5 ms·
I really liked this write-up because it focused on the practicality of the various security mechanisms. Most articles I see usually have a blanket statement lik
by sgarg 9y ago
I really liked this write-up because it focused on the practicality of the various security mechanisms. Most articles I see usually have a blanket statement like "All biometric security mechanisms are bad!". I think this article does a good job comparing the various logins and describing the pros and cons for different people. Specifically, I appreciate the author calling out when people bring up the "What if" edge-cases, where the correct response is you likely have much bigger problems at that point than the security level of your phone.
- rothbardrand 9y agoSpecifically, getting more people to have better security on their devices is a very difficult User Experience problem, and Apple's pretty good at solving these kinds of problems. TouchID moved the ball forward quite a bit, and FaceID will probably go even further. Obviously neither provide ultimate security, but Apple is in a strategic advantage since they make the hardware and software to make the barn walls and roof super secure, but it does nothing if the front door is left open.
- mikeash 9y agoBefore TouchID, I set my passcode to 0000 with a four-hour window where I didn't have to reenter it. I only had one set at all because Find My Friends refused to keep me logged in unless I had a passcode set. With TouchID, I have a complex passcode that I have to enter a couple times a week. It's less secure than some hypothetical setup where I have a complex passcode I have to enter every time I unlock the phone, but it's far more secure than what I was actually doing before.
- phire 9y agoMy android phone forces me to re-enter my passcode every 24 hours. I think that strikes a nice security median. If someone does get procession of my phone, I only need to stall for less than 24 hours. The rest of the time, the fingerprint scanner works near perfectly. It's actually faster to use the fingerprint scanner than the standard slide to unlock, which is all I ever had setup on my previous phones.
- dpkonofa 9y agoiOS does the same after 48 hours of not being unlocked or re-authorized. I agree that this seems like a decent security compromise. Anyone with physical access to your phone for more than 48 hours has other vectors to pursue that are far easier than just trying to guess your password.
- ruytlm 9y agoIs this a standard setting that can be managed?
- late2part 9y agoHere's a dumb question I haven not easily found the answer to. Can I configure my iphone to require TouchID, FaceID, and a PIN for each unlock of my phone every time?
- danjoc 9y ago>All biometric security mechanisms are bad They are though, if bad == insecure. Customs can make you unlock with fingerprint or face. If you can't lock yourself out, it's not secure.
- pertymcpert 9y agoCustoms can do that anyway if you have a password.
- Jeremy1026 9y agoConstitutionally, an individual can not be forced to enter a password for law enforcement (including customs agents).
- eanzenberg 9y agoThat's the point, "constitutionally" while they lock you up for hours/days on end to obtain the warrant needed to give up your password unless you are willing to stay locked up.
- colejohnson66 9y agoMany border agents, it seems, have the “if you have nothing to hide” mentality. So if you’re refusing to unlock your phone, clearly you’re hiding something.
- Jeremy1026 9y agoGet that sweet settlement for wrongful imprisonment.
- tastythrowaway 9y agoHow many times has this actually happened though?
- coldtea 9y ago