6 ms·
I've never used fingerprint scanners for paranoid reasons as this, so this gives me both some undeserved smugness and renewed paranoia. Are long pins and passw
by Multicomp 7y ago
I've never used fingerprint scanners for paranoid reasons as this, so this gives me both some undeserved smugness and renewed paranoia.
Are long pins and passwords still the most secure way to control access to your phone? Is there U2F for phones as a 2nd factor?
- OJFord 7y agoYou can use NFC or USB Yubikeys etc.
- andimm 7y agoI know Yubkeys can be used as a second factor for apps but can you use them to unlock a phone aswell?
- eumoria 7y agoYubikeys can do FIDO along with storing a static complex password. I know android phones can lock with a password so it seems possible but it would be extremely clunky to have to plug in your key every time you unlock your phone.
- carstenhag 7y agoAlso sorta silly, because you are going to have to carry it with your phone anyway.
- wongarsu 7y agoIn the scenario "I forgot my phone and now it's gone" the Yubikey offers perfect security, because I'm unlikely to loose both my phone and my keyring with my YubiKey (that assessment might not hold for a woman with a handbag). In any targeted attack it's useless.
- tialaramex 7y agoBut if you need the FIDO key to use the phone you actually are likely to lose both at once, surely?
- OJFord 7y agoOnly as likely as you are to lose your phone at the same time as your keys today, which as GP says depends on your habits / how you carry them. It's not perfect, (and my Yubikey doesn't support it so I don't do it) but what is?
- tialaramex 7y ago> Only as likely as you are to lose your phone at the same time as your keys today This makes no sense and I struggle to even comprehend how somebody could come to this conclusion. Before: I take my phone out, I unlock it, I look at something on the phone, then I get distracted, I leave it on a bar, a desk, somebody's refrigerator, wherever. Now: I take my phone out. I need the FIDO key to unlock it, so I get that out too, I unlock the phone, I look at something on the phone, and then I get distracted and this time leave both the FIDO key and the phone in the same exact place, because of course I do I was using them both when I was distracted. Can at least one of the people who seems so sure that somehow this wouldn't alter how often they lose the two items they now need together explain their thinking? Do you just... lose things randomly like maybe you have a gaping hole in your pocket and things fall out but you've never bothered to repair it? How are you losing things so that it somehow doesn't matter whether they're used together?
- OJFord 7y ago> Now: I take my phone out. I need the FIDO key to unlock it, so I get that out too, I unlock the phone, I look at something on the phone, and then I get distracted and this time leave both the FIDO key and the phone in the same exact place, because of course I do I was using them both when I was distracted. If I had an NFC one what I imagine doing is just pulling my phone out of one pocket and tapping it against the other, where my keys are. I suppose if I was going to plug it in I could do that today (albeit with a USB-C adapter) but I don't because, the security point you mention aside, it's a usability nightmare (even if I didn't need an adapter).
- DCKing 7y agoLong pins and passwords make you a lot more susceptible to casual attackers, as they can be gotten from shoulder surfing and casual video, like e.g. surveillance footage. Fingerprint replicas (or your actual fingers) are obtainable by targeted attackers of some sophistication. But if you're targeted by attackers willing to go that length for you, you have other problems. IMO, fingerprints provide the best practical security.
- benj111 7y agoUltimately its a device you're carrying around with you, if someone wants access they're probably going to get it, all you're aiming to stop is chance opportunists. Pin, fingerprint reader (that works) is enough. Btw, I don't think 'casual attackers' really fits with access to, and willingness to go through cctv.
- dillonmckay 7y agoOnly one of those can unlock your phone while you are unconscious, or with a body part that has been removed.
- smcl 7y agoThose would be the "attackers willing to go that length" the person was referring to. If these are the adversaries you want to defend against, your solution is even simpler - don't store such secrets on your phone. Also maybe hire a bodyguard.
- scarface74 7y agoIf those are your adversaries, they are going to use rubber hose decryption.
- mikestew 7y agoIs that more of a day-to-day problem for you than shoulder surfing? I ask because I used to have a drinking problem, too.
- 7y ago
- jcadam 7y agoI don't use fingerprint readers because they don't freaking work for me.
- isodude 7y agoThe best is to have a secret phone like secure folder or private space. Thus you are protected even if someone makes you unlock the phone.
