266
top 50 comments
sorted by: hot top controversial new old
[-] mp3@lemmy.ca 93 points 3 days ago

As soon as the word "convenient" is used, you know it will affect security.

[-] hades@feddit.uk 34 points 3 days ago

Yep, they technically didn’t claim it was to make it more secure.

[-] athatet@lemmy.zip 3 points 2 days ago

The fact that it’s under the security tab means they technically DID.

load more comments (1 replies)
[-] NaibofTabr@infosec.pub 16 points 3 days ago

This is always the tradeoff. Security must always impose a cost.

[-] ricecake@sh.itjust.works 10 points 3 days ago

Why do you think that? Public key authentication systems are invariably more secure, and a wide variety are also simpler for the end user to use.

It's a misconception that they are in opposition to each other. Why would they be? One's about knowing who's doing something and the other is about how much effort it takes to do it.

[-] davidgro@lemmy.world 14 points 3 days ago

Because in general, making things more difficult for an adverse party has great potential for also having side effects for proper users. And conversely, making things easier for proper users very often also makes it easier for adversaries.

You're right that it's not a strict 100% rule, but it's so common a pattern that keeping it in mind when making security decisions (to avoid fulfilling it or at least weigh risks) is a good practice.

load more comments (2 replies)
[-] neatchee@piefed.social 17 points 3 days ago* (last edited 2 days ago)

This has big "don't use a standard deadbolt on your front door; it's not as strong as reinforced titanium doors with time-release locks" energy

Like, not technically wrong, but does not fit the standard risk profile, it's overkill for most situations.

Also to everyone talking about US law enforcement, this is just so easy to protect from, not worth ditching biometrics: if you see cops approaching and are worried about a device being unlocked, just reboot it. If you need to do it surreptitiously, just hold the power button to force shut it off after ~10s. This will always require a password to unlock after

[-] CubitOom@infosec.pub 6 points 2 days ago* (last edited 2 days ago)

In this analogy, it would be more like a PSA to not use the deadbolt, and to make it more convenient to get in and out, just leave your backdoor unlocked. Then if you see someone walking up, you can simply lock your backdoor.

A password is a standard feature on phones, nothing to install. Avoiding biometrics is simply avoiding a bad practice.

[-] schipelblorp@sh.itjust.works 7 points 2 days ago

People used to use a PIN to get into their phones. Those are obnxiously easy to shoulder surf. A fingerprint is much better in any situation where you can't be compelled to give it.

[-] neatchee@piefed.social 4 points 2 days ago* (last edited 2 days ago)

You've misunderstood my analogy.

Most people don't need the strongest form of protection. It's about risk profile.

Also biometrics don't replace passwords. They supplement them. They allow certain features to be accessible with reduced security, if that fits your risk profile, while maintaining the high security of passwords for specific functionality.

[-] CubitOom@infosec.pub 4 points 2 days ago

I haven't misunderstood anything.

Biometrics is a compromise between security and convenience. It is a bad practice for anyone actually concerned with their security, and who values security over convenience.

You can use biometrics if you want. However, if you are going to craft analogies, try to depict the situation more accurately.

[-] neatchee@piefed.social 11 points 2 days ago

The analogy is perfectly accurate.

An imperfect, simpler form of security vs a higher, more cumbersome form of security.

Where is the problem with that analogy?

Biometrics are not "bad practice for anyone concerned about security". They are one type of security that is sufficient and effective for certain risk profiles but not others. Users should make informed decisions based on their needs and the features of the security implementations they are considering.

Your hyperbole is, in fact, dangerous as it pushes people who do not understand security to blindly accept policies that are not good for their risk profile. We have proof that proper usage of biometrics is more consistent with end-users than proper usage of passwords. It's not just about convenience. It's also about adoption and proper compliance.

Absolutist policies and positions like yours do harm. Just look at how NIST recommendations have moved away from things like frequent password change enforcement because it leads to bad behavior (writing down passwords, etc)

[-] Rooster326@programming.dev 4 points 2 days ago

Okay and if you don't see the cops approaching? Because they use undercover cars, dress in plain clothes, and won't identify to anyone on demand? Yes even federal agents?

[-] neatchee@piefed.social 4 points 2 days ago

Again it's about risk profile. if you believe there is a chance that will happen to you, then go ahead.

Personally I just turn my personal phone off when approaching a border or attending a rally and that covers me. I'm not really worried about getting mugged from behind by a federal agent.

[-] nixukty@lemmy.zip 10 points 3 days ago

Do you really not use your phones fingerprint reader and type in your passcode every time?

I get that you can be compelled by law enforcement to give up your biometrics, but if you're gonna end up in that sort of situation it's 2 buttons and a tap to temporarily disable biometrics.

[-] CubitOom@infosec.pub 8 points 2 days ago

Yes, strong password and no biometrics is basic security practice.

[-] Appoxo@lemmy.dbzer0.com 2 points 2 days ago* (last edited 2 days ago)

The grid pattern is way better than any password in terms of reasonable password lengths

[-] cantstopthesignal@sh.itjust.works 8 points 2 days ago* (last edited 2 days ago)

Do you really not use your phones fingerprint reader and type in your passcode every time?

