4 ms·
I always get the sense of cognitive dissonance when I read security researches and advocates write about passwords and fingerprints. If you have access to my d
by baffledbysmall 12y ago
I always get the sense of cognitive dissonance when I read security researches and advocates write about passwords and fingerprints. If you have access to my device, you have access to my physical person, and my physical person will freely give up any password because no secret I have is worth my life. This isn't Hollywood, I'll give up my password with even the hint of physical violence that could maim or otherwise affect my quality of life.
Fingerprint readers, as Apple uses them per device backed by a strong high entropy password, are good enough for securing the average persons access to a device.
My physical security, something much more dear to me than my secrets, is protected not by keys and tumblers, but by a 1/4 inch of glass that can be cut through in seconds with $5 from the hardware store. Even the key and lock can be circumvented with a rubber mallet and a bump key, or a set of picks. So why use them? Because locks keep honest people honest, and those looking to cause you harm will cause you harm, regardless of what digital security you use.
- Someone1234 12y agoYou cannot say that without linking to this: https://xkcd.com/538/ https://xkcd.com/538/
- astazangasta 12y agoJake Applebaum was detained routinely during border crossings in the early wikileaks days. They (FBI?) demanded he decrypt his hard drive for them. He refused. As far as I know they never managed to get inside. This works, at least some of the time.
- jrochkind1 12y agoI think you take the right approach to true security risk analysis. But there are all sorts of cases you leave out. Someone might very well have access to your device without having access to your physical person. Because your device was lost or stolen. Someone may very well not be willing to threaten you with physical harm, but be willing to hack your device. (Not every adversary is from a Hollywood movie either!) Law enforcement agencies may not be legally allowed to compel you to reveal your password, but legally allowed to hack your device. Etc.
- baffledbysmall 12y agoPerhaps, but I feel that anyone sophisticated enough to replicate my fingerprint perfectly before it reverts to password only, and to do so before I'm able to make a remote wipe, and able to even find my fingerprints (lost phone) and to be lucky enough that the fingerprint is the one I used to secure the device, makes this a sufficiently low risk to the average user in my opinion. If you're at odds with an American TLA, your 4 digit pin isn't going to slow them down at all. Besides, the entropy on the average 4 digit pin is really low, it has a greater chance of using 5, 6, 8, and 9 for righties, and 4, 5, 7, 8 for lefties. Combine this with repeated finger grease blobs, and I don't feel anyone can logically argue that a pin is a sufficiently more secure option compared to a fingerprint.
- baffledbysmall 12y agoSorry, I should amend that last statement to be using the model Apple is using with it's touch ID where the fingerprint simply authenticates use of a high entropy password stored on the device, and the datum of the fingerprint is in not sent.