Live data from Hacker News

Fingerprints are Usernames, not Passwords

blog.dustinkirkland.com

41–50 of 261 posts

Re: Fingerprints are Usernames, not Passwords

#41
post #34

All these academic arguments about the security of fingerprints are interesting but completely are detached from the day-to-day use of TouchID. I've been using it for about a week or so now. It's incredibly convenient. It unlocks my phone almost instantly. It prevents random people near by phone from being unable to unlock it. If a thief got their hands on it, they'd have a few attempts to unlock it with a fake finge…

Please don't delude yourself into thinking this is any safer against the typical kind of smartphone theft.

Thieves will offload the phone to someone using software explicitly designed to wipe electronics to be resold.

Whether they are wiping an iphone that happens to have touch ID or not is only relevent towards the resale price once it's wiped.

Clearly Apple marketing works, as it's somehow convinced a member of (I'd hope) a more technical audience that their electronics are somehow safer against thieves.

Re: Fingerprints are Usernames, not Passwords

#42

I'm not so sure. How many people are motivated to dupe your fingerprints to get into your iPhone? How many of those people could conceivably get into your iPhone through other ways? Fingerprints are a nice way to keep almost everyone out of your device. And for the rest, well, I really doubt some other locking mechanism would've kept them out.

Identification via fingerprints is fine, it's the authorization to do something that can be problematic. So, unlocking your phone, not too bad, accessing your bank records, not so good.

If the fingerprint is the identification that is used to then trigger decryption of securely stored data, it's a lot less secure of a mechanism than a fingerprint AND a password.

There was a good recent discussion that fingerprints also do not enjoy the same protection as passwords, as the fingerprint is not a "content of your mind". Here's the wired article on this: http://www.wired.com/opinion/2013/09/the-unexpected-result-o...

It was also discussed at length on HN, but I can't find the thread.

Re: Fingerprints are Usernames, not Passwords

#43
"Once your fingerprint is compromised how do you change it?"

This is the central question for all biometrics for me and I believe one of the hardest problems to solve. There are many people who believe they are solving this by using ever more intricate biometric identifiers, thus increasing the bar to reproduce them beyond what they believe currently feasible. But I'm yet to see that central question addressed.

What happens when you lose control of a biometric key?

Re: Fingerprints are Usernames, not Passwords

#44
post #21
post #8

Earlier quoted context omitted.

Unique? Maybe. Unreplicable? I can't imagine so, we're all just a bunch of molecules. At some point in the perhaps-not-too-distant future, we will likely have very sophisticated brain-scanning technologies, and combined with advances against biometric methods, basically any form of authentication will be useless. I have absolutely no idea how to get around this, and can only hope that our society has advanced enough…

That's an rather interesting idea. If you could get Cory Doctorow to write "The Day the Password Died" from your prompt, I'd be very happy. Synopsis: an evil government steals the private thoughts and passwords of its citizens, most of whom are unaware of the threat. A few paranoid individuals come up with increasingly bizarre biometric passwords, but the government has secretly approved unauthorized (and speedy) clo…

That would be pretty cool. I can't imagine that nobody else has thought of this idea before, though...

What really scares me, though, is when we get to the point of not just being able to read thoughts, but being able to write them. How would you ever know that your memories and emotions have not been tampered with? As far as you know, you've always loved your corporate overlords, and would never do anything to work against them...

Re: Fingerprints are Usernames, not Passwords

#46
post #34

All these academic arguments about the security of fingerprints are interesting but completely are detached from the day-to-day use of TouchID. I've been using it for about a week or so now. It's incredibly convenient. It unlocks my phone almost instantly. It prevents random people near by phone from being unable to unlock it. If a thief got their hands on it, they'd have a few attempts to unlock it with a fake finge…

Please don't delude yourself into thinking this is any safer against the typical kind of smartphone theft. Thieves will offload the phone to someone using software explicitly designed to wipe electronics to be resold. Whether they are wiping an iphone that happens to have touch ID or not is only relevent towards the resale price once it's wiped. Clearly Apple marketing works, as it's somehow convinced a member of (I'…

Uh, no. Of course it's doesn't prevent theft. (Though the new 'wipe the phone in 10 tries' thing may deter it, separate from TouchID, I'm not sure.)

The point is that with TouchID (as opposed to no passcode) the thief will not be able to send porn to my mom or read my text messages before they wipe the phone.

Re: Fingerprints are Usernames, not Passwords

#47

Uhhh, what? Of course, there are civil liberties at issue as well, since Apple could potentially share the information collected with governments. http://truthseekerdaily.com/2013/09/exclusive-apple-admits-iphone-5s-fingerprint-database-to-be-shared-with-nsa/ This link has many of the hallmarks of bullshit, but it still spooks me.

Link references a satire site. Disappointed to see it's still got legs.

Re: Fingerprints are Usernames, not Passwords

#48

I'm not so sure. How many people are motivated to dupe your fingerprints to get into your iPhone? How many of those people could conceivably get into your iPhone through other ways? Fingerprints are a nice way to keep almost everyone out of your device. And for the rest, well, I really doubt some other locking mechanism would've kept them out.

What are people going to do when, in the all-too-near future, criminals begin sharing and selling databases of stolen high resolution finger prints? One theft isn't practical? How about a million? Driven by a never-ending pursuit of monetary gain via crime; with criminals always happy to conquer the latest technology wave. There's absolutely no reason to think that criminals won't amass substantial finger print recor…

I'm not sure I agree. How exactly is anyone (other than the government) supposed to be able to get all these fingerprints? Are you suggesting people are just going to go around and start dusting for prints anywhere they can or what? Maybe fingerprint phishing? (That doesn't even make sense unless we start transmitting actual fingerprint data to servers instead of mostly using it to protect password managers client-side.) The reason identity thieves can get their hands on social security numbers and passwords is because people have to share that information deliberately a lot more often. If you breach the right database, maybe you'll score the jackpot and get the financial details of a few million people, but what database can you breach to get peoples' fingerprints in a format that allows you to create fake fingers to bypass biometrics? Who's going to be keeping high-res copies of fingerprints around, let alone in enough quantity where it might actually pose a risk to a decent proportion of the population?

Re: Fingerprints are Usernames, not Passwords

#49

Earlier quoted context omitted.

I'm sure 5s's are fetching at least $400 on the conservative side. If all I have to do is spend like $5 and follow a how-to on a website, I think a lot of people would be willing to make the investment.

If your objective is to sell a stolen iPhone then you still have to know the owners Apple ID and password due to activation lock. Being able to bypass Touch ID isn't going to help you.

Nope. If it's not a hardware lock, it will be bypassed.

Re: Fingerprints are Usernames, not Passwords

#50

Uhhh, what? Of course, there are civil liberties at issue as well, since Apple could potentially share the information collected with governments. http://truthseekerdaily.com/2013/09/exclusive-apple-admits-iphone-5s-fingerprint-database-to-be-shared-with-nsa/ This link has many of the hallmarks of bullshit, but it still spooks me.

Frankly I just ignore the bullshit-scented links and don't even bother getting spooked; usually if it's real, it will show up again in a less-suspicious place, and I'll pay attention to it then.

It may be an imperfect filter, but just you can't waste your time giving credence to an article on "www.gunsgunsguns.com" about why civilians need automatic weapons, or every other crackpot link.

Post reply on HN