5 ms·
I completely agree. While two factor auth is probably overkill for just unlocking a device to many people, I would like to at least have the option. One of my
by cjunky 12y ago
I completely agree.
While two factor auth is probably overkill for just unlocking a device to many people, I would like to at least have the option.
One of my concerns is that if your device is ever taken by an organization that has the ability to command your fingerprints then they can quite easily unlock your device negating any encryption.
Also while I think its unlikely right now for criminals to make fake fingerprints in order to steal financial transactions, its a flaw and ApplePay is going to financially motivate those criminals to look into ways to refine the process and make it easier to do.
- tillinghast 12y agoI would surmise that this is because Apple relies upon the PIN as a failsafe in the event that the Touch ID sensor can't / won't read your fingerprint. Let's say you only have your right thumbprint scanned and you injure it to the extent that it's no longer recognizable to the Touch ID sensor—what then? Two-factor authentication would need to rely upon a much more reliable criteria than Touch ID.
- cjunky 12y agoYou could always set up one pin/passcode for two factor auth and then use a separate passphrase as a fallback to unlock the device. It woould be much better security that way. Also while we are on the subject using a short pincode to unlock the device is asking for trouble. While the device ID is tied to the decryption and there is no way to extract it yet I have no confidence that it will remain that way forever. At which point the ability to crack a short pin off the device means the pin will get cracked in seconds.
- pilif 12y agoTurn your phone off before crossing a border. Put the wrong finger on the sensor five times in quick succession when you are asked to hand over your phone and you don't get a chance to turn it off. In both cases, the phone will require a passphrase for unlocking (if you configure one as opposed to just a simple code, of course). Having a really long passphrase and the ability to very quickly render the fingerprint reader useless is a huge improvement in security over previous touchid-less phones. Having to both type a code and using my fingerprint (in that case, in addition to a very long passphrase, which would be difficult to explain to users how that works) would be very annoying, at least for me.
- ghshephard 12y agoPin, not a passphrase. Just switching to a 4 digit pin would be heaven for me (I have an iPhone 5) - I would have zero problem entering touchID + a 4 digit pin.
- r00fus 12y agoEven simply disabling "simple passcode" and using an equivalently simple alphanumeric passcode makes the task a lot more difficult for the brute-force cracker. In fact, if you look at one of the cracking tools that law enforcement is known to use [1], iOS8 looks to have made things more difficult: "iOS 8 Currently under version 4.0 Advanced logical extraction will extract less data compare to previous iOS versions." [1] http://releases.cellebrite.com/releases/ufed-release-notes-4-0.html http://releases.cellebrite.com/releases/ufed-release-notes-4...
- ghshephard 12y agoThe idea would be multi-level protection: Short period of time - touchid to unlock. Medium period of time (adjustable) - touchID+Pin Long period of time - (adjustable) - passcode Different people could set the values as appropriate. For me, it would be < 5 minutes touch ID, < 1 hours touchID+Pin, > 1 hours passcode.
- cjunky 12y agocompletely agree!