4 ms·
Isn't it obvious that logging in with your face or your fingerprint is less secure? Sure, it's convenient, but any thug can just forcefully unlock your device.
by bufferoverflow 3y ago
Isn't it obvious that logging in with your face or your fingerprint is less secure? Sure, it's convenient, but any thug can just forcefully unlock your device.
- bbddg 3y agoI think for anyone not working in national security, any thug could just as easily get your password out of you.
- forward1 3y agoReminds me of this wondeful scene in Ronin: Everybody has a limit. I spent some time in interrogation... once. They make it hard on you ? - They don't make it easy. Yeah, it was unpleasant. I held out as long as I could. All the stuff they tried. You just can't hold out for ever. How'd they finally get to you? They gave me a grasshopper. - What's a grasshopper? That's two part gin, two part brandy, one part crème de menthe...
- kube-system 3y agoMost thugs don't have physical access required to exploit this. They're on the other side of the world and are doing credential stuffing attacks.
- renegat0x0 3y agoIn case od data leak - you cannot change your face, or fingerprints. You can change passwords though.
- ezfe 3y agoGood news that you can’t bring someone’s face to google and ask for access to their account… Please don’t insert commentary when it’s clear you don’t know what you’re talking about
- renegat0x0 3y agoThieves can steal a car using tech magic. That is also true about access to accounts. That contradicts your comment. Biometrics, if stolen, can be used to access any of accounts if one obtains knowledge about how to use it for hacking. Your comment violates HN guidelines, but as guideline says I assume good faith therefore I have provided details about how you're incorrect on that one.
- ezfe 3y agoA passkey does not contain and is not derived from biometric data, so one cannot login to an account using biometric data alone. If one wanted to use biometric data to access a Google Account secured with a passkey, one would: 1. Need to find a device with that passkey on it (or an account like iCloud Keychain or 1Password that contains the synced passkey). Biometric data could be used to unlock the iPhone, in theory. I'm not aware of this being done in practice. 2. Then unlock that passkey. On iOS, biometric data could be used to perform this step, just as accessing the iPhone in step 1. If you hold the power/volume buttons or do a Find My lock, it disables biometric auth on an iPhone. I assume there are equivalent tools on Android. So, if I lose my iPhone and someone also scanned my face, they could login to my Google account by generating a face accurate enough to fool Face ID, and only if they did it before I marked the phone as lost.
- renegat0x0 3y agoIt does not have to be a thug who makes your picture. Titanic has crashed. Microsoft has been hacked. There are no solutions that do not contain bugs. There are no drivers for sensors that cannot be hacked. Sure hacking a device is difficult, sure. Maybe nearly impossible, but I doubt it. All software has bugs. Some even backdoors. Some data are centralized and kept on big tech cloud storage which is a honey pot for hackers. Once hacker has biometrics data on your phone captured, it could be used. Not only to obtain your passkeys, but outside of your phone. A simple google search confirms that. There was a biometric data breach. Sure this might not be the best result, but I spend 2 seconds searching for it. Quite generic article, but I think it is sufficient. https://www.secureworld.io/industry-news/biometric-data-breach-consequences https://www.secureworld.io/industry-news/biometric-data-brea... Quotes "Facial recognition and fingerprint information cannot be changed. Once they are stolen, it can't be undone." "Putting all the data found in the leak together, criminals of all kinds could use this information for varied illegal and dangerous activities." Keychain, iCloud, 1Password... These are just details.
- Savely 3y agoYeah, because good old passwords are safe against thermo-rectal cryptoanalysis.
- forward1 3y agoMost "thugs" interested in data sit in windowless offices in Manila or Delhi and effortlessly spam phishing and other attacks on weak credentials; they do not roam the streets looking for face-unlockable devices to exfiltrate. That is to say, almost all attacks are remote. And just because someone walking next to you on the street might have a black belt in martial arts, does not mean they're going to turn you into a pretzel on sight. The reality is people are not good at creating, managing and using credentials well - and this is an existential risk for most users not realized until it's possibly too late. Any efforts to assist, support and otherwise absolve users of credential responsibility is a net win for infosec (though likely a loss for privacy).
- grotorea 3y agoCan't the thug apply the 20$ wrench to your face until you say your password?