Earlier quoted context omitted.
I don't think you can call something a cute feature when it's turned on on most phones and is used to unlock them. I would guess that by far the majority of iPhone 5S's have TouchID enabled. I wouldn't be surprised if it's more than 90%. The feature is just that well executed.
I would be very surprised if it is that high now even with the early adopter skew. Reports say that last year it was around a quarter of smartphone users use passcode locks on their work phone ( http://www.welivesecurity.com/2012/02/28/sizing-up-the-byod-... ). I imagine 5S rates are higher than that, but 90% would be insanely impressive. When it comes to computer security, as usual, people's apathy is the biggest pr…
Fingerprints are Usernames, not Passwords
71–80 of 261 posts
Re: Fingerprints are Usernames, not Passwords
#72Earlier quoted context omitted.
You are just repeating a dogma, not explaining why it is not good to think of a fingerprint as a username.
It's not a username. It's a fingerprint. Usernames are how we indicate an identity to a computer. (Note "an" identity; identities do not one-to-one map to humans.) Identity is what we are trying to establish in the first place; if we simply knew you were authorized to use an identity we wouldn't need auth in the first place. Having a matching fingerprint is evidence that an authorized user is authorized to use that i…
Considering that you leave your fingerprint everywhere you touch with your bare hands, is that really true?
Re: Fingerprints are Usernames, not Passwords
#73Re: Fingerprints are Usernames, not Passwords
#74All these academic arguments about the security of fingerprints are interesting but completely are detached from the day-to-day use of TouchID. I've been using it for about a week or so now. It's incredibly convenient. It unlocks my phone almost instantly. It prevents random people near by phone from being unable to unlock it. If a thief got their hands on it, they'd have a few attempts to unlock it with a fake finge…
s/TouchID/Face Unlock/g and back up about 2 years and you can find all the same things said about Ice Cream Sandwich. It's a cute feature. It's not going to change the world, sell another billion phones, push other companies out of the market, or save anyone from serious attacks. It's probably a good idea to enable it anyway.
Re: Fingerprints are Usernames, not Passwords
#75Earlier quoted context omitted.
Depends on scenario. If you steal a phone from a bag on the subway, you'll never be able to get that photo but can probably lift the print right off the phone itself. So maybe iOS has better-yet-still-mediocre protection against snooping yet inferiorly-mediocre guards against identity theft. Yawn. In neither case is the phone meaningfully protected against serious attack. Why must we have this argument? It's a cute f…
but can probably lift the print right off the phone itself That doesn't seem to be the case to my knowledge. The evidence from the successful attack is that you need an excellent-quality print from one of the specific fingers that has been programmed into the phone. Some phones probably have that on them, but it appears likely that many do not.
edit: build an app, get your colleague, significant other etc touch it on any touchscreen phone or get on camera and create a 3d printed finger. 3d printing vs touchid...maybe
Re: Fingerprints are Usernames, not Passwords
#76I'll be interested when someone breaks Touch ID in a real life theft. This is not a simple process, it's not clear that a determined thief is even likely to find a good enough print in a real life case, and you can't mess around because after 5 failed attempts it will prompt for a password. Touch ID will likely cover the vast majority of security use cases for iPhone owners.
I saw the CCC video and I think you are right, a suitable print being found on the phone is a bit slim, although not impossible. However, I think the point of the article is that you can change a compromised password, you can't change a compromised fingerprint. As is mentioned, there are plenty of databases with fingerprint information. Also, for the crowd that is paranoid about government accessing their data, an au…
Re: Fingerprints are Usernames, not Passwords
#77Fundamentally, a username and password are parts of the same thing - a collection of information (often a string of text) that you need to get access to something. The 'username' is usually just the part of that isn't necessarily hidden. Part of the problem is that Apple's iOS has no username, just a password. Thus, one of the differences with a fingerprint 'password' that I haven't seen much discussed is that it wou…
Re: Fingerprints are Usernames, not Passwords
#78Earlier quoted context omitted.
It is more difficult to defeat a touch sensor than face unlock. With face unlock, I just need a photo of the phone's owner. With a fingerprint unlock, I need to go to at least a little trouble to fake the fingerprint.
Depends on scenario. If you steal a phone from a bag on the subway, you'll never be able to get that photo but can probably lift the print right off the phone itself. So maybe iOS has better-yet-still-mediocre protection against snooping yet inferiorly-mediocre guards against identity theft. Yawn. In neither case is the phone meaningfully protected against serious attack. Why must we have this argument? It's a cute f…
Re: Fingerprints are Usernames, not Passwords
#79- A username is something you know.
- A password is something you know.
- A pinpad is something you have.
- A finger print is something you have.
Re: Fingerprints are Usernames, not Passwords
#80Earlier quoted context omitted.
It is more difficult to defeat a touch sensor than face unlock. With face unlock, I just need a photo of the phone's owner. With a fingerprint unlock, I need to go to at least a little trouble to fake the fingerprint.
>I just need a photo of the phone's owner. As they said when they unveiled the feature and people mentioned this: give them a little credit.
http://www.soyacincau.com/2011/11/12/clarification-on-the-ic...