Live data from Hacker News

I recommend against using biometric identification

medium.freecodecamp.org

71–80 of 239 posts

Re: I recommend against using biometric identification

#71
post #61

Earlier quoted context omitted.

Who you are, what you have, and what you know. Those are what we need to have good security. Fingerprints confirm who you are. What you have is the phone, in this case. What you know is the password. If you're concerned about security, use the print/face and the password.

Fingerprints don't confirm who you are though. In certain circumstances they can, but a phone sensor accepting whatever input it is being given isn't one of those circumstances.

They do an adequate job for the vast majority of use cases. I guess you could hire a security guard to walk with you and ensure your ID matches your physical traits?

Nothing is ever completely secure and usable. There will be some trade offs.

Re: I recommend against using biometric identification

#72

> And to be clear, a court in the US cannot force you to give up your passcode. That passcode exists in your head, and yours alone. It is your property, and won’t be used to incriminate you or strong-arm access to your data unless you voluntarily give it up. While technically true this is false in practice. While they can't force you to provide your passcode they can force you to unlock your phone. Francis Rawls has…

I think, at some point it gets to the Supreme court which will decide whether it's covered by the 5th amendment or not.

Sucks to be in jail waiting for that process to play out, though. *edit typo!

Re: I recommend against using biometric identification

#73
post #50

Earlier quoted context omitted.

Ehh... it's not the same as a username. It's more like fingerprints are door locks. Any determined thief can get around it. But it protects you from people who aren't really all that determined. And for most people door locks are sufficient. But if you are a major crime lord, protecting something extremely valuable, or just really into security then door locks are not enough.

The "door lock" analogy ignores the biggest flaw with fingerprints: they're forever. If your door lock is compromised, you can change the key. If someone steals your password, you can change the password. If someone steals your fingerprint, you can never change your fingerprint (same with your face). The other stuff is dead-on: its a "good enough" security measure for phones. But as a security practitioner, the bigge…

Actually fingerprints are relatively easy, if painful, to change.

Your point stands, of course.

Re: I recommend against using biometric identification

#74
post #56

Earlier quoted context omitted.

I think the idea is that legally it is closer to a username. A judge can allow the police to knock down your apartment door through a warrant. But they can't compel you to speak and incriminate yourself. Much the same, they can force you to reveal your fingerprint, but cannot compel you to share a password.

> Much the same, they can force you to reveal your fingerprint, but cannot compel you to share a password. Unfortunately this is dependent on your jurisdiction. In Virginia it's been ruled that law enforcement can't force a password out of you, but in federal court and in other jurisdictions (Florida), they can imprison you indefinitely for not revealing your password. The justification used is that the password itse…

Do you have a federal court decision to cite? Your other comments pointed to two state court decisions (FL and VA).

Re: I recommend against using biometric identification

#75

I would personally like to have groups of things that can be unlocked - that I can define - Nothing - essential what's on lock (weather, maybe news headlines) - Face - basic stuff - games, calculator, News apps - Fingerprint - mail, calendar, text message, browser - Pass code - banking, settings A one all seems backward - there are something things I don't want to protect at all (don't care if someone can access) on…

I figured granular security has more of an enterprise appeal than consumer, and I still don't really see it.

Email, for example. Day-to-day our normal authentication should cover what's in my inbox and/or the last few months of messages. A "deep dive" of emails from 10 years ago should probably have a second level of authentication. You don't access them that often. Yet, once your compromised your whole history of emails can get slurped up very quickly.

I pointed out to my wife not to email anything with our ssn to our tax guy. She kind of balked, but I pointed out if in 10 years he's compromised it's probably still in his email and trivial to scan for ssn or tax documents.

It's been years, but I was at a company that switched to an auto-delete policy after 90 days or something. I thought it was compliance related, but I also think they encouraged you to store important messages in a local inbox which would seem to contradict that.

Re: I recommend against using biometric identification

#76
post #67
post #65

Earlier quoted context omitted.

Android has pretty good profile support, I have my own profile, a guest one which is wiped when you logout, and one for my kids which can't buy things. Works pretty well for me, there's a little profile icon in quick settings to switch

Nice! That must be a new feature? It had no such thing, the last time I used Android. Err... I use a Windows phone, even though I'm normally a Linux user. I kinda like it.

It is present on my Nexus 5 running 6.0.1, and absent on my HTC One A9, running 7.0.

I suspect that it's a feature dropped from many/most customized versions of Android.

Re: I recommend against using biometric identification

#77

Earlier quoted context omitted.

Biometric data is not a username. Biometric data is also not a password. Biometrics is biometrics. I like to think of it sitting between a continuum between "username" and "password". I might like a setting to require both a Touch ID (or Face ID) and a passphrase to unlock my iPhone. However, Touch ID has flaked out enough times for me (not accepting my fingerprints) that I probably wouldn't like to risk it in practi…

Biometrics is closer to a username.

Where would Genital ID fall on your continuum?

Re: I recommend against using biometric identification

#78
post #63
post #49

Earlier quoted context omitted.

If you have email set up on your phone and someone steals your phone without a passcode it’s pretty much game over for all your online accounts. Also defeats two factor auth in case you have that on your phone. Also a lot of services let you reset your password via SMS etc.

For SMS all you have to do is put the SIM card in a different phone, locking your phone does not help. The only accounts you can change the password with a simple email are low security accounts without much of worth to steal. I'm sure there are people with more stringent security needs, but most people just need to deter casual snooping and don't need to stop hackers. I personally do not like having the same securit…

You can set a separate pin code on the SIM and if everything works as designed, the SIM should be useless without the PIN after losing power.

Re: I recommend against using biometric identification

#79
post #74
post #56

Earlier quoted context omitted.

> Much the same, they can force you to reveal your fingerprint, but cannot compel you to share a password. Unfortunately this is dependent on your jurisdiction. In Virginia it's been ruled that law enforcement can't force a password out of you, but in federal court and in other jurisdictions (Florida), they can imprison you indefinitely for not revealing your password. The justification used is that the password itse…

Do you have a federal court decision to cite? Your other comments pointed to two state court decisions (FL and VA).

https://arstechnica.com/tech-policy/2017/09/judge-wont-relea...

Re: I recommend against using biometric identification

#80
post #50

Earlier quoted context omitted.

Ehh... it's not the same as a username. It's more like fingerprints are door locks. Any determined thief can get around it. But it protects you from people who aren't really all that determined. And for most people door locks are sufficient. But if you are a major crime lord, protecting something extremely valuable, or just really into security then door locks are not enough.

The "door lock" analogy ignores the biggest flaw with fingerprints: they're forever. If your door lock is compromised, you can change the key. If someone steals your password, you can change the password. If someone steals your fingerprint, you can never change your fingerprint (same with your face). The other stuff is dead-on: its a "good enough" security measure for phones. But as a security practitioner, the bigge…

https://www.xkcd.com/538/ applies.

Neither Touch ID nor passwords keep determined intruders out. If someone really wants to know what's on your phone, they will arrest/kidnap you and threaten you with prison/violence.

Post reply on HN