3 ms·
Your biometrics are already getting analyzed from all angles somewhere in China just from all the face apps that predict which Disney princess you are. And you
by trickstra 7y ago
Your biometrics are already getting analyzed from all angles somewhere in China just from all the face apps that predict which Disney princess you are. And you cannot change it like a password. So that's why it's a gimmick.
- aneutron 7y agoThat is not very civil of you. OP is making a very solid point. Consider your threat model first. If you're a high value target, then yes it's probably a gimmick as you're more likely to have a gun to your head. But for other attack vectors that are more automatable and deployed at large (e.g. Trojan Apps), as OP suggests, it is a lot of things, but not a gimmick.
- sV5OvuqTZXPSqw1 7y agoFirst, shoutout to HN for not blocking my Tor throwaway. I am someone who would be considered to be a "high value target" since I have had some of these things happen to me and I'm certain they will happen again in the future. I work in a politically sensitive industry where it turns out these things are commonplace. When I was younger I was always security conscious and took serious trade-offs to maintain my privacy. You could have called me paranoid, but I think I was more excited at the idea of being protected against all of these high-level threats, even if most of them were nonexistent at the time. While this discipline certainly benefited me later in life, I've realized that I will never again get the chance to reasonably evaluate my threats as "average" and enjoy some of the simpler conveniences of technology that come at the cost of compromising some high-severity threat models. Of course I still think there are a lot of precautions the average person can take to protect their privacy without major trade-offs, but those don't usually include state actor-level threats against your devices. I wouldn't change a thing now, but when I talk to people who see no reason to take anything more than the average precautions, I no longer think it's "cool" to do anything more than that because I know for a fact I would too if I was in their shoes.
- inetknght 7y ago> That is not very civil of you. I think @trickstra was quite civil in their comment. And they also brought up a completely valid point: > > And you cannot change it like a password. So that's why it's a gimmick. Regardless of threat model, not being able to change biometrics makes them very high value to an opposing force. Using biometrics "for the masses" to whom they don't have that completely different threat model practically eliminates their ability to upgrade their threat model since their biometrics have potentially been compromised already. Therefore, it very much is a gimmick.
- Karunamon 7y agoI'd say the threat model is critical. If your adversary is a state power targeting you personally, you have already lost. They'll just throw you in jail, or worse, until you put your thumb on the button. If your adversary is a random thief, or the untrustworthy general public, then it works great, and is a significant upgrade from the zero security that most people had prior to the proliferation of biometrics on phones.
- trickstra 7y agoYou are missing the point - it would be an upgrade, if it wasn't coupled with the proliferation of random apps scanning faces and fingerprints and people randomly giving out their biometrics to anyone. It won't take long before script kiddies will crawl the internet using the latest biometric leak just checking which other services the victims used.