I recommend against using biometric identification
41–50 of 239 posts
Re: I recommend against using biometric identification
#42> And to be clear, a court in the US cannot force you to give up your passcode. That passcode exists in your head, and yours alone. It is your property, and won’t be used to incriminate you or strong-arm access to your data unless you voluntarily give it up. While technically true this is false in practice. While they can't force you to provide your passcode they can force you to unlock your phone. Francis Rawls has…
The "police can't force you to give up your passcode" misconception stems from a case in Virginia from 2014 [2], and while that may still be the case in Virginia, it does not mean you can just say "my phone is locked with a passcode, fuck off cop" in every other jurisdiction.
1: https://9to5mac.com/2017/06/01/fifth-amendement-passcodes-pa...
Re: I recommend against using biometric identification
#43Op completely misses how insecure a four digit pin is for prying eyes. If I work in the same office as you, or share any space with you at all, I can pretty much guarantee I can easily sneak a glimpse at your pin when you enter it.
If you want to protect against police, whatever the reason, then PIN is ok butbut be careful when entering it in public.
Re: I recommend against using biometric identification
#44"Historically it was unsafe to fly in an airplane so you shouldn't now"
Re: I recommend against using biometric identification
#45I'd like to add a feature to the FaceID, requiring the user to wink instead of looking with both eyes open, or have a customized facial gesture, which only the user knows. It adds an extra layer of security. Not only that, you get to wink at your phone often as a sign of affection (LOL). Instead of winks, one might choose to do other facial gestures such as stick their tongue out, do a duck-face, etc.
Re: I recommend against using biometric identification
#46- Nothing - essential what's on lock (weather, maybe news headlines) - Face - basic stuff - games, calculator, News apps - Fingerprint - mail, calendar, text message, browser - Pass code - banking, settings
A one all seems backward - there are something things I don't want to protect at all (don't care if someone can access) on one extreme, and things that MUST be protected as much as possible on the other extreme.
I get leaking between apps is an issue, and there are other problems around this - but this approach seems more reasonable
And yeah, for some users (my parents) they just want something simple and don't want to deal with this. So face or fingerprint is a lot better than no code, so this is still an improvement
Re: I recommend against using biometric identification
#47I'd like to add a feature to the FaceID, requiring the user to wink instead of looking with both eyes open, or have a customized facial gesture, which only the user knows. It adds an extra layer of security. Not only that, you get to wink at your phone often as a sign of affection (LOL). Instead of winks, one might choose to do other facial gestures such as stick their tongue out, do a duck-face, etc.
And it’s defeated by someone just watching you unlock your phone in public once.
Re: I recommend against using biometric identification
#48Op completely misses how insecure a four digit pin is for prying eyes. If I work in the same office as you, or share any space with you at all, I can pretty much guarantee I can easily sneak a glimpse at your pin when you enter it.
Exactly, thieves can decide which phone to steal after seeing the PIN (think about a bus or subway in a rush hour.) It's possible to get many pictures of someone if you know who s/he is. It's hard to collect fingerprints, at least for the average thief. If you want to protect against police, whatever the reason, then PIN is ok butbut be careful when entering it in public.
The only reason I have a lock on my phone is so if I lose my phone somewhere randoms can't access it.
If they're going to mug me for my phone they can mug me just as easily for my passcode or my fingerprint.
I guess there is an argument for pick pockets but that's a lesser concern for me. Anywhere it's likely to happen my hand is usually on my phone.
Re: I recommend against using biometric identification
#49I don't require any password on my phone. The only reason I put a fingerprint on it is to prevent pocket dials. And even with that, it sometimes almost seems to dial 911 by mistake. All I need is a way for the screen to ignore input (when it turns itself on) unless I activate it with the power button. Are there really that many people who truly need very high security on their phones? Seems to me most people just wan…
Also a lot of services let you reset your password via SMS etc.
Re: I recommend against using biometric identification
#50The issues raised in the article may explain why Apple just added the ability to passcode-lock your device by pressing the power button 5 times. Though people have been raising similar issues about biometric identification for years. See this article from back when TouchID was released 2013, titled Fingerprints are Usernames, not Passwords . http://blog.dustinkirkland.com/2013/10/fingerprints-are-user...
Ehh... it's not the same as a username. It's more like fingerprints are door locks. Any determined thief can get around it. But it protects you from people who aren't really all that determined. And for most people door locks are sufficient. But if you are a major crime lord, protecting something extremely valuable, or just really into security then door locks are not enough.
If your door lock is compromised, you can change the key. If someone steals your password, you can change the password. If someone steals your fingerprint, you can never change your fingerprint (same with your face).
The other stuff is dead-on: its a "good enough" security measure for phones. But as a security practitioner, the biggest problem IMO is that Apple using TouchID and FaceID is giving the general public the wrong idea about security. Apple claims that these innovations are "cutting edge" security, and so consumers buy into this and then also use fingerprints to secure things like their bank accounts, work logins, password vaults (this is a big one - someone steals your phone and you use your fingerprint to access your LastPass account, which has all of your passwords in it? And your phone is also your 2FA device? You're screwed.) etc, where they really aren't "good enough" at all.
I've worked at companies where we disabled fingerprint logins on certain devices because highly sensitive info is held on those devices, and fingerprints just aren't secure enough to protect them. Then we get yelled at by people from the company because "Apple says fingerprints are the best for security, why aren't you letting us use them?" It's a pain.