Live data from Hacker News

Fingerprints are Usernames, not Passwords

blog.dustinkirkland.com

61–70 of 261 posts

Re: Fingerprints are Usernames, not Passwords

#62
post #58
post #54

Earlier quoted context omitted.

It is more difficult to defeat a touch sensor than face unlock. With face unlock, I just need a photo of the phone's owner. With a fingerprint unlock, I need to go to at least a little trouble to fake the fingerprint.

Depends on scenario. If you steal a phone from a bag on the subway, you'll never be able to get that photo but can probably lift the print right off the phone itself. So maybe iOS has better-yet-still-mediocre protection against snooping yet inferiorly-mediocre guards against identity theft. Yawn. In neither case is the phone meaningfully protected against serious attack. Why must we have this argument? It's a cute f…

but can probably lift the print right off the phone itself

That doesn't seem to be the case to my knowledge. The evidence from the successful attack is that you need an excellent-quality print from one of the specific fingers that has been programmed into the phone. Some phones probably have that on them, but it appears likely that many do not.

Re: Fingerprints are Usernames, not Passwords

#63

I'm not so sure. How many people are motivated to dupe your fingerprints to get into your iPhone? How many of those people could conceivably get into your iPhone through other ways? Fingerprints are a nice way to keep almost everyone out of your device. And for the rest, well, I really doubt some other locking mechanism would've kept them out.

What are people going to do when, in the all-too-near future, criminals begin sharing and selling databases of stolen high resolution finger prints? One theft isn't practical? How about a million? Driven by a never-ending pursuit of monetary gain via crime; with criminals always happy to conquer the latest technology wave. There's absolutely no reason to think that criminals won't amass substantial finger print recor…

Let's say criminals manage to build a database of everybody's fingerprint. Now, I steal a phone, and have access to that database. How do I query it?

Re: Fingerprints are Usernames, not Passwords

#64
post #54
post #37

Earlier quoted context omitted.

s/TouchID/Face Unlock/g and back up about 2 years and you can find all the same things said about Ice Cream Sandwich. It's a cute feature. It's not going to change the world, sell another billion phones, push other companies out of the market, or save anyone from serious attacks. It's probably a good idea to enable it anyway.

It is more difficult to defeat a touch sensor than face unlock. With face unlock, I just need a photo of the phone's owner. With a fingerprint unlock, I need to go to at least a little trouble to fake the fingerprint.

Ehh, I haven't crunched the numbers, but that's not necessarily true. Instead of taking a still picture, use video to take a few images and generate a rough 3d image. While I don't think the initial face recognition on Android had it, I believe they (or someone else) did later.

I have no idea how finger print vs facial recognition compare in accuracy, but a decently implemented facial recognition system shouldn't be compromised by a still image.

Re: Fingerprints are Usernames, not Passwords

#65
Fundamentally, a username and password are parts of the same thing - a collection of information (often a string of text) that you need to get access to something. The 'username' is usually just the part of that isn't necessarily hidden.

Part of the problem is that Apple's iOS has no username, just a password. Thus, one of the differences with a fingerprint 'password' that I haven't seen much discussed is that it would make him harder to share that tablet with his wife, since they can share one four-digit passcode, but not (as far as I know) two different fingerprints. The fingerprint makes it much harder for the popular family use cases between letting one person in and letting everyone in.

Edit: OK, cool, my comment is invalid.

Re: Fingerprints are Usernames, not Passwords

#66
post #51

Not essential to the main thesis of the article, but still: "But let's just say you're okay with Apple sharing your fingerprints with the NSA, as I've already told you, they're not private at all." Ok, they are not private but I'd still not willingly put them on anything controlled by an US corporation. Govt sending their agents to collect my fingerprints from glasses? Not feasible, too costly. Agency asking Apple to…

As others have joked: Imagine how much people would freak out if Apple devices had a microphone or a camera capable of recording you surreptitiously!

If you're worried that Apple will roll over for the NSA, and that the NSA will, at some point, be out to get you, the quantity of information they could gather through backdoors on your phone is so astounding that it's hard to understand why hashed fingerprint feature analysis would be the last straw.

Re: Fingerprints are Usernames, not Passwords

#67
post #54
post #37

Earlier quoted context omitted.

s/TouchID/Face Unlock/g and back up about 2 years and you can find all the same things said about Ice Cream Sandwich. It's a cute feature. It's not going to change the world, sell another billion phones, push other companies out of the market, or save anyone from serious attacks. It's probably a good idea to enable it anyway.

It is more difficult to defeat a touch sensor than face unlock. With face unlock, I just need a photo of the phone's owner. With a fingerprint unlock, I need to go to at least a little trouble to fake the fingerprint.

>I just need a photo of the phone's owner.

As they said when they unveiled the feature and people mentioned this: give them a little credit.

Re: Fingerprints are Usernames, not Passwords

#68
Realistically 1) most people don't use a PIN code, 2) those that do use their birthday MMDD or DDMM.

If you think someone where you work/live might have to tools to lift your fingerprint from a beer bottle or spacebar, you probably have more serious problems than the contents of your iPhone.

I'm sure security nuts will put their iPhone in a shielded box with a coded lock on it, in addition to using (and painfully entering on each unlock) a high entropy passphrase that's as long as possible.

More power to them.

TouchID is a good enough to prevent my daughters from seeing the naughty texts I send to my wife (none of your business either), and that's more or less the level of security TouchID is designed for.

Re: Fingerprints are Usernames, not Passwords

#69
post #39

Earlier quoted context omitted.

I don't think you can call something a cute feature when it's turned on on most phones and is used to unlock them. I would guess that by far the majority of iPhone 5S's have TouchID enabled. I wouldn't be surprised if it's more than 90%. The feature is just that well executed.

I would be very surprised if it is that high now even with the early adopter skew. Reports say that last year it was around a quarter of smartphone users use passcode locks on their work phone ( http://www.welivesecurity.com/2012/02/28/sizing-up-the-byod-... ). I imagine 5S rates are higher than that, but 90% would be insanely impressive. When it comes to computer security, as usual, people's apathy is the biggest pr…

I'm sure opt-in/opt-out is a major factor, too. I don't have a 5S, but I'm pretty sure it's opt-out. I think even after upgrading to iOS7 I had to opt-in again to turn on the numerical pass code.
Post reply on HN