http://blogs.msdn.com/b/b8/archive/2011/12/16/signing-in-wit...
The important thing is that this feature is completely optional and can be disabled in organizations by group policy.
31–40 of 46 posts
http://blogs.msdn.com/b/b8/archive/2011/12/16/signing-in-wit...
The important thing is that this feature is completely optional and can be disabled in organizations by group policy.
I find it annoying that we're innovating different ways of doing the exact same thing: switching from completely locked to completely unlocked. I want near-instant access to a notepad for jotting down thoughts. I want more locking for reading existing notes. Still more for accessing email. I want a strong lock protecting apps related to finances. The simple lock (just to prevent pocket-dialing) should be like a slide…
One of my absolute favorite iOS features in iOS5 before I switched to Android was the new "take a photo from the lock screen" button. I felt understood when they added that.
Serious question: why aren't we using biometrics, e.g., fingerprints or iris detection? I want authentication that: (1) identifies me, not a key-holder, and (2) requires only things that I will always have with me.
Because biometrics is the least secure and easiest to copy method of security. There are three types: What you know, what you have, and what you are. What you know is the most secure in theory, but suffers from the limitation on human memory. But it can not be stolen from someone without them knowing. (Yes I know it can be stolen from a device, but that a problem in implementation and not fundamental.) What you have…
Isn't the fact that scanned fingerprints are still used by immigration control and criminal investigators evidence against this?
Serious question: why aren't we using biometrics, e.g., fingerprints or iris detection? I want authentication that: (1) identifies me, not a key-holder, and (2) requires only things that I will always have with me.
I'm curious too. Japan has had fingerprint scanners on phones for a while. E.g. http://www.nfcrumors.com/11-15-2011/fujitsu-launches-nfc-pho... Would be a great feature to have on my iPhone. At least in Apple's case, perhaps the problem is the added cost of the scanner combined with Apple's one-size-fits-all model (as opposed to offering different models, so fingerprint scanners only for those who need the extra secu…
Serious question: why aren't we using biometrics, e.g., fingerprints or iris detection? I want authentication that: (1) identifies me, not a key-holder, and (2) requires only things that I will always have with me.
You can't change biometrics, so once someone forges your identity they will always have access to anything that requires only biometric identification.
Anyway, this is already the case – fingerprints are used as evidence of criminal liability. If someone forges my fingerprints, they could get me into a huge amount of trouble, in theory.
Earlier quoted context omitted.
Because biometrics is the least secure and easiest to copy method of security. There are three types: What you know, what you have, and what you are. What you know is the most secure in theory, but suffers from the limitation on human memory. But it can not be stolen from someone without them knowing. (Yes I know it can be stolen from a device, but that a problem in implementation and not fundamental.) What you have…
This is completely counterintuitive to me. How are you going to remotely copy my fingerprint or iris? Isn't the fact that scanned fingerprints are still used by immigration control and criminal investigators evidence against this?
Lets also say that you somehow become aware of them having a copy of your fingerprints and you remember that your phone requires your fingerprints to unlock; what do you do?
It's the fact that you can't permanently change your fingerprints nor restrict access to them which make them bad for authentication. Those two qualities also make them good for forensics.
A question that bugs me about these kind of locked phones: What about emergency calls? I don't have a smartphone so I don't know how it works, but it seems from what I've seen that modern cellphones prevent people from using them for emergency calls unless they know the swipe/unlock code. Is that correct? edit: just googled, looks like android and iphone have an 'emergency call' button on the lock screen. Fair enough…
It should be mentioned that this creates problems of its own. Toronto Police recently released their numbers, and 18% of the calls to 911 were pocket dials created by those "emergency call" buttons. We're talking hundreds of thousands of calls clogging 911 each year, each requiring the operator listen to the whole pocket dial, attempt to make contact, call back, and if no contact is possible, send a squad car to inve…
Earlier quoted context omitted.
Because biometrics is the least secure and easiest to copy method of security. There are three types: What you know, what you have, and what you are. What you know is the most secure in theory, but suffers from the limitation on human memory. But it can not be stolen from someone without them knowing. (Yes I know it can be stolen from a device, but that a problem in implementation and not fundamental.) What you have…
This is completely counterintuitive to me. How are you going to remotely copy my fingerprint or iris? Isn't the fact that scanned fingerprints are still used by immigration control and criminal investigators evidence against this?
Not at all - they use it for identification not authentication.
It's a completely different application.
Earlier quoted context omitted.
You can't change biometrics, so once someone forges your identity they will always have access to anything that requires only biometric identification.
How does one forge biometrics? (Notice that I'm not asking how to spoof biometric readers with insecure designs, e.g., the one mythbusters busted). Anyway, this is already the case – fingerprints are used as evidence of criminal liability. If someone forges my fingerprints, they could get me into a huge amount of trouble, in theory.
At the end of the day a finger or an iris is a physical object you can make. Since it's impossible to keep the "key" secret, you can always copy it and make one - how hard you have to work to make it depends on how good the design is, but fundamentally there is no secret and without a secret it's useless for authentication.
> If someone forges my fingerprints, they could get me into a huge amount of trouble, in theory.
Yes, they can, and sometimes they do. But it's not common enough for police to worry about it.
Earlier quoted context omitted.
This is completely counterintuitive to me. How are you going to remotely copy my fingerprint or iris? Isn't the fact that scanned fingerprints are still used by immigration control and criminal investigators evidence against this?
> Isn't the fact that scanned fingerprints are still used by immigration control and criminal investigators evidence against this? Not at all - they use it for identification not authentication. It's a completely different application.