4 ms·
It will be interesting some day if the line becomes blurred between "what you know" and "what you are" and you could be compelled to turn over something against
by supernova87a 2y ago
It will be interesting some day if the line becomes blurred between "what you know" and "what you are" and you could be compelled to turn over something against your will. Because that boundary is if anything getting less clear over time?
For example, if your voiceprint were required to unlock your phone, but not a particular passphrase. Could you be compelled to speak (or just recorded speaking) general statements in order to unlock?
- autoexec 2y agoI'd argue that the solution then is the same as the solution now. Do not use or depend on biometrics for security or privacy. Stick with pins and passwords and you can't be compelled to give up that information just as you can't be compelled to give up the combination to a safe. I'd bet that law enforcement will be routinely using backdoors to gain access to our devices long before the laws that protect us from giving up a password are changed.
- dataflow 2y ago> I'd argue that the solution then is the same as the solution now. Do not use or depend on biometrics for security or privacy. Stick with pins and passwords and you can't be compelled to give up that information just as you can't be compelled to give up the combination to a safe. This is practically impossible. IMO it has been impossible for as long as phones have fused the decryption key and the screen unlock key into the same thing. (Some older Android ROMs let you have separate unlock and deception keys; does anyone know of any that still do?) Either you choose a strong encryption key, in which case you have to spend a ton of time typing it in every time you want to unlock your phone, or you choose something easy to type in which case the key becomes easy to crack. And in either case you have to do it over and over again in front of other people or security cameras constantly recording you.
- autoexec 2y agoAre passwords/passcodes really the only form of entropy used when generating encryption keys for an iphone? I'd expect that a longer password would only increase your security but that even the shortest password wouldn't leave the encrypted data trivial to crack. > And in either case you have to do it over and over again in front of other people or security cameras constantly recording you. That's partly prevented by having keys randomize their position on the screen so that your movements don't give away your code, and also by occasionally changing your password. Obviously if a camera is looking directly at the screen while you enter your password you're probably screwed.
- dataflow 2y ago> Are passwords/passcodes really the only form of entropy used when generating encryption keys for an iphone? I don't believe I ever claimed that. > I'd expect that a longer password would only increase your security but that even the shortest password wouldn't leave the data encryption trivial to crack. How short are you talking? Most people do like 4-6 digits. That's not going to protect you against anyone brute-forcing keys on the raw encrypted data. Your only real hope is the TPM holding the real key and being physically secure, which you have no way to ensure. And that still fails due to cameras etc. as mentioned. > That's partly prevented by having keys randomize their position on the screen That's almost security theater. It really only protects you from laymen, not state actors. It forces you to use numeric digits if you want that, which itself makes your key much weaker. > Obviously if a camera is looking directly at the screen while you enter your password you're probably screwed. Which is guaranteed to happen at some point when you're in public.
- thfuran 2y agoYou can be compelled to provide some information, but I'm not sure you can be compelled to voice it aloud, even if that is the usual means of conveying it.
- cryptonector 2y agoThe right to not self-incriminate is very limited. Historically if it is a foregone conclusion that you have contraband hidden or locked away then you can be coerced by the courts to reveal the location and/or furnish the key to unlock it. The theory is that handing over a key is not testifying. Therefore neither is providing your biometrics testifying either, and possibly even revealing your passcodes would be testifying either.
- _DeadFred_ 2y agoAnd of course 'The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated' aka the fourth amendment doesn't apply.