Live data from Hacker News

Face ID, Touch ID, No ID, PINs and Pragmatic Security

troyhunt.com

291–300 of 314 posts

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#291
post #217
post #177

> ...when you do use the biometric options we're about to get into, you're still going to need [a pin] on your phone anyway. For example, every time you hard-reboot an iPhone with Touch ID you need to enter the PIN This is what has been missing from every discussion of this issue that I've seen so far. The face scan isn't "insecure" even if you're worried about border searches. Just turn off your phone when you get i…

I don't want to be that 'if you've got nothing to hide then' guy but why are people so worried about what border agents in particular will see on their cell phone? I am not saying that I wouldn't mind at all if my phone was searched. But I can't think of anything in particular that I would be concerned about if it was. Sure in theory the agent could remember some personal information and come back later and use that…

Just because you are innocent and have nothing to hide, it does not mean they cannot still use the evidence you provide to convict you. Basically, it comes back to the same reason that many lawyers generally advise you to never talk to the police (1). IANAL.

(1) https://www.vice.com/en_us/article/mvkgnp/law-professor-poli...

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#292
post #278
post #205

Earlier quoted context omitted.

> The face scan isn't "insecure" even if you're worried about border searches. Just turn off your phone when you get in the security line! Pin will be required on start. As far as border searches go, border officers have the authority to request your PIN just as they have the authority to request your thumbprint/faceprint/etc. If you don't give it to them, you can be detained and/or your phone confiscated [1]. Reboot…

You know what would be really neat? A different, restricted/camouflaged unlock when you make a slight facial expression that would probably go unnoticed. regular face: regular unlock right eyebrow raised a tiny bit: hide my sensitive stuff from a casual search* *and after a few minutes, if I don't deactivate it, start deleting.

Unfortunately, lying (including fraudulent representation) to a federal agent is a crime (https://en.wikipedia.org/wiki/Making_false_statements).

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#293

Earlier quoted context omitted.

They can request your PIN all they want, but you are not obligated to provide it. They can temporarily detain you but not indefinitely, and the EFF is challenging their authority to even do that. [0] Personally, I would refuse to unlock my phone. My privacy and upholding civil liberties is worth being detained for a few hours (or even days). [0] https://www.eff.org/press/releases/eff-aclu-media-conference...

This only works if your lawyer is with you or you're white.

Why would you have your lawyer with you? Better to have them outside of the range of border control agents (remote) so they don't get arrested too.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#294

Earlier quoted context omitted.

Personally, I'd like to see identity tied to my smartwatch, with authentication happening via capacitive coupling + Bluetooth. The way I'm envisioning it: 1. Physically touch the object you want to authenticate to. (E.g. Computer, payment terminal, smart lock, etc.) Watch uses capacitive coupling to bootstrap a Bluetooth connection to that device. 2. Device requests authentication & authorization from Watch. 3. Watch…

A watch or bracelet could also work, of course. Even a neck pendant if that's your thing. The point is physical, on your person, and crypto based on near field. The problem with longer ranges, even just a few cm, is the prospect for snooping or triggerring unintended authentications. My preference would be mm range.

> The problem with longer ranges, even just a few cm, is the prospect for snooping or triggerring unintended authentications.

The advantage of using a watch (or another device with a built-in screen) is that it avoids exactly that problem. When you authenticate, you have to physically press a button on the device, and the screen tells you precisely what it is you're authorizing.

Using capacitive coupling as the initial communication channel would also help with that, since you'd have to actually touch the object you want to authenticate to with your bare skin.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#295

Earlier quoted context omitted.

A watch or bracelet could also work, of course. Even a neck pendant if that's your thing. The point is physical, on your person, and crypto based on near field. The problem with longer ranges, even just a few cm, is the prospect for snooping or triggerring unintended authentications. My preference would be mm range.

