Live data from Hacker News

Fingerprints Are Usernames, Not Passwords (2013)

blog.dustinkirkland.com

71–80 of 106 posts

Re: Fingerprints Are Usernames, Not Passwords (2013)

#71
post #67

Earlier quoted context omitted.

lol. This is not Hollywood. A phone thief isn't going to be using tape and superglue to find your fingerprint. Do you really want to encourage someone to remove your index finger when they mug you for your phone?

But is there a single piece of evidence for this ever happening outside of Hollywood?

Yes. A man had his finger ripped off by a thief stealing his iPad. It was not for the touch ID, but that is beside the point IMO. There have been plenty of incidents where muggers remove fingers to steal rings. I don't think a phone is so different.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#72
post #64

Something I feel that's always missed in these discussions is context: Who is the adversary you're attempting to protect against? Your kids screwing around with your phone? TouchID does the job. Random people screwing around with your phone if they find it? Same thing. Government gets ahold of it? Yeah.. notsomuch. Considering that the primary adversaries of an average smartphone user are other mere mortals, not dedi…

Still, I'd rather not give hardened criminals a reason to cut off my fingers.

Have there been any reports of this actually happening in the past year?

Re: Fingerprints Are Usernames, Not Passwords (2013)

#73
Everything about this article is well-intentioned — and wrong.

"much as a your email address or username identifies you, perhaps from a list."

Your email address or username may identify you, but it also may not. Your fingerprint absolutely identifies you and only you.

"For authentication, you need a password or passphrase. Something that can be independently chosen"

A password is a secret phrase. We're used to thinking about passwords in terms of strings, but anything secret that I know about would serve the definition. In fact, like a character-based string password, I can even make a copy of my fingerprint password and store it somewhere if I wanted a backup.

A fingerprint is both a username and a password. Trying to hold some analogy between Touch ID and traditional username/password combinations doesn't hold and it completely misses the point of the innovation.

That's why it's convenient, and skepticism of civil liberties aside, convenience means better security because people will use it.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#74
post #64

Something I feel that's always missed in these discussions is context: Who is the adversary you're attempting to protect against? Your kids screwing around with your phone? TouchID does the job. Random people screwing around with your phone if they find it? Same thing. Government gets ahold of it? Yeah.. notsomuch. Considering that the primary adversaries of an average smartphone user are other mere mortals, not dedi…

Still, I'd rather not give hardened criminals a reason to cut off my fingers.

I'd probably just unlock it for them if they had my phone and my person in their possession

Re: Fingerprints Are Usernames, Not Passwords (2013)

#75
post #73

Everything about this article is well-intentioned — and wrong. "much as a your email address or username identifies you, perhaps from a list." Your email address or username may identify you, but it also may not. Your fingerprint absolutely identifies you and only you. "For authentication, you need a password or passphrase. Something that can be independently chosen" A password is a secret phrase. We're used to think…

fingerprints aren't secrets. you leave a copy on everything you touch.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#76
post #46

Earlier quoted context omitted.

I'm sure he -does- think low entropy passwords are bad. However, once compromised, those can be changed. That's the point. (Plus, passwords aren't routinely collected and shared by governmental agencies. Just throwing that out there). As you say, with Apple's TouchID, you are actively choosing a less secure method to access your device, for convenience. But...that's also pretty close to what the author said. "Biometr…

>> "Plus, passwords aren't routinely collected and shared by governmental agencies" Y U no read Greenwald? Not sure if trolling.

It took me a moment to work this out too, but they meant that the police don't ask for your passwords when they arrest you for an unrelated charge; the DMV doesn't ask you for them when you get a drivers license (do US DMVs do that?) etc.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#77
Fingerprints aren't passwords. They also aren't usernames. They're fingerprints, and they have different characteristics from both usernames and passwords.

Rather than try to shoehorn fingerprints into our existing terminology, let's look at what fingerprints can do and what implications they provide, and then use them accordingly. The article sadly fails to do this.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#78
I agree with the below comments. These types of papers are always emphasizing rigor over actual experience.

Many types of "100%" security fail because of this disconnect. Forced rotating passwords or long ones with required symbols and number? Most people choose to have easy to remember ones (e.g. pass1, pass2, pass3,) Or it's so difficult to memorize that they'll write it down somewhere nearby.

The points are important, but they're directed at consumer products. I wonder how the same person would look at bike-locks...which even with the most expensive locks are only a deterrent given the right tools.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#79
post #71

Earlier quoted context omitted.

But is there a single piece of evidence for this ever happening outside of Hollywood?

Yes. A man had his finger ripped off by a thief stealing his iPad. It was not for the touch ID, but that is beside the point IMO. There have been plenty of incidents where muggers remove fingers to steal rings. I don't think a phone is so different.

Having looked up this iPad theft, they didn't rip his finger off - the drawstring of his bag got tightly wrapped around his little finger and the force of their grabbing the bag stripped it. An awful thing to happen, sure, but not at all "had his finger ripped off by a thief" - it was a pure accident.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#80

Something I feel that's always missed in these discussions is context: Who is the adversary you're attempting to protect against? Your kids screwing around with your phone? TouchID does the job. Random people screwing around with your phone if they find it? Same thing. Government gets ahold of it? Yeah.. notsomuch. Considering that the primary adversaries of an average smartphone user are other mere mortals, not dedi…

So this article is a year old, I don't know if Apple has managed to improve things since then. But if it were as easy to get access as the article suggests... I agree you take the right approach by identifying adversaries. And I agree that it's relatively reliable against kids or random people randomly screwing around. And not against governments. But there's a whole bunch in between that. Business competitors? Ex-pa…

I remember reading the original article on cracking Apple's fingerprint ID and the crackers mentioned that, while definitely crackable, it requires a certain level of sophistication and thus they considered the addition very worthwhile as a way to protect against robbing, etc.
Post reply on HN