4 ms·
All that's well and good until companies start implementing their own FaceID then forcing you to use it [0] on the back of trusting Apple, even CALLING it the s
by RonanTheGrey 6y ago
All that's well and good until companies start implementing their own FaceID then forcing you to use it [0] on the back of trusting Apple, even CALLING it the same thing.
This app linked above (my bank) contains NONE of the security you've mentioned above.
And, incidentally, for me, biometrics STILL fail every test that matters to me: If I am dead, a bad actor can still gain access to my accounts. With a password, they cannot.
[0] https://apps.apple.com/us/app/bbva-m%C3%A9xico-bancomer-m%C3%B3vil/id374824226 https://apps.apple.com/us/app/bbva-m%C3%A9xico-bancomer-m%C3...
- RonanTheGrey 6y agoRather than downvote me for pointing out how companies abuse this, explain how this is an improvement.
- RonanTheGrey 6y agoLol...
- acdha 6y ago> This app linked above (my bank) contains NONE of the security you've mentioned above. This misunderstanding is where you went wrong: your bank doesn’t have a choice about this. If they use FaceID, they don’t have a choice about implementing that - the app can ask it to perform the public-key authentication operation but there’s no way for the developer to choose to weaken the security of the system. Similarly, you should read up about how these systems incorporate liveness checks. A dead body will not pass those and, if you weren’t aware, Apple’s implementation requires a password after a reboot or a small number of failed tries. It’s presumably possible for a well-resourced attacker to bypass those but you’d have to think about how much more vulnerable you are if you use only a password which is much easier for an attacker with that level of resources to capture. If you’re worried about Tom Cruise recording a mask from your still-cooling body, think about how much easier it’d be to get a camera to record you entering it - which you do a lot more in public if you don’t use biometrics - and how trivially this could be done without your knowledge.
- RonanTheGrey 6y agoI think you misunderstood (but I appreciate your reply) This bank is NOT using FaceID, they invented their own version and are calling it the same thing. Your picture goes to their servers. Who knows what happens after that. And they're piggy backing on Apple's trust where FaceID is concerned in order to do it. They are not the only company I have seen do this.