Live data from Hacker News

FaceID Security [pdf]

images.apple.com

291–300 of 314 posts

Re: FaceID Security [pdf]

#291
post #201

Earlier quoted context omitted.

Apple’s studies/metrics showed that basically no one (5-10%?) used passwords or pins before TouchID. You already have to educate them to use a password, is it that hard to say ‘and don’t use biometrics either’?

No, now you have an additional problem, because they might ignore the advice to use a password now that they think their device is secure by default

If you don’t know a passcode is required for touchID/FaceID, you don’t know enough about the topic to comment.

Re: FaceID Security [pdf]

#292
post #79
post #66

Earlier quoted context omitted.

> It's unlikely that someone will be able to unlock my phone without me knowing it when using TouchID Do you really think it's likely that someone will steal your phone and then trick you into looking at your own phone without you realizing it? At that point you might as well be tricked into putting your finger on a TouchID sensor.

Well it's definitely possible to have me looking my phone held by someone else. And it's then too late...

Yea, it’s possible a thief would be so brazen as to return to the scene of the crime and show you your stolen phone just to unlock it (instead of just assaulting you till you unlocked it). Who are you worried about, the Mission Impssibke team?

Re: FaceID Security [pdf]

#293

I'd like to know how iPhone X users control (play pause) apps directly from their lockscreens. That no longer works right? Isn't that a major disadvantage?

You have to swipe to log-in. The system authenticates you automatically, but doesn't show the home screen unless you swipe.

Re: FaceID Security [pdf]

#294
post #180
post #110

Earlier quoted context omitted.

And they could also install a hardware keyboard. Neither of which is going to happen. Just because you can do something doesn't mean you should.

Fingerprint reader on the back is unobtrusive and quite an intuitive way to unlock a phone. I can hardly find any issue or "major compromise" with it. A physical keyboard on the other hand makes a phone at least twice as thick, twice as heavy, and twice as ugly (although the last one is more subjective).

If I had a dollar for every time I watched someone turn their Android phone around to look for the fingerprint sensor on the back, I would have a lot more free time to post on HN.

Re: FaceID Security [pdf]

#295

I'll bet most people who dismiss TouchID and FaceID as useless because they're "usernames" and not "passwords", have a bog standard lock and key on their house. Funny thing about those house keys. They can be stolen, lost, or duplicated from pictures. But TouchID and FaceID have liveness tests to prevent forgeries, your biometrics can't be easily stolen, and you can't lose them. A house key is called a "key" though,…

You can refuse to give out a password or claim you forgot, but with biometrics there is not much of an option.

Re: FaceID Security [pdf]

#296

Earlier quoted context omitted.

> It sounds like fpgaminer's argument is that biometric keys can't be compromised because of "liveness tests". You're arrested, and the cops hold the phone up to your face to unlock it. That's a pretty big compromise, and there's literally nothing you can do to prevent it.

The same holds true for physical keys. If you're arrested then the cops can tie you, grab the keys and unlock your door "and there's literally nothing you can do to prevent it.". Also some guy can just make a copy your key (pretty trivial) -- heck people can even break your door bypassing the key altogether.

But with passwords that is not the case.

Re: FaceID Security [pdf]

#297
post #163

Earlier quoted context omitted.

Yes, but the police have to get warrants. If they fail to get a warrant, then it's inadmissable in court. In the phone case, they don't need a warrant if your authentication method is literally your face.

In the United States, the Supreme Court does not allow warrantless cell phone searches. https://en.wikipedia.org/wiki/Riley_v._California

Well, that's usually not the case in the other 96% of the world.

And even there, would this stop a police force who routinely abuses, beats up, or even kills innocent people on the street for no or imagined provocation?

Re: FaceID Security [pdf]

#298
post #141

Earlier quoted context omitted.

It doesn't activate unless you look at the lock screen, so you can just refuse to look at it? https://www.wired.com/story/iphone-x-faceid-security/

> It doesn't activate unless you look at the lock screen, so you can just refuse to look at it? Have you ever been detained? As far as I'm concerned, "refuse to look at it" is useful as a prevention tactic as not having any lock at all.

huh... is touchID more useful? Is a PIN more useful?

I'm honestly curious, what's the difference between "I refuse to look at my phone" and "I refuse to enter my PIN" when being detained?

Re: FaceID Security [pdf]

#299
Just wondering, at what point will the face camera data be used to send feedback to advertisers? Being able to tell if phone users watched (for example) a youtube ad and with what facial expression dynamics would be worth something to someone.

Re: FaceID Security [pdf]

#300

Earlier quoted context omitted.

Or I guess our detection of risk differs. I have never been detained when I didn't have a "hair on my neck raise" with enough time to disable my phone. If you are in such high risk situations continuously that "be proactive when you're at-risk" is appreciably the same as "don't use FaceID ever", then I say you are doing something very wrong and not just incidentally being stopped for a suspicion of possibly doing som…

Even for long alphanumeric passcodes, a pipe wrench has a 99.99% effectiveness in passcode discovery, given sufficiently bad actors. https://xkcd.com/538/

Please don’t link to XKCD, especially when it’s been already done multiple times in this thread. It is pretty much the lowest effort comment you can make besides maybe “+1”.
Post reply on HN