7 ms·
The "door lock" analogy ignores the biggest flaw with fingerprints: they're forever. If your door lock is compromised, you can change the key. If someone steal
by bodz 9y ago
The "door lock" analogy ignores the biggest flaw with fingerprints: they're forever.
If your door lock is compromised, you can change the key. If someone steals your password, you can change the password. If someone steals your fingerprint, you can never change your fingerprint (same with your face).
The other stuff is dead-on: its a "good enough" security measure for phones. But as a security practitioner, the biggest problem IMO is that Apple using TouchID and FaceID is giving the general public the wrong idea about security. Apple claims that these innovations are "cutting edge" security, and so consumers buy into this and then also use fingerprints to secure things like their bank accounts, work logins, password vaults (this is a big one - someone steals your phone and you use your fingerprint to access your LastPass account, which has all of your passwords in it? And your phone is also your 2FA device? You're screwed.) etc, where they really aren't "good enough" at all.
I've worked at companies where we disabled fingerprint logins on certain devices because highly sensitive info is held on those devices, and fingerprints just aren't secure enough to protect them. Then we get yelled at by people from the company because "Apple says fingerprints are the best for security, why aren't you letting us use them?" It's a pain.
- ethnic_throw 9y agoActually fingerprints are relatively easy, if painful, to change. Your point stands, of course.
- namelost 9y agohttps://www.xkcd.com/538/ https://www.xkcd.com/538/ applies. Neither Touch ID nor passwords keep determined intruders out. If someone really wants to know what's on your phone, they will arrest/kidnap you and threaten you with prison/violence.
- bodz 9y agoNo security is going to keep "determined" intruders out. But the point is that you should still strive to achieve "good enough" security. The problem is that while the actual ranking from least secure to most secure is "nothing < touchid/faceid < passcode", Apple's marketing and implementation gives people the false impression that its "nothing < passcode < touchid/faceid", which is bad for security.
- panopticon 9y agoI think "nothing < passcode < touchid/faceid" might be true for a startling number of people. I've seen many people with ridiculously easy passcodes and even funnier Android patterns (e.g., one of my colleagues uses his first initial as his Android unlock pattern, and my mom uses her dog's name as her passcode). So Touch/FaceID isn't better than a good passcode, but maybe it's better than a crappy passcode.
- BenjiWiebe 9y agoI could be wrong, but doesn't a passcode actually encrypt the data (for sure on password manager/banking/etc apps) whereas FaceID/TouchID/<insert biometric here> doesn't? And what about hashing? AFAIK you can't really hash biometrics.
- colejohnson66 9y agoWith Touch ID and Face ID, you are required to have a passcode. What's the point of Touch ID if it fails and doesn't have any other way into the phone? As for hashing biometrics, Apple has the Secure Enclave which is for storing the biometrics.
- bigiain 9y agoAnd TouchID/FaceID that people use is way better than passcodes they do not because they're a pain in the arse. I noticed a distinct improvement in the speed of the TouchID unlock going from an iPhone 6 to a 7, which pretty much reduced all friction to me using it. Apple's marketing fluff suggests FaceID will be "twice as fast" as TouchID.
- dvhh 9y agoIsn't there a danger of providing 10 wrong passwords and thus trigger the data deletion builtin ?
- coldtea 9y ago>If someone steals your fingerprint, you can never change your fingerprint (same with your face). Because you expect repeated attacks from the person who stole your fingerprints? Who are you, James Bond?
- booleandilemma 9y agoIt doesn't have to be a repeated attack from the same attacker. Imagine your fingerprint data is leaked to hundreds of hackers.
- coldtea 9y agoAnd many of those hackers (or even one of them) care enough to (a) steal your phone, (b) fake your fingerprints with a cast or whatever? Yeah, I'll risk it...
