Live data from Hacker News

Face ID, Touch ID, No ID, PINs and Pragmatic Security

troyhunt.com

91–100 of 314 posts

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#91
post #50

Earlier quoted context omitted.

But wht was wrong with TouchID ? Were there any examples of it being weak security. What will be after Touch ID? Will Apple continue progress and built in PinchID - a tiny needle that sting you to test if you are you based on your blood/DNA? This is a serious question. Because of there was noting wrong with Touch then why is it removed from new phone and replaced with Face ID. Im also concerned about the data Apple w…

TouchID also is problematic if you're wearing gloves, which people who don't live in San Francisco do during non-trivial portions of the year.

Curious how much face one needs to show during winter for FaceID to work.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#92

Earlier quoted context omitted.

For phone-based biometrics, the PIN has always been a backup for the fingerprint/face recognition, because these things aren't 100% reliable. Not even considering any security aspects here, just practicalities, like your hands are dirty or your face isn't being recognised (perhaps you've got bandages on your face or whatever). Having the PIN as a replacement is a good thing in these cases, otherwise you could be lock…

FaceID + shortpin = unlock longpin = unlock

Yes! I'd love this.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#93

Earlier quoted context omitted.

I believe they said 1:50,000 and 1:1,000,000.

https://www.reddit.com/r/answers/comments/1ggc2q/why_do_euro...

He's not correcting the use of a period, he's correcting the numbers themselves. 1:50,000 and 1:1,000,000 vs 1:10,000 and 1:50,000

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#95
post #32

It would be interesting if we could specify a particular face pattern to unlock the phone. Imagine you set up your phone to open only if you smile, now if someone picks up your phone and try to unlock it by pointing it at your face, not smiling would be easier than closing your eyes or looking away. Not even mentioning the health benefit of just smiling :)

It would be awkward to smile/pose before/after a funeral, just because I need to call my mum or check my email... That being said, I do think that there could be a legitimate use case here. One could set up a particular "emotion" (a face pattern) associated with someone forcing them to unlock a phone using their face. I mean, if someone pulls a gun or a knife on me, I'll probably just do as they say and look at the p…

y, if someone has a knife or gun I would just give them what they want and worry about a distress call after you're safe instead of getting fancy trying to activate an 'I'm being mugged' feature.

I think that could be a nice feature but would add stress to the situation when you should just be focussed on staying alive trying to remember how to do that special thing or enter an alternate code.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#96
post #94

Given that the authentication methods are "differently secure," wouldn't it be good if we were offered the option to combine them and require both for unlock? I would love to use Face ID + PIN or Touch ID + PIN for better security.

I've been wondering that too. If possible, it'd be nice to combine username, second-factor, and password, as they all perform different functions that people often ambiguate:

- Your username is who you think you are.

- Your second-factor (faceprint, thumbprint, keyfob) is who you claim to be.

- Your password is your proof.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#97
post #32

It would be interesting if we could specify a particular face pattern to unlock the phone. Imagine you set up your phone to open only if you smile, now if someone picks up your phone and try to unlock it by pointing it at your face, not smiling would be easier than closing your eyes or looking away. Not even mentioning the health benefit of just smiling :)

I'd like to see a duress expression. Spitting your tongue out would disable the face authentication and require a PIN.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#98
post #61
post #50

Earlier quoted context omitted.

TouchID also is problematic if you're wearing gloves, which people who don't live in San Francisco do during non-trivial portions of the year.

Not sure if this applies to Apple's implementation, but my phone fingerprint recognition fails if my finger is wet (sweat, washing hands). I haven't tried training it with a wet fingerprint.

This definitely applies to Apple's implementation. It's infuriatingly sensitive to even damp fingers, in my experience.

Re: Face ID, Touch ID, No ID, PINs and Pragmatic Security

#100
post #50

Earlier quoted context omitted.

But wht was wrong with TouchID ? Were there any examples of it being weak security. What will be after Touch ID? Will Apple continue progress and built in PinchID - a tiny needle that sting you to test if you are you based on your blood/DNA? This is a serious question. Because of there was noting wrong with Touch then why is it removed from new phone and replaced with Face ID. Im also concerned about the data Apple w…

TouchID also is problematic if you're wearing gloves, which people who don't live in San Francisco do during non-trivial portions of the year.

FaceID requires a swipe up too, so it’s no better for gloves.
Post reply on HN