266
you are viewing a single comment's thread
view the rest of the comments
[-] JRaccoon@discuss.tchncs.de 7 points 4 days ago

Yes, but that's besides the point. If the convenient options for a normie user are

  • Having a weak password
  • Having a strong password and a fingerprint

Out of those the fingerprint with a strong password is way better option, imo.

In the USA, they can legally force you to unlock a device using biometrics.

Also, how does that work? Can't they legally force you to enter your password too? Or can you claim you don't remember it? If that works, can't you just have a band-aid on your finger or something? Surely they cannot force you to take it off and risk getting an infection on the large wound you just happened to get yesterday...?

[-] PlexSheep@infosec.pub 5 points 3 days ago
[-] JRaccoon@discuss.tchncs.de 2 points 3 days ago

Haha, reading some of the responses in this thread actually reminded me of that xkcd but I couldn't immediately find it. Thanks!

[-] queermunist@lemmy.ml 16 points 4 days ago* (last edited 4 days ago)

Also, how does that work? Can’t they legally force you to enter your password too?

No, because forcing someone to enter a password is "compelled speech" and against the 1st Amendment. It's also testimonial, which means compelling that speech would also be self incrimination, which is against the 5th Amendment.

Don't ask me why forcing someone to make a hand gesture is not also compelled speech and not testimonial. The Constitution is mostly nonsense being interpreted by life appointed morons who interpret things however they like.

[-] 0x0@infosec.pub 10 points 4 days ago* (last edited 4 days ago)

A normal user will most likely never encounter a situation where their weak password would be at risk, but are much more likely to having their biometrics forced by law enforcement or border control.

They will rip your bandaid off and force your finger or face to scan while holding your device.

Any weak password at all would have been better in a situation like that.

[-] JRaccoon@discuss.tchncs.de 5 points 4 days ago

Oh wow, things really have gotten bad over there. For me personally, the much greater risk is that I forget my phone somewhere or someone steals it and in that scenario a weak password is the larger issue.

It seems there isn't a single correct answer here. The threat model is different for everyone.

[-] CubitOom@infosec.pub 3 points 4 days ago* (last edited 4 days ago)

I think the correct answer is that your device shouldn't suggest you to have a weak password work around, it should suggest a stronger password

[-] curbstickle@anarchist.nexus 3 points 4 days ago

'Or' not 'and'. Fingerprint replaces the password for access.

A bandaid would simply be removed. No you can't just say "no". A password is protected though.

this post was submitted on 02 Aug 2026
266 points (100.0% liked)

Cybersecurity

10403 readers
231 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 3 years ago
MODERATORS