Yes, but that’s besides the point. If the convenient options for a normie user are
Having a weak password
Having a strong password and a fingerprint
Out of those the fingerprint with a strong password is way better option, imo.
In the USA, they can legally force you to unlock a device using biometrics.
Also, how does that work? Can’t they legally force you to enter your password too? Or can you claim you don’t remember it? If that works, can’t you just have a band-aid on your finger or something? Surely they cannot force you to take it off and risk getting an infection on the large wound you just happened to get yesterday…?
Also, how does that work? Can’t they legally force you to enter your password too?
No, because forcing someone to enter a password is “compelled speech” and against the 1st Amendment. It’s also testimonial, which means compelling that speech would also be self incrimination, which is against the 5th Amendment.
Don’t ask me why forcing someone to make a hand gesture is not also compelled speech and not testimonial. The Constitution is mostly nonsense being interpreted by life appointed morons who interpret things however they like.
A normal user will most likely never encounter a situation where their weak password would be at risk, but are much more likely to having their biometrics forced by law enforcement or border control.
They will rip your bandaid off and force your finger or face to scan while holding your device.
Any weak password at all would have been better in a situation like that.
I’m on a relatively boring android phone and biometrics are only available in circumstances where it’s already vaguely confident it’s you.
Miss the fingerprint reader by too much? It’s now a pin unlock. Haven’t used pin recently enough? No biometrics.
It’s pretty far from being replaced, considering I seem to need to use the pin on the lock screen several times a day at least.
When you go through a border crossing or go to do something that might get you on the RADAR of a police or government entity, just wipe your phone or carry a burner.
They are looking to bypass pretty much any security you use at that point so for that threat profile and the security required to safeguard you, a password will not be sufficient and you are not going to win.
I’m not advocating for or against passwords here. I’m pointing out that A/. you can lockdown the device with key presses to make it require a password, some devices will require a password to be entered at certain intervals and when a device is restarted, and the only time you’d really need to worry about this is when dealing with law enforcement. At which point it’s likely that your particular threat profile would require you to forego biometrics entirely.
But it’s still not the same as no password. There’s still a barrier, but you can be coerced to remove that barrier.
If you don’t think they can force you to give up a pin or password, i would point you to the sheer number of incarcerated people who actually have been proven innocent who admitted to a crime because the police coerced a confession.
Oh wow, things really have gotten bad over there. For me personally, the much greater risk is that I forget my phone somewhere or someone steals it and in that scenario a weak password is the larger issue.
It seems there isn’t a single correct answer here. The threat model is different for everyone.
Yes, but that’s besides the point. If the convenient options for a normie user are
Out of those the fingerprint with a strong password is way better option, imo.
Also, how does that work? Can’t they legally force you to enter your password too? Or can you claim you don’t remember it? If that works, can’t you just have a band-aid on your finger or something? Surely they cannot force you to take it off and risk getting an infection on the large wound you just happened to get yesterday…?
No, because forcing someone to enter a password is “compelled speech” and against the 1st Amendment. It’s also testimonial, which means compelling that speech would also be self incrimination, which is against the 5th Amendment.
Don’t ask me why forcing someone to make a hand gesture is not also compelled speech and not testimonial. The Constitution is mostly nonsense being interpreted by life appointed morons who interpret things however they like.
Bible / Quran, is that you?
‘Or’ not ‘and’. Fingerprint replaces the password for access.
A bandaid would simply be removed. No you can’t just say “no”. A password is protected though.
A normal user will most likely never encounter a situation where their weak password would be at risk, but are much more likely to having their biometrics forced by law enforcement or border control.
They will rip your bandaid off and force your finger or face to scan while holding your device.
Any weak password at all would have been better in a situation like that.
How?
You can’t be compelled to give up your password.
A weak password they can guess.
Compared to guaranteed success, a weak password is superior.
Youre comparing a weak password to no password here and suggesting no password is better.
I’m not. I have never seen a device that can be set up without a password or pin in addition to face or fingerprint unlock.
You have to have both.
Once the biometrics are there, it replaces the pin/password in most scenarios I can think of.
Cell phone access, logging into a PC, etc.
Setting up both doesn’t mean that both are required for access.
Biometrics can be compelled (forced). So face or fingerprint can be forced, making them irrelevant to security - the same as no password.
I’m on a relatively boring android phone and biometrics are only available in circumstances where it’s already vaguely confident it’s you.
Miss the fingerprint reader by too much? It’s now a pin unlock. Haven’t used pin recently enough? No biometrics.
It’s pretty far from being replaced, considering I seem to need to use the pin on the lock screen several times a day at least.
https://immpolicytracking.org/policies/ice-notice-of-intent-to-award-contract-to-cellebrite-for-smartphone-hacking-technology/
When you go through a border crossing or go to do something that might get you on the RADAR of a police or government entity, just wipe your phone or carry a burner.
They are looking to bypass pretty much any security you use at that point so for that threat profile and the security required to safeguard you, a password will not be sufficient and you are not going to win.
I’m not advocating for or against passwords here. I’m pointing out that A/. you can lockdown the device with key presses to make it require a password, some devices will require a password to be entered at certain intervals and when a device is restarted, and the only time you’d really need to worry about this is when dealing with law enforcement. At which point it’s likely that your particular threat profile would require you to forego biometrics entirely.
But it’s still not the same as no password. There’s still a barrier, but you can be coerced to remove that barrier.
If you don’t think they can force you to give up a pin or password, i would point you to the sheer number of incarcerated people who actually have been proven innocent who admitted to a crime because the police coerced a confession.
Oh wow, things really have gotten bad over there. For me personally, the much greater risk is that I forget my phone somewhere or someone steals it and in that scenario a weak password is the larger issue.
It seems there isn’t a single correct answer here. The threat model is different for everyone.
I think the correct answer is that your device shouldn’t suggest you to have a weak password work around, it should suggest a stronger password