5 ms·
I don't understand why what's essentially a login (fingerprint, face, dna) is considered a password. It simply isnt. And I don't understand why I cant (on And
by thresh 9y ago
I don't understand why what's essentially a login (fingerprint, face, dna) is considered a password. It simply isnt.
And I don't understand why I cant (on Android 7) combine fingerprint and then PIN/Pattern to unlock my device. It's mind boggling and completely stupid.
- metafunctor 9y agoBiometric data is not a username. Biometric data is also not a password. Biometrics is biometrics. I like to think of it sitting between a continuum between "username" and "password". I might like a setting to require both a Touch ID (or Face ID) and a passphrase to unlock my iPhone. However, Touch ID has flaked out enough times for me (not accepting my fingerprints) that I probably wouldn't like to risk it in practice.
- sperling75 9y agoBiometrics is closer to a username.
- lolsal 9y agoWhy? I am not terribly upset if someone has my username, but I would be very concerned if they had reproducible biometrics of mine (fingerprints, facial, etc).
- lugg 9y agoBecause biometrics are usually relatively publicly accessible information. Passwords aren't. You're arguing reproducibility. Well, your face can be replicated by a picture you put on Facebook, fingerprints are left everywhere you go.
- SAI_Peregrinus 9y agoUsernames are fixed values and are generally public. Biometrics are also fixed values and are generally only slightly less public. They're both identifiers. Passwords can be changed and are secrets. They're authenticators. The difference between them is exactly the difference between identifiers and authenticators. Misunderstanding this difference causes tons of issues, in a wide variety of situations. The most notable one recently is probably Social Security Numbers being used as both, which leads to identity theft.
- skygazer 9y agoWhere would Genital ID fall on your continuum?
- skygazer 9y agoPerhaps I was too flippant. Point being, the “public availability/replicability” of the biometric would seem correlated to the point on the username->password continuum. This will probably matter less once our future devices can interact with our sci-fi personal nanites, or rfid implants in the meantime.
- tonyztan 9y ago> And I don't understand why I cant (on Android 7) combine fingerprint and then PIN/Pattern to unlock my device. It's mind boggling and completely stupid. This. I've been looking for a way to have two factor unlock (Fingerprint + PIN) for a long time.
- thatswrong0 9y agoThe 99% use case for having to unlock a phone with TouchID / FaceID / 4 digit passcode is to prevent people from snooping on your phone (think children, coworkers, strangers, thiefs) within a relatively short period of time. If your phone is stolen, for example, you'll probably contact Apple and remotely disable it within a day, probably sooner. I don't think TouchID / FaceID / 4 digits are intended for the 1% use case: preventing malicious actors with long term access to the phone from getting in (think police, government agents, etc.). As a result, most people I see have 4 digit codes on their phones, without the "10 wrong passwords erases all phone data" option enabled. That alone is probably more insecure than FaceID / TouchID over the short term. Sure, a 3D map of your face or your fingerprint is not a true password.. but for this use case, they're a perfectly fine substitute while being more convenient. If you want long term protection, then you should use an alphanumeric password for your phone with the "10 wrong passwords" option enabled. But most people don't want or need that.