- bodz 9y agoThe OPM hack resulted in millions of people's fingerprints and names being hacked, and now are floating out on the internet for anyone to look up. Individuals who had their fingerprints stolen in that hack can now never use fingerprint readers with any reasonable confidence, since now all a hacker has to do is search that person's name and pull their fingerprint from one of aforementioned databases. > fake your fingerprints with a cast Fingerprint scanners like those on phones have been shown to be able to be fooled by using $10 worth of office supplies and some play-dough. It's not like we're talking mastermind levels of intelligence to do this stuff. Of course, all of this completely ignores the fact that your phone likely already has several copies of your fingerprint already on it since you touched it, so it's not like someone hacking your fingerprints is even necessary. That's an entirely different reason of why fingerprint security is abysmal, though.
- coldcode 9y agoPeople keep saying fingerprints are all over the internet but I have seen no actual proof (1) how you can steal an iPhone fingerprint record (2) how you can use this data to generate a fake fingerprint sufficient to open the iPhone or even (3) copy a fingerprint off of the outside of the phone and open the iPhone.
- naravara 9y ago>If someone steals your fingerprint, you can never change your fingerprint (same with your face). At what point is stealing a fingerprint, retina print, or face going to be economical enough for the thief that this would be an actual valid concern in 99% of use cases? Both FaceID and TouchID need to read a living person with a pulse in order to authenticate. You can't just take a printout of a fingerprint and drop it in. This is a really heavy lift to try to jack some random person's phone. Unless you're securing State Secrets or occupy rarefied enough heights that you have a Swiss bank account I don't really see anyone bothering. >and so consumers buy into this and then also use fingerprints to secure things like their bank accounts, work logins, password vaults Which bank accounts are taking fingerprints? Do you mean people's banking apps on their phones? In order to get to that they would need to steal both your phone AND your fingerprint. If a thief is this enterprising your info. is lost anyway. And again, they would need an extremely high fidelity reading of your fingerprint and the ability to reskin a living finger with it. And they would have to execute all this before you get to an Apple Store or a PC to remotely shut it down. >Then we get yelled at by people from the company because "Apple says fingerprints are the best for security, why aren't you letting us use them?" It's a pain. This often happens when someone shoves policy down people's throats without explaining themselves or getting buy-in from their clients. This is a communication skills problem, not an issue with biometrics.
- bodz 9y ago> At what point is stealing a fingerprint, retina print, or face going to be economical enough for the thief that this would be an actual valid concern in 99% of use cases? For the average person who is just securing their phone that only stores pictures of their cat, this isn't a concern, but that's far less than 99%. For pretty much anyone who is logged into their work email/VPN via their phone, or is using fingerprint scanners to secure their work laptop, this is a very real concern that I have seen exploited a few times in the real world. > Both FaceID and TouchID need to read a living person with a pulse in order to authenticate. TBD with FaceID, but with TouchID this isn't the case. You can defeat TouchID with $10 worth of office supplies and some play-dough. > Which bank accounts are taking fingerprints? Do you mean people's banking apps on their phones? In order to get to that they would need to steal both your phone AND your fingerprint. Since your phone literally has your fingerprint left on it from when you touched it, this isn't really a difficult task. And as I mentioned, it's even worse if you're one of the people who uses a password manager on your phone that is also locked with fingerprint. Then, every account you have is now compromised. And even if you're using 2FA, your phone is likely your 2FA device, which the thief also has. > This often happens when someone shoves policy down people's throats without explaining themselves or getting buy-in from their clients. This is a communication skills problem, not an issue with biometrics. No, it is undeniably an issue with biometrics (and the way they're treated). Training and awareness (communications) is one of the primary problems that any security implementation will try to tackle, but it's just made more difficult to do that when Apple is pushing falsehoods like "TouchID is the most secure thing ever!" in all of their marketing materials.
- imron 9y ago> ignores the biggest flaw with fingerprints: they're forever. The second biggest flaw being your phone is covered in your fingerprints!
- otempomores 9y agoThird is that in a woeof hires photography every picture can contain your fingerprints.
- seandougall 9y ago> you can never change your fingerprint Not quite true from the phone's perspective. Most people have nine backups to fall back on if they really need to.
- hvidgaard 9y agoIt's a sad state. I've heard wealthy and influential investors talk about how they don't think real 2FA is worth anything, because they just want to use their finger for everything. No matter how easy or hard it is to steal, the major problem is that you only have 10 fingers. If all of them gets compromised we still need something else.