For example, every time you hard-reboot an iPhone with Touch ID you need to enter the PIN This is what has been missing from every discussion of this issue that I've seen so far. The face scan isn't "insecure" even if you're worried about border searches. Just turn off your phone when you get i…

I don't want to be that 'if you've got nothing to hide then' guy but why are people so worried about what border agents in particular will see on their cell phone? I am not saying that I wouldn't mind at all if my phone was searched. But I can't think of anything in particular that I would be concerned about if it was. Sure in theory the agent could remember some personal information and come back later and use that…

My Canadian friend (woman) made the mistake of making a connecting flight in the States on her way to visit me in Mexico.

The border agent accused her of prostitution. He wanted to get into her phone to see her latest Facebook Messenger and Tinder correspondence. She let him because, of course, it's easier than canceling her entire vacation plans.

Now, the tips in this thread wouldn't have helped her. But do you see how it's not just "I don't have anything to hide?" What about not letting some border agent power trip all over you? Reading your Tinder messages for fucks sake?

Post reply on HN