Live data from Hacker News

I recommend against using biometric identification

medium.freecodecamp.org

61–70 of 239 posts

Re: I recommend against using biometric identification

#61
post #5

The issues raised in the article may explain why Apple just added the ability to passcode-lock your device by pressing the power button 5 times. Though people have been raising similar issues about biometric identification for years. See this article from back when TouchID was released 2013, titled Fingerprints are Usernames, not Passwords . http://blog.dustinkirkland.com/2013/10/fingerprints-are-user...

Ehh... it's not the same as a username. It's more like fingerprints are door locks. Any determined thief can get around it. But it protects you from people who aren't really all that determined. And for most people door locks are sufficient. But if you are a major crime lord, protecting something extremely valuable, or just really into security then door locks are not enough.

Who you are, what you have, and what you know. Those are what we need to have good security. Fingerprints confirm who you are. What you have is the phone, in this case. What you know is the password.

If you're concerned about security, use the print/face and the password.

Re: I recommend against using biometric identification

#62

Earlier quoted context omitted.

I see people saying Apple should allow fingerprint plus passcode, but I've yet to hear someone explain how it would work if it can't read your fingerprint? A longer passcode? Why not just use the longer passcode in the first place.

How does it work today if you just enable fingerprint authentication (I'm asking because I don't know) ? Do you also have to set a backup passcode to use in case it can't read your fingerprint? Can you register multiple fingerprints in case you decide to put your main index finger too close to a sanding belt?

On iPhone, you can register multiple fingerprints, but if it can't read your finger within 5(?) tries, it requires a passcode. It also allows you to skip the fingerprint and just enter the passcode if you want. That's useful for when you ask someone you trust to find something on your phone for you.

Re: I recommend against using biometric identification

#63
post #49
post #40

I don't require any password on my phone. The only reason I put a fingerprint on it is to prevent pocket dials. And even with that, it sometimes almost seems to dial 911 by mistake. All I need is a way for the screen to ignore input (when it turns itself on) unless I activate it with the power button. Are there really that many people who truly need very high security on their phones? Seems to me most people just wan…

If you have email set up on your phone and someone steals your phone without a passcode it’s pretty much game over for all your online accounts. Also defeats two factor auth in case you have that on your phone. Also a lot of services let you reset your password via SMS etc.

For SMS all you have to do is put the SIM card in a different phone, locking your phone does not help.

The only accounts you can change the password with a simple email are low security accounts without much of worth to steal.

I'm sure there are people with more stringent security needs, but most people just need to deter casual snooping and don't need to stop hackers.

I personally do not like having the same security on everything. I find that detrimental. I think phone makers should do a better job of having multiple tiers of security.

Re: I recommend against using biometric identification

#65
post #58

I would personally like to have groups of things that can be unlocked - that I can define - Nothing - essential what's on lock (weather, maybe news headlines) - Face - basic stuff - games, calculator, News apps - Fingerprint - mail, calendar, text message, browser - Pass code - banking, settings A one all seems backward - there are something things I don't want to protect at all (don't care if someone can access) on…

I am not sure why phones haven't been made with different profiles. Yesterday (?), someone here mentioned they wanted to be able to give the (presumed) cops a phone that was blank. I pointed out that was a horrible idea, but didn't really explain why. If it is a totalitarian regime, they'll just kill you. If you're ever really in such a situation, a blank phone is probably the worst thing you can give them. Instead,…

Android has pretty good profile support, I have my own profile, a guest one which is wiped when you logout, and one for my kids which can't buy things.

Works pretty well for me, there's a little profile icon in quick settings to switch

Re: I recommend against using biometric identification

#67
post #65
post #58

Earlier quoted context omitted.

I am not sure why phones haven't been made with different profiles. Yesterday (?), someone here mentioned they wanted to be able to give the (presumed) cops a phone that was blank. I pointed out that was a horrible idea, but didn't really explain why. If it is a totalitarian regime, they'll just kill you. If you're ever really in such a situation, a blank phone is probably the worst thing you can give them. Instead,…

Android has pretty good profile support, I have my own profile, a guest one which is wiped when you logout, and one for my kids which can't buy things. Works pretty well for me, there's a little profile icon in quick settings to switch

Nice! That must be a new feature? It had no such thing, the last time I used Android.

Err... I use a Windows phone, even though I'm normally a Linux user. I kinda like it.

Re: I recommend against using biometric identification

#68
post #61

Earlier quoted context omitted.

Ehh... it's not the same as a username. It's more like fingerprints are door locks. Any determined thief can get around it. But it protects you from people who aren't really all that determined. And for most people door locks are sufficient. But if you are a major crime lord, protecting something extremely valuable, or just really into security then door locks are not enough.

Who you are, what you have, and what you know. Those are what we need to have good security. Fingerprints confirm who you are. What you have is the phone, in this case. What you know is the password. If you're concerned about security, use the print/face and the password.

Fingerprints don't confirm who you are though.

In certain circumstances they can, but a phone sensor accepting whatever input it is being given isn't one of those circumstances.

Re: I recommend against using biometric identification

#69
post #14

Earlier quoted context omitted.

I mean, it's less plainly visible then your face, or even pictures of your face. I bet you there's an algorithm somewhere that can take a picture of your face and turn it into a 3d model. Then you can take that model, 3d print it, then use it to unlock your phone.

I believe this was the exact attack they were talking about preventing with the "we worked with Hollywood mask-makers" line. Also, as far as I understand, the demo videos are misleading: these systems (this and Windows Hello) are taking infrared pictures of your face, not visible-light pictures. From their perspective, you look like a (3D depth-tested) network of hot capillaries. This is 1. rather hard to recreate wi…

A few years ago, Apple bought Primsense. Primsense made the sensor in the original Kinect. They've now integrated this into their Face ID system, or at least that's what the keynote suggests. It projects a known random dot pattern and an ASIC does some image processing to figure out the depth in the image (nice patent, by the way).

So they have two bits of info: the 3D reconstruction and an infrared image with/without dots, they also have a colour image using the FaceTime camera. I would be surprised if they didn't use more information than just the point cloud. Biometric security at airports uses a similar system, you can see the laser light when yo go through the e-Passport gates.

https://techcrunch.com/2017/09/12/iphone-x-basically-has-a-k...

Re: I recommend against using biometric identification

#70

Earlier quoted context omitted.

How does it work today if you just enable fingerprint authentication (I'm asking because I don't know) ? Do you also have to set a backup passcode to use in case it can't read your fingerprint? Can you register multiple fingerprints in case you decide to put your main index finger too close to a sanding belt?

On iPhone, you can register multiple fingerprints, but if it can't read your finger within 5(?) tries, it requires a passcode. It also allows you to skip the fingerprint and just enter the passcode if you want. That's useful for when you ask someone you trust to find something on your phone for you.

I see. So maybe a combination of fingerprint + shorter passcode to unlock, or a long passphrase to bypass?
Post reply on HN