• fyf@lemmy.world
    link
    fedilink
    English
    arrow-up
    16
    ·
    16 hours ago

    I can’t speak for OP, but in the US, you can be compelled to unlock a phone via fingerprint or face ID. You can’t be compelled to give over your PIN. That violates the right against self incriminating.

    • ricecake@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      7
      ·
      16 hours ago

      Totally true. That’s not the common threat most people need to guard against however. Additionally, at least on Android, the device is relatively eager to force pin usage if the stars don’t align for biometrics

      • 0x0@infosec.pub
        link
        fedilink
        English
        arrow-up
        6
        arrow-down
        3
        ·
        16 hours ago

        Almost any user are much more likely to encounter a situation where their biometrics are forced and not their password. Passing a border for example.

        Biometrics should never be used instead of a password, only as usernames. A password can be changed, your thumbs can’t.

        • ricecake@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          5
          ·
          edit-2
          13 hours ago

          Have you ever had your phone searched by the police or at the border? I haven’t, but I have had someone try to unlock my phone before.

          I’d contend most people have a threat model that puts opportunistic access by household members or someone watching them enter their passcode and then snatching the phone and running above border patrol search.

          While you can’t change your biometrics, walk me through why that matters. I’m not sharing my biometrics outside of the device, and you can’t submit them remotely, so if you lift a print off of something it doesn’t really get you much without also taking the phone. Once you’re there, you’re a bit beyond the typical phone thief in terms of threat.

          The most common vulnerability is having an absurdly weak password, pin or unlock pattern. For those people biometrics is a vast improvement specifically because it’s both secure against likely threats, and it’s just as easy as hitting 5 four times in a row.

          Every method has trade offs, and there’s nothing to gain by pretending otherwise. Likewise, I don’t think I would ever say “never use something”, except for some contrived examples.

        • Viceversa@lemmy.world
          link
          fedilink
          English
          arrow-up
          5
          arrow-down
          1
          ·
          edit-2
          13 hours ago

          Almost any user are much more likely to encounter a situation where their biometrics are forced and not their password. Passing a border for example.

          That’s valid only for americans. And even then: how many of them are crossing country borders regularly?

    • deliriousdreams@fedia.io
      link
      fedilink
      arrow-up
      2
      ·
      12 hours ago

      Which means it’s not secure against the authorities but probably is secure against the average thief and or snooping younger sibling/spouse. So, your threat profile and the use of biometrics/vs password may vary.

      • fyf@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        12 hours ago

        Definitely not. The average thief can get you to unlock it with your face or finger far easier than get your PIN.

        • ricecake@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          4
          ·
          7 hours ago

          If you point a weapon at me in a way that would compel me to help you unlock my phone with fingerprint or face unlock, I promise you it would not be any harder for you to get me to unlock the device with the pin.

          • fyf@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            16 minutes ago

            You assume that you are conscious, or even alive in your scenario.

        • deliriousdreams@fedia.io
          link
          fedilink
          arrow-up
          1
          ·
          12 hours ago

          Doubtful. The average thief isn’t robbing you at gunpoint. They grab the phone out of your hand and book it.

          But even if they did stick around for that, most people use a 4 number pin and that’s basically just as easy as face or fingerprint unlock. Its an additional maybe 2 seconds.

          If they can force you to put your finger on the sensor they can force you to give them the pin.

          • fyf@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            11 minutes ago

            Do any phones even allow 4 digit Pins? Apple doesn’t, and my Samsung doesn’t.

            No one can force you to give up the PIN. They can threaten, and you may give in to that threat. But that isn’t forcing, that isn’t against your will.

            But, a criminal can get you to unlock your phone with biometrics against your will easily enough - brute strength, render you unconscious, or even dead.

    • Viceversa@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      13 hours ago

      You can’t be compelled to give over your PIN. That violates the right against self incriminating.

      Is that valid only to USA citizens or foreigners can use that trick too?

      • deliriousdreams@fedia.io
        link
        fedilink
        arrow-up
        2
        ·
        12 hours ago

        It’s valid for anyone visiting the US. Even if they do so illegally. Its a right given by the constitution and it’s amendments and those apply to everyone in the US. Importantly, people often forget that the Constitution isn’t a limiting document for the people. It’s a limiting document for the government.