Live data from Hacker News

Face ID, Touch ID, No ID, PINs and Pragmatic Security

troyhunt.com

61–70 of 314 posts

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#61
post #50

Earlier quoted context omitted.

But wht was wrong with TouchID ? Were there any examples of it being weak security. What will be after Touch ID? Will Apple continue progress and built in PinchID - a tiny needle that sting you to test if you are you based on your blood/DNA? This is a serious question. Because of there was noting wrong with Touch then why is it removed from new phone and replaced with Face ID. Im also concerned about the data Apple w…

TouchID also is problematic if you're wearing gloves, which people who don't live in San Francisco do during non-trivial portions of the year.

Not sure if this applies to Apple's implementation, but my phone fingerprint recognition fails if my finger is wet (sweat, washing hands).

I haven't tried training it with a wet fingerprint.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#62
post #39
post #30

Earlier quoted context omitted.

> I'd suggest that Dropbox users somewhat self select for those not as concerned about security as others. And more concerned about availability. I would rather say that Dropbox is being used by many people without tech knowledge. And while they might be concerned about security, they often just don't know how improtant 2 factor authentication is. At least that's what I can see for some friends & family.

eeh, since when does u2a protect against back-end breaches? thats just a security layer against phishing or password leaks... don't get me wrong, i'd advice everyone to use it for anything remotely critical, because its pretty easy to setup and live with, but it really doesnt help against state actors or hackers that compromised the data servers.

> since when does u2a protect against back-end breaches?

Because if someone steals your DB password, they still won't be able to login to your account.

Maybe they won't have to, if they also stole your data and found a way to decrypt it, but since those are different things, it is plausible that there could be a leak of login information without a leak of data, in which case your two-factor authentication would keep the attackers out of your data.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#63
post #32

It would be interesting if we could specify a particular face pattern to unlock the phone. Imagine you set up your phone to open only if you smile, now if someone picks up your phone and try to unlock it by pointing it at your face, not smiling would be easier than closing your eyes or looking away. Not even mentioning the health benefit of just smiling :)

I would look forward to the headline where the police had to tickle the accused in order to get access to his phone against his will.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#64

Earlier quoted context omitted.

But wht was wrong with TouchID ? Were there any examples of it being weak security. What will be after Touch ID? Will Apple continue progress and built in PinchID - a tiny needle that sting you to test if you are you based on your blood/DNA? This is a serious question. Because of there was noting wrong with Touch then why is it removed from new phone and replaced with Face ID. Im also concerned about the data Apple w…

TouchID was removed because it took up space on the front of the phone and Apple wanted the screen to be bigger. There's no deeper reason than that. > Will Apple continue progress and built in PinchID - a tiny needle that sting you to test if you are you based on your blood/DNA? I struggle to believe you when you say that's a serious question... > Im also concerned about the data Apple will collect. The FaceID data w…

TouchID is trivially defeated by a 6-year-old:

https://www.usatoday.com/story/news/nation/2016/12/28/girl-u...

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#65
post #50

Earlier quoted context omitted.

But wht was wrong with TouchID ? Were there any examples of it being weak security. What will be after Touch ID? Will Apple continue progress and built in PinchID - a tiny needle that sting you to test if you are you based on your blood/DNA? This is a serious question. Because of there was noting wrong with Touch then why is it removed from new phone and replaced with Face ID. Im also concerned about the data Apple w…

TouchID also is problematic if you're wearing gloves, which people who don't live in San Francisco do during non-trivial portions of the year.

As long as you can easily unbutton your shirt:

http://www.dailymail.co.uk/sciencetech/article-2430654/iPhon...

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#66

Near-field worn devices. http://nfcring.com is an example of what I have in mind. What I'd like to see is this tied into an identity system, such that the ring (or other very-hard-to-misplace, but replaceable and discardable) token is not itself an identity, but rather an access token to an identity store which can present any given identity to any given system. That might be a consistent identity across multiple ses…

So, someone steals the NFC ring and then own the phone? Ring + heat detection of PIN tap pattern will end up giving a false sense of 2FA. (not sure how the ring auths on being worn, didnt see it on the website).

Or cutting off a finger or hand?

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#67
post #4
post #3

All I know is that I will avoid any system that can work if I am not conscious.

So you would prefer FaceID over TouchID?

Yeah, FaceID seems like an improvement in this aspect - unless OP is locking his fingerprints in a safe before going to bed.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#68
post #50

Earlier quoted context omitted.

But wht was wrong with TouchID ? Were there any examples of it being weak security. What will be after Touch ID? Will Apple continue progress and built in PinchID - a tiny needle that sting you to test if you are you based on your blood/DNA? This is a serious question. Because of there was noting wrong with Touch then why is it removed from new phone and replaced with Face ID. Im also concerned about the data Apple w…

TouchID also is problematic if you're wearing gloves, which people who don't live in San Francisco do during non-trivial portions of the year.

> people who don't live in San Francisco

I find this humorous because for me, an Australian, San Francisco is quite cold and I wore gloves there.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#69
For me it's a simple question of cost vs. reward: do I care enough about the security of whatever data is stored with a company, that I'm willing to give the company personal information, when their terms of service almost assuredly give them complete license with it?

This, of course, starts with the question: do I even want to put this in the cloud to begin with?

Edit: I was talking about two factor auth.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#70

For me it's a simple question of cost vs. reward: do I care enough about the security of whatever data is stored with a company, that I'm willing to give the company personal information, when their terms of service almost assuredly give them complete license with it? This, of course, starts with the question: do I even want to put this in the cloud to begin with? Edit: I was talking about two factor auth.

From the OP: "the data is stored in the iPhone's secure enclave and never leaves the device". It appears that this has nothing at all to do with the cloud. And if you don't trust Apple's word here, then you also have no reason to trust that they (or any other handset maker) haven't programmed the camera to surreptitiously take and transmit photos at all times.
Post reply on HN