6 ms·
What do you object to exactly if the biometric data is on device only? I’m not sure what is the privacy risk there. The apps that authenticate you don’t have a
by Renaud 2y ago
What do you object to exactly if the biometric data is on device only?
I’m not sure what is the privacy risk there. The apps that authenticate you don’t have access to biometric data.
The main risk I see is if that data was compromised and made available for something else, but I haven’t seen any breach of that that ended up being useful for anything?
Or maybe I missed something?
- jzb 2y agoSome folks may find collecting biometric data inherently creepy. I mean, yeah, there's also "what might happen when* it's leaked" but ... I just don't like it. It feels maximally invasive. * These days, I'd assume when, not if.
- kjs3 2y agoYou can change a password, you can't change your face. Agreed that we have yet to see the mass-hack based on biometric data that generates the ohshit moment, but from a risk perspective 'it hasn't happened yet' is cold comfort.
- exe34 2y ago> you can't change your face if you get involved with the wrong/right sort of people, they might do it for you
- catlikesshrimp 2y agoI would rather change my password. Easier, faster, less painful. And it doesn't affect how others perceive me.
- giantrobot 2y agoThe biometric data is not your password. It's used to unlock a session token. Getting that session token requires a "what you know" password. There's lots of events that invalidate that session token not the least of which on phones is multiple presses on the lock button (on iOS at least).
- Ajay-p 2y agoI don't trust the device, the maker, the company behind the facial recognition technology, and you. If I give software access to analyzing my face it opens the door to overt and covert acts that further erode my privacy. But really, I don't need a reason other than I'm uncomfortable with it. I worry about people who are comfortable with it..
- dylan604 2y agoI don't want to upset or scare you, but if you've ever been in a picture that someone else has posted online to any social platform, your face has already been tagged, recognized, and a very thick file exists about you and everything you do, like, know, associate, etc.
- MrDrMcCoy 2y agoTheoretically, those kinds of images lack the necessary detail to qualify as biometric data. If they somehow do, then the whole category becomes invalid for that purpose. I personally oppose all forms of biometrics for security, as it can neither be invalidated, nor is it safe from physical coercion. I also oppose biometric use for "tracking attention" because it's none of anybody's business but mine.
- fragmede 2y agotracking attention when you're driving is everyone's business. I'd rather you have a camera in your car making sure you're looking at the road, than have to drive next to someone who is on their cellphone and is trusting the self driving feature of their car.
- MrDrMcCoy 2y agoThere's a difference between tracking attention locally for driving as you suggest, and doing so for advertising and mobile device security, which is what the conversation was previously about. While I consider your example valid in a vacuum, it poses a substantial privacy and financial risk in the real world. If a car that tracks attention also phones home, your insurance carrier may raise your rates or cancel your plan for occasional glances away (sneezes, children, etc), regardless of an actual problem on the road. Such measures ought to only exist locally within a car, but I have absolutely no faith that it will be implemented that way given the current data shared along those lines.
- domador 2y agoMy own main objection is to biometric data being used as a password, since it is a publicly-viewable, likely-duplicatable password that can never be changed. My second objection is to the possibility of physical injury to me by someone that really wants to steal my credentials.
- Zambyte 2y agoFor what it's worth, you can be beaten with a wrench until you cough up a password also. Obviously there is a difference, but it's worth considering and understanding that.
- domador 2y agoOr I can cough up my password long before that, but if they need my biometrics, then they'll have to hold on to me personally... or a piece of me.
- dfxm12 2y agoit is a publicly-viewable, likely-duplicatable password that can never be changed. Is this true? I mean, you can't really show an iPhone a photo of your face to unlock it, can you? Or are you thinking of a different attack vector? My second objection is to the possibility of physical injury to me by someone that really wants to steal my credentials. This possibility exists even if your creds are something you know. It also exists if your creds are something you have, and you happen to have them on your person.
- jerbear4328 2y ago> Is this true? I mean, you can't really show an iPhone a photo of your face to unlock it, can you? Or are you thinking of a different attack vector? If you have the information that the iPhone wants to see, it is possible to create a synthetic face matching that data and hold it up in front of the phone.[1] You could also probably open up the phone and hotwire the sensors to give the hardened processor holding your Face ID data the readings it wants. Both of these things are super difficult to do, and much further out of reach of your average thief than simply printing out a picture of the person's face, but the point remains that it is theoretically possible. [1] Bkav Corporation has made masks that can fool Face ID for about $150: https://www.pcmag.com/news/researchers-claim-they-can-dupe-iphone-x-face-id-with-a-mask https://www.pcmag.com/news/researchers-claim-they-can-dupe-i... https://www.bkav.com/top-new/-/view-content/65202/bkav-s-new-mask-beats-face-id-in-twin-way-severity-level-raised-do-not-use-face-id-in-business-transactions https://www.bkav.com/top-new/-/view-content/65202/bkav-s-new...