• carl_dungeon@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    6 months ago

    Last week, the 9th Circuit Court of Appeals in California released a ruling that concluded state highway police were acting lawfully when they forcibly unlocked a suspect’s phone using their fingerprint.

    You can turn that and Face ID off on iOS by mashing the power button 5 times- it locks everything down.

    • FiveMacs@lemmy.ca
      link
      fedilink
      English
      arrow-up
      0
      ·
      6 months ago

      ⚠️ WARNING: On android, mashing the power button 5 times calls emergency services…

      • Victor@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        6 months ago

        Not on my Pixel 6. 🤷‍♂️ It just does what I told it to do, namely to open the camera.

        Edit: these are some Reddit down votes. I just didn’t know I had this feature, and I apparently have disabled it, but I don’t remember doing so. Oh well.

  • Boozilla@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    6 months ago

    I’ve avoided willingly using biometrics so far. Though I’m sure our faces, gaits, body shapes, etc, are all stored somewhere, willingly or not.

    Say no to biometrics. It’s like having a password you can never change.

    • chrash0@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      6 months ago

      it’s not a password; it’s closer to a username.

      but realistically it’s not in my personal threat model to be ready to get tied down and forced to unlock my phone. everyone with windows on their house should know that security is mostly about how far an adversary is willing to go to try to steal from you.

      personally, i like the natural daylight, and i’m not paranoid enough to brick up my windows just because it’s a potential ingress.

      • Boozilla@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        6 months ago

        It’s not a great analogy. Your house and its windows are exposed to your neighborhood/community. Your internet device is adjacent to every hacker on the web.

        • chrash0@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          6 months ago

          it’s an analogy that applies to me. tldr worrying about having my identity stolen via physical access to my phone isn’t part of my threat model. i live in a safe city, and i don’t have anything the police could find to incriminate me. everyone is going to have a different threat model. some people need to brick up their windows

          • Boozilla@lemmy.world
            link
            fedilink
            English
            arrow-up
            0
            ·
            6 months ago

            Assuming the phone’s security works as intended, what you’re saying is true. However, it’s a legit concern that the security is not airtight, and physical access is not actually required to harvest your biometric data.

            I know the phone manufacturers make all sorts of claims about how secure biometric data is, but they have a profit motive to do so. I’m not being brick-up-my-windows paranoid by pointing out all the security failures and breaches we’ve seen over the years. Companies that have billions on the line are still frequently falling short at securing their own assets, much less their customer’s data.

            I understand biometrics are convenient, and many folks love the ease / coolness factor of using them. Just don’t kid yourself that it’s secure by requiring your physical phone. Once the dark web has a digital copy of your biometric data, it’s compromised forever.

    • ricecake@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      0
      ·
      6 months ago

      So, it really depends on your personal threat model.

      For background: the biometric data doesn’t leave the device, it uses an on-device recognition system to either unlock the device, or to gain access to a hardware security module that uses very strong cryptography for authentication.

      Most people aren’t defending against an attacker who has access to them and their device at the same time, they’re defending against someone who has either the device or neither.

      The hardware security module effectively eliminates the remote attacker when used with either biometric or PIN.
      For the stolen or lost phone attack, biometric is slightly more secure, but it’s moot because of the pin existing for fallback.

      The biggest security advantage the biometrics have to offer is that they’re very hard to forget, and very easy to use.
      Ease of use means more people are likely to adopt the security features using that hardware security module provides, and that’s what’s really dialing up the security.

      Passwords are most people’s biggest vulnerability.

      • Boozilla@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        6 months ago

        I’ve read all this before. If you believe the people who designed and implemented the device and its myriad layers of firmware and software were 1. All acting in good faith and 2. Knew WTF they were doing… then: yes, sure.

        Unfortunately that’s way too many strangers for me. Hundreds of people design and code these things. Meanwhile, every week there’s a clever new breach somewhere.

        • lolcatnip@reddthat.com
          link
          fedilink
          English
          arrow-up
          0
          arrow-down
          2
          ·
          6 months ago

          If you’re that afraid if the people who build phones, why are you ok with using any device that can access the internet?

          • Boozilla@lemmy.world
            link
            fedilink
            English
            arrow-up
            0
            ·
            6 months ago

            I like how being cautious with my biometric data is beung framed as irrational fear and paranoia. As if ID theft never happens.

            • lolcatnip@reddthat.com
              link
              fedilink
              English
              arrow-up
              0
              arrow-down
              2
              ·
              6 months ago

              Using biometric data to unlock your phone does not make you more vulnerable to petty criminals.

  • riodoro1@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    6 months ago

    Maybe don’t live in a fucking dystopia. The US is a police state and you have no freedom left.

    • Chakravanti@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      0
      arrow-down
      1
      ·
      edit-2
      6 months ago

      You do have the delusion of it though. It may not be real but if you want it to be you can work hard for money that was never real to begin with.

      The more of those Talisman you handle the more magick will save your life til your labor is done with.