Earlier quoted context omitted.
Apple’s studies/metrics showed that basically no one (5-10%?) used passwords or pins before TouchID. You already have to educate them to use a password, is it that hard to say ‘and don’t use biometrics either’?
No, now you have an additional problem, because they might ignore the advice to use a password now that they think their device is secure by default
FaceID Security [pdf]
291–300 of 314 posts
Re: FaceID Security [pdf]
#292Earlier quoted context omitted.
> It's unlikely that someone will be able to unlock my phone without me knowing it when using TouchID Do you really think it's likely that someone will steal your phone and then trick you into looking at your own phone without you realizing it? At that point you might as well be tricked into putting your finger on a TouchID sensor.
Well it's definitely possible to have me looking my phone held by someone else. And it's then too late...
Re: FaceID Security [pdf]
#293I'd like to know how iPhone X users control (play pause) apps directly from their lockscreens. That no longer works right? Isn't that a major disadvantage?
Re: FaceID Security [pdf]
#294Earlier quoted context omitted.
And they could also install a hardware keyboard. Neither of which is going to happen. Just because you can do something doesn't mean you should.
Fingerprint reader on the back is unobtrusive and quite an intuitive way to unlock a phone. I can hardly find any issue or "major compromise" with it. A physical keyboard on the other hand makes a phone at least twice as thick, twice as heavy, and twice as ugly (although the last one is more subjective).
Re: FaceID Security [pdf]
#295I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…
Re: FaceID Security [pdf]
#296Earlier quoted context omitted.
> It sounds like fpgaminer's argument is that biometric keys can't be compromised because of "liveness tests". You're arrested, and the cops hold the phone up to your face to unlock it. That's a pretty big compromise, and there's literally nothing you can do to prevent it.
The same holds true for physical keys. If you're arrested then the cops can tie you, grab the keys and unlock your door "and there's literally nothing you can do to prevent it.". Also some guy can just make a copy your key (pretty trivial) -- heck people can even break your door bypassing the key altogether.
Re: FaceID Security [pdf]
#297Earlier quoted context omitted.
Yes, but the police have to get warrants. If they fail to get a warrant, then it's inadmissable in court. In the phone case, they don't need a warrant if your authentication method is literally your face.
In the United States, the Supreme Court does not allow warrantless cell phone searches. https://en.wikipedia.org/wiki/Riley_v._California
And even there, would this stop a police force who routinely abuses, beats up, or even kills innocent people on the street for no or imagined provocation?
Re: FaceID Security [pdf]
#298Earlier quoted context omitted.
It doesn't activate unless you look at the lock screen, so you can just refuse to look at it? https://www.wired.com/story/iphone-x-faceid-security/
> It doesn't activate unless you look at the lock screen, so you can just refuse to look at it? Have you ever been detained? As far as I'm concerned, "refuse to look at it" is useful as a prevention tactic as not having any lock at all.
I'm honestly curious, what's the difference between "I refuse to look at my phone" and "I refuse to enter my PIN" when being detained?
Re: FaceID Security [pdf]
#299Re: FaceID Security [pdf]
#300Earlier quoted context omitted.
Or I guess our detection of risk differs. I have never been detained when I didn't have a "hair on my neck raise" with enough time to disable my phone. If you are in such high risk situations continuously that "be proactive when you're at-risk" is appreciably the same as "don't use FaceID ever", then I say you are doing something very wrong and not just incidentally being stopped for a suspicion of possibly doing som…
Even for long alphanumeric passcodes, a pipe wrench has a 99.99% effectiveness in passcode discovery, given sufficiently bad actors. https://xkcd.com/538/