> The problem with longer ranges, even just a few cm, is the prospect for snooping or triggerring unintended authentications. The advantage of using a watch (or another device with a built-in screen) is that it avoids exactly that problem. When you authenticate, you have to physically press a button on the device, and the screen tells you precisely what it is you're authorizing. Using capacitive coupling as the initi…

Both good points. I've been thinking of some contact / button interaction as well, though that's a toss between keeping the device as physically and electrically simple as possible, vs. some level of interaction. A circuit-completion button on a ring might work, which wouldn't require, say, an additional battery. Though battery life would quite likely be years.

Do you have any refs on capacitive coupling? Is that essentially touchscreen devices? How does that fare in exposed / outdoor environments? I'm thinking of wide applications, and something which wouldn't operate at, say, Tokyo Subway levels of use and demand aren't particularly amenable.

(That's tabling the discussion of whether or not you'd want to have per-use charges for transit use or want to offer that as a public service, or only filter based on individuals, etc.)

Field range might be set by speed-of-light delays. Roughly a nanosecond per 30cm (about 10 foot).

Given a 4 GHz clockspeed, your time resolution is about 0.25 nanosecond, or 7.5 cm -- call it 3 inches.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#296
post #203

> a thread emerged about abusive spouses. Now if I'm honest, I didn't see that angle coming and it made me curious - what is the angle? I mean how does Face ID pose a greater threat to victims of domestic violence than the previous auth models? If someone has the PIN and the phone, they can get in without the person (without their biometrics.) Fingerprints and Face recognition increase the chances that an abusive spo…

So... wouldn't that make biometrics a lesser threat?

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#297
post #203

> a thread emerged about abusive spouses. Now if I'm honest, I didn't see that angle coming and it made me curious - what is the angle? I mean how does Face ID pose a greater threat to victims of domestic violence than the previous auth models? If someone has the PIN and the phone, they can get in without the person (without their biometrics.) Fingerprints and Face recognition increase the chances that an abusive spo…

> Fingerprints and Face recognition increase the chances that an abusive spouse needs the other person every time they access the phone.

No they don’t - you have always been able to use a PIN a instead of touchID, so knowing the pin still works just as well with or without it.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#298
post #197

Earlier quoted context omitted.

Before TouchID, I set my passcode to 0000 with a four-hour window where I didn't have to reenter it. I only had one set at all because Find My Friends refused to keep me logged in unless I had a passcode set. With TouchID, I have a complex passcode that I have to enter a couple times a week. It's less secure than some hypothetical setup where I have a complex passcode I have to enter every time I unlock the phone, bu…

My android phone forces me to re-enter my passcode every 24 hours. I think that strikes a nice security median. If someone does get procession of my phone, I only need to stall for less than 24 hours. The rest of the time, the fingerprint scanner works near perfectly. It's actually faster to use the fingerprint scanner than the standard slide to unlock, which is all I ever had setup on my previous phones.

Is this a standard setting that can be managed?

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#299
post #23

There is an opposite use case which will make me consider getting an iPhone X for a long time. Every so often, I leave my phone at home and I need my wife to get some info from it. Or my phone runs out of batteries and my wife's phone is there, and I use to to make a phone call. With Face ID, these possibilities go away.

If it's implemented in the same way as TouchID, you can always fall back to PIN.

Oh. Thank you for pointing this out. It was not clear to me that this is the case. From a quick look at their initial marketing material, it seemed like the way to unlock it was to wave it in front of your face.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#300
post #32

It would be interesting if we could specify a particular face pattern to unlock the phone. Imagine you set up your phone to open only if you smile, now if someone picks up your phone and try to unlock it by pointing it at your face, not smiling would be easier than closing your eyes or looking away. Not even mentioning the health benefit of just smiling :)

It would be awkward to smile/pose before/after a funeral, just because I need to call my mum or check my email... That being said, I do think that there could be a legitimate use case here. One could set up a particular "emotion" (a face pattern) associated with someone forcing them to unlock a phone using their face. I mean, if someone pulls a gun or a knife on me, I'll probably just do as they say and look at the p…

As with almost all things, YOU DON'T HAVE TO USE THAT FEATURE.
Post reply on HN