Live data from Hacker News

Face ID, Touch ID, No ID, PINs and Pragmatic Security

troyhunt.com

71–80 of 314 posts

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#74

Earlier quoted context omitted.

But wht was wrong with TouchID ? Were there any examples of it being weak security. What will be after Touch ID? Will Apple continue progress and built in PinchID - a tiny needle that sting you to test if you are you based on your blood/DNA? This is a serious question. Because of there was noting wrong with Touch then why is it removed from new phone and replaced with Face ID. Im also concerned about the data Apple w…

TouchID was removed because it took up space on the front of the phone and Apple wanted the screen to be bigger. There's no deeper reason than that. > Will Apple continue progress and built in PinchID - a tiny needle that sting you to test if you are you based on your blood/DNA? I struggle to believe you when you say that's a serious question... > Im also concerned about the data Apple will collect. The FaceID data w…

> TouchID was removed because it took up space on the front of the phone and Apple wanted the screen to be bigger. There's no deeper reason than that.

The Pixel handset has the fingerprint sensor on the back of the phone. It appears to work quite well. Much of this needless outrage could be obviated by allowing multiple simultaneous biometrics for auth; while taking the phone out of your pocket, place your finger on the sensor to initiate FaceID.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#75

Nice article. However: > It's alarming not just because the number is so low, but because Dropbox holds such valuable information for so many people. I'd suggest that Dropbox users somewhat self select for those not as concerned about security as others. And more concerned about availability. Dropbox does not encrypt your data server side (or at the very least, can easily decrypt it). And they have proponents of warr…

Confidentiality, Integrity and Availability (CIA). Those are all part of information security.

This is actually quite interesting, since it is a bit like CAP theorem. When you increase confidentiality and integrity, you might be affecting availability in a negative way. Take Dropbox as an example. Since they don't have efficient end-to-end encryption offering, they can offer you password resets (=availability of data is good). Add in secure end-to-end encryption and password resets won't be enough, you need to have in addition good backups for the encryption keys to ensure access to the data.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#76
post #32

It would be interesting if we could specify a particular face pattern to unlock the phone. Imagine you set up your phone to open only if you smile, now if someone picks up your phone and try to unlock it by pointing it at your face, not smiling would be easier than closing your eyes or looking away. Not even mentioning the health benefit of just smiling :)

It would be awkward to smile/pose before/after a funeral, just because I need to call my mum or check my email...

That being said, I do think that there could be a legitimate use case here. One could set up a particular "emotion" (a face pattern) associated with someone forcing them to unlock a phone using their face. I mean, if someone pulls a gun or a knife on me, I'll probably just do as they say and look at the phone, rather than risk an additional hole in my body. But unlocking a phone and sending a distress call is something I could live with.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#77
post #73

you can change your pin. you can't change your face.

Which is why it's nice that none of the biometric auths can be used without also having a PIN for backup auth. And also why it's nice that you can disable biometrics entirely.

The comment was aimed at the Snowden example. If Snowden thought his pin was compromised he could always change his pin, but once his face is compromised what does he doe?

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#78
post #32

It would be interesting if we could specify a particular face pattern to unlock the phone. Imagine you set up your phone to open only if you smile, now if someone picks up your phone and try to unlock it by pointing it at your face, not smiling would be easier than closing your eyes or looking away. Not even mentioning the health benefit of just smiling :)

I seem to recall a video-based one that did something like this - it would tell you to make a specific facial posture to unlock the device, maybe Google's?

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#79
post #70

For me it's a simple question of cost vs. reward: do I care enough about the security of whatever data is stored with a company, that I'm willing to give the company personal information, when their terms of service almost assuredly give them complete license with it? This, of course, starts with the question: do I even want to put this in the cloud to begin with? Edit: I was talking about two factor auth.

From the OP: "the data is stored in the iPhone's secure enclave and never leaves the device" . It appears that this has nothing at all to do with the cloud. And if you don't trust Apple's word here, then you also have no reason to trust that they (or any other handset maker) haven't programmed the camera to surreptitiously take and transmit photos at all times.

I'm talking about two factor auth.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#80
post #46

Nice article. However: > It's alarming not just because the number is so low, but because Dropbox holds such valuable information for so many people. I'd suggest that Dropbox users somewhat self select for those not as concerned about security as others. And more concerned about availability. Dropbox does not encrypt your data server side (or at the very least, can easily decrypt it). And they have proponents of warr…

My problem with dropbox alternatives is that they are either far more expensive or don't run on linux (with syncing).

https://spideroak.com/one/ runs on Linux. I have not checked how it compares to DropBox pricing wise, but ticks all my security/privacy boxes
Post reply on HN