Yes, yes I do. I like having friction between me and my addictive distraction rectangle.

[-] LordCrom@lemmy.world 2 points 2 days ago

Yes, I type in a password each time.

load more comments (2 replies)
[-] ricecake@sh.itjust.works 22 points 3 days ago

Why?

It's not like they're literally using your face or fingerprint as a password. They're not even storing them, just a hash tied to an hsm key.

[-] twjolson@lemmy.world 26 points 3 days ago

I can't speak for OP, but in the US, you can be compelled to unlock a phone via fingerprint or face ID. You can't be compelled to give over your PIN. That violates the right against self incriminating.

[-] ricecake@sh.itjust.works 13 points 3 days ago

Totally true. That's not the common threat most people need to guard against however. Additionally, at least on Android, the device is relatively eager to force pin usage if the stars don't align for biometrics

[-] 0x0@infosec.pub 10 points 3 days ago

Almost any user are much more likely to encounter a situation where their biometrics are forced and not their password. Passing a border for example.

Biometrics should never be used instead of a password, only as usernames. A password can be changed, your thumbs can't.

[-] ricecake@sh.itjust.works 9 points 3 days ago* (last edited 3 days ago)

Have you ever had your phone searched by the police or at the border? I haven't, but I have had someone try to unlock my phone before.

I'd contend most people have a threat model that puts opportunistic access by household members or someone watching them enter their passcode and then snatching the phone and running above border patrol search.

While you can't change your biometrics, walk me through why that matters. I'm not sharing my biometrics outside of the device, and you can't submit them remotely, so if you lift a print off of something it doesn't really get you much without also taking the phone. Once you're there, you're a bit beyond the typical phone thief in terms of threat.

The most common vulnerability is having an absurdly weak password, pin or unlock pattern. For those people biometrics is a vast improvement specifically because it's both secure against likely threats, and it's just as easy as hitting 5 four times in a row.

Every method has trade offs, and there's nothing to gain by pretending otherwise. Likewise, I don't think I would ever say "never use something", except for some contrived examples.

[-] atrielienz@lemmy.world 2 points 2 days ago

I love this "in the US" thing. Like we're the only country where that's true and there aren't whole European countries doing the exact same thing.

While I admit nothing exists in a vacuum and there's a lot of push toward a police state in the US, we also aren't the only country doing that, by far. We're just more open about it since Cheeto in Chief took office again.

[-] twjolson@lemmy.world 3 points 2 days ago

Or maybe I don't have knowledge and experience in EU law and didn't want to pretend I do.

load more comments (5 replies)
[-] picnic@lemmy.dbzer0.com 3 points 2 days ago

I travel a few times a month to US, China, Hong Kong etc.

I shut down my grapheneos phone on the border. Graphene also allows you to set auto reboot to phone if unlocked from 10mins to like 72 hours.

I do use biometrics on my device. I think its a tradeoff I'm willing to make.

load more comments (14 replies)
load more comments (1 replies)
[-] JRaccoon@discuss.tchncs.de 16 points 3 days ago

I think it depends. Some people might be inclined to use too short or simple password because they don't wanna constantly be typing a long password. It's much better to have a strong password and fingerprint/face rec for convince than just a insecure password.

[-] CubitOom@infosec.pub 17 points 3 days ago

In the USA, they can legally force you to unlock a device using biometrics.

Also, biometrics can be fooled in other ways.

load more comments (10 replies)
[-] GamingChairModel@lemmy.world 7 points 3 days ago

The other underappreciated threat model is shoulder surfing, especially in an age of ubiquitous high resolution cameras. Punching in a numerical PIN within view of a camera potentially leaks that secret, and some high resolution cameras can even pick up letters and symbols from the on screen keyboards.

Being compelled to give biometrics doesn't do enough for an adversary (including government adversaries) to do everything with a phone, the way having the password or PIN does, and I would argue that governments would be better at tricking people into inadvertently giving up their PINs and passwords than they'd be at compelling biometrics within the time window that they still work (before the phones lockout biometrics as a valid unlocking method), or being able to do stuff to exploit extraction tools past the lock screen.

So the threat model needs to be understood for what it is.

load more comments (6 replies)
[-] DudleyMason@lemmy.ml 4 points 2 days ago

And typing in a password every time is the opposite of usability..

Hot take: biometrics are often criticized for being less secure, but that ignores the deficiencies of passwords. Especially on phones, it's very doable to look over someone's shoulder while they're unlocking their phone or do the same with a camera. You can't do that with a fingerprint, at least not nearly as easily.

And yes, I understand that in the US (amongst others?) the legal situations with passwords and biometrics are different, but IMO that's more of a legal question, and not everyone lives in the US.

Android also has an "emergency lockdown" option, which disables biometrics for unlocking your phone - or you can shut it down (worst case scenario force shut down with a long hold on the power button) to get it into a BFU state, which is much harder to crack.

load more comments (4 replies)
load more comments
view more: next ›
this post was submitted on 02 Aug 2026
266 points (100.0% liked)

Cybersecurity

10399 readers
45 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 3 years ago
MODERATORS