266
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
this post was submitted on 02 Aug 2026
266 points (100.0% liked)
Cybersecurity
10403 readers
207 users here now
c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.
THE RULES
Instance Rules
- Be respectful. Everyone should feel welcome here.
- No bigotry - including racism, sexism, ableism, homophobia, transphobia, or xenophobia.
- No Ads / Spamming.
- No pornography.
Community Rules
- Idk, keep it semi-professional?
- Nothing illegal. We're all ethical here.
- Rules will be added/redefined as necessary.
If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.
Learn about hacking
Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub
Notable mention to !cybersecuritymemes@lemmy.world
founded 3 years ago
MODERATORS
I think it depends. Some people might be inclined to use too short or simple password because they don't wanna constantly be typing a long password. It's much better to have a strong password and fingerprint/face rec for convince than just a insecure password.
In the USA, they can legally force you to unlock a device using biometrics.
Also, biometrics can be fooled in other ways.
Yes, but that's besides the point. If the convenient options for a normie user are
Out of those the fingerprint with a strong password is way better option, imo.
Also, how does that work? Can't they legally force you to enter your password too? Or can you claim you don't remember it? If that works, can't you just have a band-aid on your finger or something? Surely they cannot force you to take it off and risk getting an infection on the large wound you just happened to get yesterday...?
https://xkcd.com/538
Haha, reading some of the responses in this thread actually reminded me of that xkcd but I couldn't immediately find it. Thanks!
No, because forcing someone to enter a password is "compelled speech" and against the 1st Amendment. It's also testimonial, which means compelling that speech would also be self incrimination, which is against the 5th Amendment.
Don't ask me why forcing someone to make a hand gesture is not also compelled speech and not testimonial. The Constitution is mostly nonsense being interpreted by life appointed morons who interpret things however they like.
A normal user will most likely never encounter a situation where their weak password would be at risk, but are much more likely to having their biometrics forced by law enforcement or border control.
They will rip your bandaid off and force your finger or face to scan while holding your device.
Any weak password at all would have been better in a situation like that.
Oh wow, things really have gotten bad over there. For me personally, the much greater risk is that I forget my phone somewhere or someone steals it and in that scenario a weak password is the larger issue.
It seems there isn't a single correct answer here. The threat model is different for everyone.
I think the correct answer is that your device shouldn't suggest you to have a weak password work around, it should suggest a stronger password
'Or' not 'and'. Fingerprint replaces the password for access.
A bandaid would simply be removed. No you can't just say "no". A password is protected though.
Ah just don't go to the USA or don't take a device with information on it there.
Law enforcement can legally trick you into giving up your password, too, and that's full access right there. Having an unlocked phone but no password isn't enough to get into certain parts of the core system/security settings, and trying to get into those will prompt a password anyway (and that generally gatekeeps the access to the phone through a physical connector plugged into the port).
Neither pathway is perfect but I think for real world usage and real world adversaries (not just law enforcement, but also criminal thieves/scammers/hackers, and governmental adversaries that aren't bound by legal limits, like foreign intelligence agencies), it's better to have biometrics so that you are physically punching in your PIN/password much less frequently. Especially on modern systems that get spooked easily and require a password anyway when the phone has been idle too long or when the wrong face looks at it too many times.
The other underappreciated threat model is shoulder surfing, especially in an age of ubiquitous high resolution cameras. Punching in a numerical PIN within view of a camera potentially leaks that secret, and some high resolution cameras can even pick up letters and symbols from the on screen keyboards.
Being compelled to give biometrics doesn't do enough for an adversary (including government adversaries) to do everything with a phone, the way having the password or PIN does, and I would argue that governments would be better at tricking people into inadvertently giving up their PINs and passwords than they'd be at compelling biometrics within the time window that they still work (before the phones lockout biometrics as a valid unlocking method), or being able to do stuff to exploit extraction tools past the lock screen.
So the threat model needs to be understood for what it is.
Cops can't force you to give up your password even if its 12345.
Yes but they can guess it, and if it's 12345 then ...
Well yes, but many passwords limit the number of guesses, and if its not abcde, 12345, password, or Hunter2, you have basically eliminated all of the "easy guesses".
How did you get my password?
Depends on the cops
No, depends on the country.