> ...when you do use the biometric options we're about to get into, you're still going to need [a pin] on your phone anyway. For example, every time you hard-reboot an iPhone with Touch ID you need to enter the PIN This is what has been missing from every discussion of this issue that I've seen so far. The face scan isn't "insecure" even if you're worried about border searches. Just turn off your phone when you get i…
Face ID, Touch ID, No ID, PINs and Pragmatic Security
281–290 of 314 posts
Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security
#282Stolen iPhones should be worthless. Apple need to create a system where stolen phones can be reported to them, Apple can then contact the owner/verify they are stolen. And then add them to a stolen list and disable calling/apps on those phones. And display an overlay on the screen THIS PHONE IS STOLEN. Every iphone would come with an validate phone feature that is accessible even when locked that can authenticate the…
Find My iPhone + iCloud is what you're describing. Even a DFU restore of the device won't help a thief, as the activation process will simply ask for your iCloud login and will display a "Message From Owner" that you can set at icloud.com indicating the device was stolen, making it much harder for someone to purchase and claim ignorance about the origins.
This way if you're on the subway you can have your phone out without worrying about getting robbed.
It your house gets robbed they would leave your phones because they can't be sold or reused.
Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security
#283Earlier quoted context omitted.
Local encrypted backups via itunes are an option too, if you are traveling with a laptop.
Is that still going to work? I have the impression that Apple is simplifying iTunes and removing everything but audio and video.
From macdailynews:
"iTunes backups are still there for iOS devices, but performing a restore won’t transfer your apps from your Mac, but will instead download them over the Internet from Apple, which is, of course, likely to be slower."
Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security
#284Near-field worn devices. http://nfcring.com is an example of what I have in mind. What I'd like to see is this tied into an identity system, such that the ring (or other very-hard-to-misplace, but replaceable and discardable) token is not itself an identity, but rather an access token to an identity store which can present any given identity to any given system. That might be a consistent identity across multiple ses…
Personally, I'd like to see identity tied to my smartwatch, with authentication happening via capacitive coupling + Bluetooth. The way I'm envisioning it: 1. Physically touch the object you want to authenticate to. (E.g. Computer, payment terminal, smart lock, etc.) Watch uses capacitive coupling to bootstrap a Bluetooth connection to that device. 2. Device requests authentication & authorization from Watch. 3. Watch…
The problem with longer ranges, even just a few cm, is the prospect for snooping or triggerring unintended authentications. My preference would be mm range.
Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security
#285Earlier quoted context omitted.
So, someone steals the NFC ring and then own the phone? Ring + heat detection of PIN tap pattern will end up giving a false sense of 2FA. (not sure how the ring auths on being worn, didnt see it on the website).
Or cutting off a finger or hand?
Possible to countermeasure as well.
Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security
#286Earlier quoted context omitted.
Also, the border is 100 miles from the Mexico/Canada borders and 100 miles from the shore. So, if you're concerned it's not when you're entering or leaving the country. It's any time you're in LA, NY, DC, SF, Huston or Detroit. Or any of the other thousands of miles of border.
Common misconception: If you have crossed the boarder, then within 100 miles of it they can search you. Of course, how you prove you didn't cross the boarder is an open question. But you can in fact refuse the search on that claim. I suppose they may detain you then.
They can even nab American citizens for drug possession:
"One of the people arrested was a U.S. citizen who fled the checkpoint and led the police on a five-mile chase. The unnamed man was arrested and charged with three felonies, including reckless driving, possessing a controlled substance, and endangering the welfare of a minor."
Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security
#287Repeat after me. iPhone X is less secure than the iPhone 8. Why? iPhone X: Chances of someone unlocking while you are asleep is 1 in 1 iPhone 8: Chances of someone unlocking while you are asleep is 1 in 200,000 I certainly prefer the latter odds.
Your eyes need to be open for it to unlock. Also someone can't touch your fingertips when you are asleep?
Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security
#288Earlier quoted context omitted.
On top of this, iOS 11 introduced an emergency mode that is enabled by tapping the standby button five times rapidly. It is easy to do discretely in your pocket, and it locks your phone by requiring your passcode to be entered again.
You can achieve the same effect on some Android devices by exploiting the password lock from scanning the wrong finger repeatedly.
Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security
#289I really liked this write-up because it focused on the practicality of the various security mechanisms. Most articles I see usually have a blanket statement like "All biometric security mechanisms are bad!". I think this article does a good job comparing the various logins and describing the pros and cons for different people. Specifically, I appreciate the author calling out when people bring up the "What if" edge-c…
>All biometric security mechanisms are bad They are though, if bad == insecure. Customs can make you unlock with fingerprint or face. If you can't lock yourself out, it's not secure.
Because they fall in the category of "will be used" as opposed to perfect security, which almost always falls in the category "won't be used"
Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security
#290> ...when you do use the biometric options we're about to get into, you're still going to need [a pin] on your phone anyway. For example, every time you hard-reboot an iPhone with Touch ID you need to enter the PIN This is what has been missing from every discussion of this issue that I've seen so far. The face scan isn't "insecure" even if you're worried about border searches. Just turn off your phone when you get i…
I don't want to be that 'if you've got nothing to hide then' guy but why are people so worried about what border agents in particular will see on their cell phone? I am not saying that I wouldn't mind at all if my phone was searched. But I can't think of anything in particular that I would be concerned about if it was. Sure in theory the agent could remember some personal information and come back later and use that…
The border agent accused her of prostitution. He wanted to get into her phone to see her latest Facebook Messenger and Tinder correspondence. She let him because, of course, it's easier than canceling her entire vacation plans.
Now, the tips in this thread wouldn't have helped her. But do you see how it's not just "I don't have anything to hide?" What about not letting some border agent power trip all over you? Reading your Tinder messages for fucks sake?