15 ms·
Fingerprints are not passwords, but I don't think it's useful to think of them as usernames either. This is a much more pragmatic take on it by Troy Hunt, the
by paulannesley 9y ago
Fingerprints are not passwords, but I don't think it's useful to think of them as usernames either.
This is a much more pragmatic take on it by Troy Hunt, the person behind “Have I been pwned?”: https://www.troyhunt.com/face-id-touch-id-pins-no-id-and-pragmatic-security/ https://www.troyhunt.com/face-id-touch-id-pins-no-id-and-pra...
> The first point I'll make here as I begin talking about the 3 main security constructs available is that they're all differently secure.
- rothbardrand 9y agoFingerprints are better passwords than no password. And the hassle of entering even a 4 digit numeric PIN was what Apple was trying to overcome. Too many people were leaving their phones completely unlocked all the time.
- reificator 9y agoIt's irrational, but I'm not going to use a security measure that increases the likelihood a malicious actor removes my finger.
- kibwen 9y ago1. Then you have the option not to use it, and always will (biometrics are used to augment passwords, not replace them). 2. Using passwords as a security measure increases the likelihood that a malicious actor will beat them out of you with a five-dollar wrench (and this does not mean that passwords are a bad idea).
- deleted 9y ago[deleted]
- kobeya 9y agoThe iPhone has a liveness test as part of its biometric.
- bdibs 9y agoI wonder if the finger cutter knows that...
- Majestic121 9y agoMaybe the first one won't, but the next time they most definitely will. Stealing a phone is one thing, cutting someone's finger is another risk-wise. So if you have to dramatically increase the potential penalty for getting caught, you'll make sure it actually works before doing it repeatedly, and this kind of info is shared among thugs
- valuearb 9y agoIf someone is willing to cut off your finger to access your device, that means they have access to you and the device and the means to convince you to unlock it. Cutting off someones finger to access their phone is like using high explosives to blow up a door you can easily kick open. Criminals actually don't want to get caught.
- Twisell 9y agoSeriously the amount of fingers cutted since the introduction of iPhone 5s amount certainly to zero or we would have heard the information buzzing around on all cheap news networks almost immediately. So I'm pretty confident now that this argument is moot by now. Yet we still don't have enough mileage to determine if face peeling will be a more likely issue with iPhoneX. But I could bet that "face offing" relatively is not more likely than finger cutting...
- TwoBit 9y agoIf a malicious actor will cut off your finger, he'll also put a gun to your head and demand the password... which you will no doubt give him.
- bighi 9y agoAnd it's much easier to point a gun and demand the password. The psychological detachment required to cut off a finger significantly lowers the number of criminals that will unlock your phone against your will.
- Spooky23 9y agoI have some important stuff on my phone, but not important enough to give up a finger. When the bolt cutters come out they are in. Sue me.
- ballenf 9y agoThey are as much a password as the key to your house is a password. And agree that Troy's description is best as it takes us away from unhelpful metaphors.
- ben-schaaf 9y agoI don't leave an impression of my keys on everything that I touch.
- nomel 9y agoIf your fingerprint scanner is based on simple ridge profiles, then it's shouldn't be used for security. For example, some recent Apple keynotes claim they now use sub-dermal features for identification. Implementation matters more than what the sensor is authing with.
- Elvewyn 9y agoWhat if we did something like a mix of password + finger print, by using multiple fingers in a pattern? Like, say, middle - index - ring. It would be doubly unique.
- maoej 9y agoIt would be more unique but it would take away the convenience of having your phone unlocked nearly instantly with your finger. If you're going by security, a password plus fingerprint would be most secure but inconvenient.
- foo101 9y agoIf you believe your key has been compromised (say duplicated), you can change the lock and your key. If you believe your fingerprint data has been compromised, can you change your fingerprint data?
- seandougall 9y agoAs far as your phone is concerned, yes. Nine times, for most people.
- TwoBit 9y agoOnly 1% of Dropbox users have two-factor auth enabled. But probably only 10% of Dropbox users care about the security of their files. I don't.
- techno_modus 9y agousername • password public • private detachable • non-detachable unique • arbitrary A name has to be unique. But it can simultaneously be used as a password if it is impossible to detach (copy) it and associate with another thing. One way to do it is to simply hide it like private keys and normal passwords but in this case it cannot be used as a name. An alternative approach is to make it difficult to copy/reproduce (similar to normal car or house keys). In the case of fingerprints, they can well be used as a password (in addition to its role as a name) until it is impossible to create artificial fingers and attach them to other persons.
- Phemist 9y agoFingerprints are not private though, so they fail your very first criterium of passwords. Fingerprints are also not arbitrary[1], it is possible to combine two (or more) fingerprints resulting in a new "fingerprint" in its own right, as well as being a fingerprint that is similar enough to the two (or more) original fingerprint to have a high chance of fooling most sensors on smart phones for all fingerprints involved. Also, uniqueness vs. arbitrariness smells like a false dichotomy to me. Something can be both arbitrary and unique (see for example uuids). [1] - https://www.nytimes.com/2017/04/10/technology/fingerprint-security-smartphones-apple-google-samsung.html https://www.nytimes.com/2017/04/10/technology/fingerprint-se...