Live data from Hacker News

I recommend against using biometric identification

medium.freecodecamp.org

91–100 of 239 posts

Re: I recommend against using biometric identification

#91

>And if you want really go all out, most phones — including iPhone — support 5 or even 6 digit passcodes. iphone supports arbitrary-length alphanumeric passwords.

If memory serves, you can actually set a longer numeric PIN and it will still give you the number pad for longer, but quick to enter passwords. Alphanumeric are obviously more secure but noticeably slower to enter and IMO it's nice there's a middle ground.

Re: I recommend against using biometric identification

#92
post #84

Never? If Jason Bourne is after you that's probably true. If you're worried about border security, that's maybe true. But for most people, the lock on their phone isn't protecting them from the government, it's protecting them from nosy relatives, a pick pocket, or the guy that finds the phone you left at the bar, or their 4 year old. None of these 'attackers' will ever be sophisticated enough to defeat the biometric…

"sophisticated" here could be as simple as buying a mass-produced 3d filter sized for the dual lens on the iPhone, installing a companion computer program, running it, uploading a video, and then pointing the phone at the screen. If I were your nosy relative, that certainly wouldn't stop me.

As with any security break, the first research prototypes may sound sophisticated, but they might not be that far off from practical mass-production.

Re: I recommend against using biometric identification

#95
post #50

Earlier quoted context omitted.

Ehh... it's not the same as a username. It's more like fingerprints are door locks. Any determined thief can get around it. But it protects you from people who aren't really all that determined. And for most people door locks are sufficient. But if you are a major crime lord, protecting something extremely valuable, or just really into security then door locks are not enough.

The "door lock" analogy ignores the biggest flaw with fingerprints: they're forever. If your door lock is compromised, you can change the key. If someone steals your password, you can change the password. If someone steals your fingerprint, you can never change your fingerprint (same with your face). The other stuff is dead-on: its a "good enough" security measure for phones. But as a security practitioner, the bigge…

>If someone steals your fingerprint, you can never change your fingerprint (same with your face).

Because you expect repeated attacks from the person who stole your fingerprints? Who are you, James Bond?

Re: I recommend against using biometric identification

#96
post #84

Never? If Jason Bourne is after you that's probably true. If you're worried about border security, that's maybe true. But for most people, the lock on their phone isn't protecting them from the government, it's protecting them from nosy relatives, a pick pocket, or the guy that finds the phone you left at the bar, or their 4 year old. None of these 'attackers' will ever be sophisticated enough to defeat the biometric…

> I think people need to adjust their security policies to reflect the actual security threats they're likely to face, and for most people Touch ID or FaceID are more than adequate.

Sounds like you work for Equifax. (=

Look, real security threats are out there -- even if you don't want to acknowledge them. Phones have too much sensitive data, photos, bank accounts -- now the ability to pay via text message. It's just short-sighted to think the only threats people should be worried about are their kids or neighbours.

Re: I recommend against using biometric identification

#97
post #58

I would personally like to have groups of things that can be unlocked - that I can define - Nothing - essential what's on lock (weather, maybe news headlines) - Face - basic stuff - games, calculator, News apps - Fingerprint - mail, calendar, text message, browser - Pass code - banking, settings A one all seems backward - there are something things I don't want to protect at all (don't care if someone can access) on…

I am not sure why phones haven't been made with different profiles. Yesterday (?), someone here mentioned they wanted to be able to give the (presumed) cops a phone that was blank. I pointed out that was a horrible idea, but didn't really explain why. If it is a totalitarian regime, they'll just kill you. If you're ever really in such a situation, a blank phone is probably the worst thing you can give them. Instead,…

>I am not sure why phones haven't been made with different profiles.

Because they're personal devices. And even if they had, 99% of the population wouldn't even know how to begin using them (like they don't have an extra profile on their laptop).

At most phones could use an easy "don't let the person I gave my phone to check some pic see my dick-picks" mode or similar.

Re: I recommend against using biometric identification

#99
post #88

Earlier quoted context omitted.

https://www.xkcd.com/538/ applies. Neither Touch ID nor passwords keep determined intruders out. If someone really wants to know what's on your phone, they will arrest/kidnap you and threaten you with prison/violence.

No security is going to keep "determined" intruders out. But the point is that you should still strive to achieve "good enough" security. The problem is that while the actual ranking from least secure to most secure is "nothing < touchid/faceid < passcode", Apple's marketing and implementation gives people the false impression that its "nothing < passcode < touchid/faceid", which is bad for security.

I think "nothing So Touch/FaceID isn't better than a good passcode, but maybe it's better than a crappy passcode.

Re: I recommend against using biometric identification

#100

Just Realized : Face recognition unlock : Biggest Security Scare - Case 1 : Imagine crossing security check or border crossing. Guards just take your phone and point it to you : UNLOCKED . No need to resis to give passwd - Case 2 : drug the activist and point unconscious victim ! Voila ! - Case 3 : Steal the phone, and change the cover and flash it in front of the real owner ! could go on and on ...

Case 1 and 2 are covered with FaceID - you have to be actively looking at the phone, drugged/eyes closed/looking away/etc. won't cut it.

Case 1: "Look at the phone straight-ahead with your eyes or we'll beat you with the rubber-hose again"

Case 2: Hold open the eyelids with tape. Even if the eyes have rolled-back in their sockets they can be re-positioned with some manual adjustment enough to get the system to work.

Post reply on HN