4 ms·
> I'd argue that the solution then is the same as the solution now. Do not use or depend on biometrics for security or privacy. Stick with pins and passwords an
by dataflow 2y ago
> I'd argue that the solution then is the same as the solution now. Do not use or depend on biometrics for security or privacy. Stick with pins and passwords and you can't be compelled to give up that information just as you can't be compelled to give up the combination to a safe.
This is practically impossible. IMO it has been impossible for as long as phones have fused the decryption key and the screen unlock key into the same thing. (Some older Android ROMs let you have separate unlock and deception keys; does anyone know of any that still do?)
Either you choose a strong encryption key, in which case you have to spend a ton of time typing it in every time you want to unlock your phone, or you choose something easy to type in which case the key becomes easy to crack.
And in either case you have to do it over and over again in front of other people or security cameras constantly recording you.
- autoexec 2y agoAre passwords/passcodes really the only form of entropy used when generating encryption keys for an iphone? I'd expect that a longer password would only increase your security but that even the shortest password wouldn't leave the encrypted data trivial to crack. > And in either case you have to do it over and over again in front of other people or security cameras constantly recording you. That's partly prevented by having keys randomize their position on the screen so that your movements don't give away your code, and also by occasionally changing your password. Obviously if a camera is looking directly at the screen while you enter your password you're probably screwed.
- dataflow 2y ago> Are passwords/passcodes really the only form of entropy used when generating encryption keys for an iphone? I don't believe I ever claimed that. > I'd expect that a longer password would only increase your security but that even the shortest password wouldn't leave the data encryption trivial to crack. How short are you talking? Most people do like 4-6 digits. That's not going to protect you against anyone brute-forcing keys on the raw encrypted data. Your only real hope is the TPM holding the real key and being physically secure, which you have no way to ensure. And that still fails due to cameras etc. as mentioned. > That's partly prevented by having keys randomize their position on the screen That's almost security theater. It really only protects you from laymen, not state actors. It forces you to use numeric digits if you want that, which itself makes your key much weaker. > Obviously if a camera is looking directly at the screen while you enter your password you're probably screwed. Which is guaranteed to happen at some point when you're in public.