The other underappreciated threat model is shoulder surfing, especially in an age of ubiquitous high resolution cameras. Punching in a numerical PIN within view of a camera potentially leaks that secret, and some high resolution cameras can even pick up letters and symbols from the on screen keyboards.
Being compelled to give biometrics doesn’t do enough for an adversary (including government adversaries) to do everything with a phone, the way having the password or PIN does, and I would argue that governments would be better at tricking people into inadvertently giving up their PINs and passwords than they’d be at compelling biometrics within the time window that they still work (before the phones lockout biometrics as a valid unlocking method), or being able to do stuff to exploit extraction tools past the lock screen.
So the threat model needs to be understood for what it is.
Hell, I still sometimes think about the research team that tried to make a camera in a bus (so at the front pointed towards the faces of riders) obtain passwords from the reflections off of sunglasses. They collectively facepalmed when they tried it with their test subject, but accidentally picked up the passwords of several others on the bus that were not part of the experiment.
That was something like 8-12 years ago… Capabilities now are likely insane.
The other underappreciated threat model is shoulder surfing, especially in an age of ubiquitous high resolution cameras. Punching in a numerical PIN within view of a camera potentially leaks that secret, and some high resolution cameras can even pick up letters and symbols from the on screen keyboards.
Being compelled to give biometrics doesn’t do enough for an adversary (including government adversaries) to do everything with a phone, the way having the password or PIN does, and I would argue that governments would be better at tricking people into inadvertently giving up their PINs and passwords than they’d be at compelling biometrics within the time window that they still work (before the phones lockout biometrics as a valid unlocking method), or being able to do stuff to exploit extraction tools past the lock screen.
So the threat model needs to be understood for what it is.
Hell, I still sometimes think about the research team that tried to make a camera in a bus (so at the front pointed towards the faces of riders) obtain passwords from the reflections off of sunglasses. They collectively facepalmed when they tried it with their test subject, but accidentally picked up the passwords of several others on the bus that were not part of the experiment.
That was something like 8-12 years ago… Capabilities now are likely insane.