Live data from Hacker News

Face ID, Touch ID, No ID, PINs and Pragmatic Security

troyhunt.com

301–310 of 314 posts

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#301
post #203

> a thread emerged about abusive spouses. Now if I'm honest, I didn't see that angle coming and it made me curious - what is the angle? I mean how does Face ID pose a greater threat to victims of domestic violence than the previous auth models? If someone has the PIN and the phone, they can get in without the person (without their biometrics.) Fingerprints and Face recognition increase the chances that an abusive spo…

I'm not sure, but I know with my spouse and I, we always put each others Biometrics into each other's devices (I add her fingerprints to my phone and vice versa), share a lastpass account so we know each other's passwords, add our email accounts to each other's devices so we can always look at each others email, etc. If you are married to someone and don't trust them enough to do the same I have to question the found…

> If you are married to someone and don't trust them enough to do the same I have to question the foundation the marriage is built on.

This is such a stupid attitude. It is your way or nothing, right?

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#303
post #280
post #194

Earlier quoted context omitted.

I'm not sure that Touch ID can come back in its current form. Phil stood on stage and told us Touch ID is 50,000 secure and Face ID is 1,000,000 secure. I think the only way for Touch ID to come back is for it to cover the whole display, so it can authenticate every touch.

> I think the only way for Touch ID to come back is for it to cover the whole display, so it can authenticate every touch. Touch ID only works on the first try about half the time for me, I would love to bring that experience to all my interactions with my phone.

You could set it up that at least one fingerprint has to be recognised correctly every X seconds.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#304
post #217
post #177

> ...when you do use the biometric options we're about to get into, you're still going to need [a pin] on your phone anyway. For example, every time you hard-reboot an iPhone with Touch ID you need to enter the PIN This is what has been missing from every discussion of this issue that I've seen so far. The face scan isn't "insecure" even if you're worried about border searches. Just turn off your phone when you get i…

I don't want to be that 'if you've got nothing to hide then' guy but why are people so worried about what border agents in particular will see on their cell phone? I am not saying that I wouldn't mind at all if my phone was searched. But I can't think of anything in particular that I would be concerned about if it was. Sure in theory the agent could remember some personal information and come back later and use that…

I'm not sure if it's relevant but Dubai and UAE have been known to put people in prison for quite unbelievable reasons often as they were transferring through the airport.

One such instance included a British guy who had shared a Facebook post recommending giving aid to refugees, Dubai police put him in jail over it - that was over a year ago and I believe he's still there. One instance included a microscopic amount of cannabis found on the sole of a passengers shoe, he got almost 4 years in prison.

There are many many other instances, if locking your phone stops them from even chancing it, it might be worthwhile.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#305
post #94

Given that the authentication methods are "differently secure," wouldn't it be good if we were offered the option to combine them and require both for unlock? I would love to use Face ID + PIN or Touch ID + PIN for better security.

The problem is that the PIN is always dominant over Face ID or Touch ID. Face ID doesn't work? Use your PIN. What happens if you use local 2FA and your Face ID doesn't work? You can't enter the PIN, because that would effectively render 2FA useless. This would probably require some master PIN, which makes things more complex, and increased complexity correlates which reduced security.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#306
post #105

Earlier quoted context omitted.

If you have a mac you can use Messages to check your message on your laptop directly.

Pretty much everyone at your standard 9-5 office job has their personal phone with them all the time and their personal computer with them none of the time.

You can work on a mac...

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#307

Earlier quoted context omitted.

This is especially useful for when the app developer doesn't think there is a reason for them to develop such a system. For example, I don't want my son playing a zombie game, but I myself play it often. I could then lock him out of said game, but still give him my phone to use.

This isn't exactly what you are looking for, but have you tried Guided Access on iOS (or whatever the equivalent is on Android)?

Yes, that is the way I do it currently. It's a real pain though.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#308
post #217
post #177

> ...when you do use the biometric options we're about to get into, you're still going to need [a pin] on your phone anyway. For example, every time you hard-reboot an iPhone with Touch ID you need to enter the PIN This is what has been missing from every discussion of this issue that I've seen so far. The face scan isn't "insecure" even if you're worried about border searches. Just turn off your phone when you get i…

I don't want to be that 'if you've got nothing to hide then' guy but why are people so worried about what border agents in particular will see on their cell phone? I am not saying that I wouldn't mind at all if my phone was searched. But I can't think of anything in particular that I would be concerned about if it was. Sure in theory the agent could remember some personal information and come back later and use that…

It is not only you. It exposes everybody to be blackmailed by the government or who every gets hold of the information. Judges, politicians, businessmen, scientists, journalists, etc, etc. It weakens the democratic fabric.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#310
post #306

Earlier quoted context omitted.

Pretty much everyone at your standard 9-5 office job has their personal phone with them all the time and their personal computer with them none of the time.

You can work on a mac...

Signing in to personal accounts on a work computer is a terrible privacy practice and also unprofessional IMO.
Post reply on HN