3 ms·
agreed with first two sentences. but, "..which you unlock with your password and/or biometrics"? unlocking with biometrics is actually the problem, regardless
by throwawayapples 4y ago
agreed with first two sentences.
but, "..which you unlock with your password and/or biometrics"?
unlocking with biometrics is actually the problem, regardless of where the unlocking takes place.
relying on a third-party device that you can't even verify is in the custody of its user as "the only secure way to authorize actions" is highly problematic for similar reasons.
and confirming "from other devices" rapidly turns into a user nightmare.
the irony in all this is that lengthy, strong, non-reused passwords are actually pretty secure, and they don't require any specialized technology or rely on possessing a device that you just forgot on the airplane seat pocket and is now winging its way toward another country.
- EGreg 4y agoNot necessarily. As long as the device is YOURS, you can unlock it with your face, thumbprint etc. That is how iPhones and Android security has been managed for a long time. Perhaps to unlock even more valuable transactions, you’d want to bring an external key, like a Yubikey or Ledger Nano wallet etc. Lengthy passwords that you enter are not very secure. Anyone can capture your keystrokes, look over your shoulder with a camera, or even look at heat signatures on your phone after you left to the bathroom and locked it: https://www.zdnet.com/google-amp/article/this-thermal-attack-can-read-your-password-from-the-heat-your-fingertips-leave-behind/ https://www.zdnet.com/google-amp/article/this-thermal-attack...
- throwawayapples 4y agoBiometrics are not secure. see https://news.ycombinator.com/item?id=34913240 https://news.ycombinator.com/item?id=34913240