- Lucadg 7y agoCould you elaborate?
- ivix 7y agoSamsung Knox for example. Defence in depth.
- isodude 7y agoHuawei Private Space Use another password to unlock the private space. Samsung Knox (secure folder) App hidden as a normal app (can be renamed as something completely normal) Both have separated contacts / app store etc and are separated with support from the hardware.
- HeWhoLurksLate 7y agoLike a full second phone? Easily noticeable via Wireshark. Like a folder? Probably noticeable with a utility like WinDirStat. Like a separate user? Can the other one install apps? If so, you're likely done for if someone gets access to the one account. Also there's this [1] to consider, as well. I hate shooting privacy ideas down. Unfortunately, that's all I have to contribute this time. [1] https://xkcd.com/1200/ https://xkcd.com/1200/
- isodude 7y agoWell depends I guess. After using it I like the idea with Huawei Private Space. You need to unlock the phone with a different biometric/password to get notifications even. So separate storage / user / app store. Samsung Knox is a bit more seamless, you can choose how much you share (like copy & paste). In case you are made to do it both can fool goverment to accept that you phone is clean with the correct setup.
- wjoe 7y agoFingerprints were never supposed to replace passwords, they're more analogous to usernames. I like fingerprint scanner as a quick way to unlock my phone, it's at least more secure than the 4 digit passcodes or patterns I used before that, and more convenient than that or face recognition. But I wouldn't want to use fingerprint to replace entering a password for making payments or accessing any secure data.
- dsr_ 7y agoVehemently agreeing with you. Fingerprints are identification, not authentication or authorization.
- sokoloff 7y agoGenuine question: in what way are fingerprints not authentication? (to a ~1:500K uncertainty)
- consp 7y agoA few issues: First of all because they cannot be revoked. Unless you count cutting tools and torches. Just as well as they can be easily used without the user's consent (e.g. sleeping) without them being aware of it. Note: this does not require stealing anything as in the passphrase case. Additional problems are the high false positive rate. They just identify the user, not an action of authentication/authorization; i.e. a mental action like remembering a password and actively approving something. See it this way: Your bank card identifies you, you pin number authorizes the payment. These are distinct differences. If you ignore authorization you get nfc payments which are very convenient but far less secure and easier to manipulate. Note: your pin can be revoked, your fingerprint can't.
- tialaramex 7y agoU2F doesn't feel like a natural fit for securing a phone because the core "factor" in U2F is "Something you have" and well, you "have" the phone too already. The fingerprints are "Something you are" but as we see _implementation_ may be lacking. So as you realise that leaves requiring a passphrase, "Something you know". It's awkward, but I think if you care about security that's still really the most practical solid option. Fingerprints were only ever "better than nothing" here and should not have been sold as more than that (Biometrics _can_ be very secure but they need human supervision, e.g. when police take a DNA sample you can't give them somebody else's DNA but nobody is supervising you when you press what may or may not be your actual finger up against the sensor on a stolen phone). I have a passphrase and a relatively short screen timeout for my phone, it certainly is less convenient than most people's zero authentication strategy, I noticed this when my closest place to buy groceries announced I could use the phone instead of needing a cashier. For a regular person you just wander around, bagging anything you want and scanning it with the phone, then obviously you pay at the end. But for any time I spent more than 30 seconds or so browsing the phone locked and I needed to re-enter my passphrase to scan an item, cumbersome. There are tweaks I could do to let the scanning app stay active when the screen locks, but ultimately I just won't bother, there are hand scanners for people who don't have a phone or don't want to use it like me. I'll only use the phone if I pop in to get a single item so that unlocking the phone is faster than swiping to get a scanner.
- fulafel 7y agoIt hardly counts as paranoia, the gummy bears trick is so old hat and it's obvious you have no effective assurance of keeping the prints safe.
- Ayesh 7y agoI switched to my first Fingerprint phone a year ago, and I can't imagine going back to passcode unlocking for convenience reasons. Which is the most secure? It depends on the threat model. With an NFC sensor, I suppose it should be possible to unlock a phone from a physical key, but is it really convenient? The only downside of a fingerprint is that there is no key rotating. If your fingerprint pattern is compromised, you are screwed. This doesn't have to be a security vuln in the device itself. A determined attacker can take your fingerprints off the screen surface or back fit eh phone.