• ricecake@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    7
    ·
    16 hours ago

    Totally true. That’s not the common threat most people need to guard against however. Additionally, at least on Android, the device is relatively eager to force pin usage if the stars don’t align for biometrics

    • 0x0@infosec.pub
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      3
      ·
      16 hours ago

      Almost any user are much more likely to encounter a situation where their biometrics are forced and not their password. Passing a border for example.

      Biometrics should never be used instead of a password, only as usernames. A password can be changed, your thumbs can’t.

      • ricecake@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        5
        ·
        edit-2
        13 hours ago

        Have you ever had your phone searched by the police or at the border? I haven’t, but I have had someone try to unlock my phone before.

        I’d contend most people have a threat model that puts opportunistic access by household members or someone watching them enter their passcode and then snatching the phone and running above border patrol search.

        While you can’t change your biometrics, walk me through why that matters. I’m not sharing my biometrics outside of the device, and you can’t submit them remotely, so if you lift a print off of something it doesn’t really get you much without also taking the phone. Once you’re there, you’re a bit beyond the typical phone thief in terms of threat.

        The most common vulnerability is having an absurdly weak password, pin or unlock pattern. For those people biometrics is a vast improvement specifically because it’s both secure against likely threats, and it’s just as easy as hitting 5 four times in a row.

        Every method has trade offs, and there’s nothing to gain by pretending otherwise. Likewise, I don’t think I would ever say “never use something”, except for some contrived examples.

      • Viceversa@lemmy.world
        link
        fedilink
        English
        arrow-up
        5
        arrow-down
        1
        ·
        edit-2
        13 hours ago

        Almost any user are much more likely to encounter a situation where their biometrics are forced and not their password. Passing a border for example.

        That’s valid only for americans. And even then: how many of them are crossing country borders regularly?