Live data from Hacker News

Face ID, Touch ID, No ID, PINs and Pragmatic Security

troyhunt.com

311–314 of 314 posts

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#311
post #223
post #217

Earlier quoted context omitted.

I don't want to be that 'if you've got nothing to hide then' guy but why are people so worried about what border agents in particular will see on their cell phone? I am not saying that I wouldn't mind at all if my phone was searched. But I can't think of anything in particular that I would be concerned about if it was. Sure in theory the agent could remember some personal information and come back later and use that…

Depends on how difficult it is to produce an automated system whereby one needs only plug an unlocked phone into a computer in order to hoover up all locally-stored messages, contacts, saved passwords, synced browser histories, etc. The agent themselves doesn't need to care, they can just be instructed to "unlock the phone, plug it in to this computer, wait until the progress bar finishes, hand phone back". Are you o…

This is not an attack. This is iTunes. This is trivial to do.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#312
post #217

Earlier quoted context omitted.

I don't want to be that 'if you've got nothing to hide then' guy but why are people so worried about what border agents in particular will see on their cell phone? I am not saying that I wouldn't mind at all if my phone was searched. But I can't think of anything in particular that I would be concerned about if it was. Sure in theory the agent could remember some personal information and come back later and use that…

What I worry about is Google Authenticator codes for several financial institutions, getting vacuumed out of the phone with everything else and stored on some insufficiently-secured database.

One phrase I've used with success in the past is that I have secure governmental cryptographic codes owned by someone other than myself in my laptop/bag/iphone and am not allowed under law to disclose them to unknown parties such as yourself.

Most first level TSA/DHS people measure the cost/benefit of my assertion and back off.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#313
post #147

I really liked this write-up because it focused on the practicality of the various security mechanisms. Most articles I see usually have a blanket statement like "All biometric security mechanisms are bad!". I think this article does a good job comparing the various logins and describing the pros and cons for different people. Specifically, I appreciate the author calling out when people bring up the "What if" edge-c…

Specifically, getting more people to have better security on their devices is a very difficult User Experience problem, and Apple's pretty good at solving these kinds of problems. TouchID moved the ball forward quite a bit, and FaceID will probably go even further. Obviously neither provide ultimate security, but Apple is in a strategic advantage since they make the hardware and software to make the barn walls and ro…

Here's a dumb question I haven not easily found the answer to.

Can I configure my iphone to require TouchID, FaceID, and a PIN for each unlock of my phone every time?

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#314

Earlier quoted context omitted.

I have tech knowledge, but I had absolutely no knowledge that Dropbox offered 2-factor. I don't keep confidential stuff in DB because, I know that the company effectively has access to everything. Nonetheless, 2 factor sounds interesting. So I look at this: https://www.dropbox.com/help/security/enable-two-step-verifi... Right. Now I understand why so few people have it enabled.

Explain? You read a page about two-step and say that explains why no one has enabled it? You claim to have tech knowledge, but are not able to turn on this simple security setting (or even know it exists, despite that it's listed very clearly in your Dropbox settings page)? I use two-factor/two-step verification on every single service I have, including all social media accounts, email accounts, etc. Most major servi…

> Before enabling two-step verification, you'll receive ten 8-digit backup codes. It is very important that you write these codes down and store them somewhere safe.

Do any of your other systems handle recovery like that?

Post reply on HN