back
1 comments
That's even worse.

I want to be able to set, at my option: 1) PIN-only

2) FPR + PIN (where you must use iCloud to get in if your FPR doesn't read)

3) for morons, FPR only.

I currently use a much stronger than 4 digit numeric PIN, but it is honestly a pain. If I could set both the FPR and PIN as required to get in, I could use a shorter PIN. If I'm allowed to bypass the FPR entirely, the PIN has to remain as strong as it is now.

(What I'd also like is something better than hardcoded timeouts for requiring the PIN. Like "require FPR every single time you unlock, require PIN+FPR if it has been <30 minutes or <120 minutes but no movement on accelerometer OR connected in my car, require FPR+icloud passphrase otherwise". Fully configurable by the user.)

His tweet doesn't confirm or reject your #2 (just that PIN is available as an option), so just relax and wait to see. I mean, I doubt they'd implement FDR + PIN like you want (cause it seems a minority wish?), but it's still possible.
I'm curious why you say FPR only is for morons. I feel like I'm missing something.
Only for morons is way harsher than I'd put it, but fundamentally it's a difficult to inspect security system that's based on a potentially vague analog signal.

In the security world, things which are novel are not to be trusted. The security of a system is measured in how many serious researches have attacked it, and to what degree they succeeded.

I expect that there are solid biometric security standards that have been subject of serious analysis and attack. If it turns out that Apple's implementation uses one of these standard and tested solutions then I think I'd trust it in place of a PIN. In the absence of that evidence, the Properly Paranoid position is the skeptical one.

A quote from Babbage in 1864 is apropos: "One of the most singular characteristics of the art of deciphering is the strong conviction possessed by every person, even moderately acquainted with it, that he is able to construct a cipher which nobody else can decipher."

Because compelling someone to give you a fingerprint is pretty easy, and could be done trivially at a border, or incident to arrest or detention, or by anyone willing to use a modicum of physical force.

Plus, since liveness checks are weak, anyone with access to anything containing your prints. I suspect at the next Defcon there will be a fun challenge to defeat it given a print lifted from a glass using $5 in supplies in 30 minutes. And then at the Defcon after that, the same contest will be in the children's area.

Imagine someone knocks you out and takes your phone. Use finger (possibly still attached) to authenticate. Profit.

So not really a good idea.

I rather have the option of unlocking the phone via PIN, then have the option of sending a FPR hash to a site of my choice. Speaking of which, I wonder if they salt or provide some other way of sending unique hashes to different web sites or is this now the equivalent of using a fingerprint as the same password for all sites.

Which is worse, since you can't really get a new finger (well, you get 19 more resets including toes) since your print is somehow compromised (website leak, etc.)

I read a liveblog of the presentation, and they only mentioned using it to unlock the phone and to purchase from the iTunes store. I don't think it's usable for random websites.