Hacker News new | ask | show | jobs
by matthewmacleod 2785 days ago
Both of them are terrible for security.

Please stop propagating this falsehood, or at least accept that it comes with caveats. Biometric ID on Apple devices is likely to be a significant improvement for many users.

1 comments

It _always_ depends on your threat model. Most people need protection from snooping family members, or people who find your phone if you lose it. For these use cases Face/Touch ID both work great. If you are trying to secure your data from the NSA, well you have probably already lost, but by all means, turn off Face ID.
> If you are trying to secure your data from the NSA, well you have probably already lost, but by all means, turn off Face ID.

If you're trying to secure your data from the NSA, carry a flip phone and turn it off and throw it in the freezer before you have any sensitive in-person conversations. Also have all of your sensitive in-person conversations right next to a loud white noise generator (i.e. on the seashore). And memorize all of your confidential information. And always carry a highly reliable suicide method in case you get captured and interrogated.

I'm not being funny here, these are literally the precautions that people take against state-level espionage.

"for many users"

I think the OP is signaling they were already aware of the threat model point before your comment.

How do you protect against family members who have enough pictures of you to create a 3D printed model of your head [1]?

[1]: https://www.wired.co.uk/article/hackers-trick-apple-iphone-x...

> How do you protect against family members who have enough pictures of you to create a 3D printed model of your head [1]?

With therapy.

Was that ever confirmed? The article you link raises doubts about it, and I could find no followup when searching, just contemporary press.

Here's a contemporary article doubting it: https://arstechnica.com/information-technology/2017/11/hacke...

After 10 attempts it's going to wipe the phone.

Given how sensitive FaceID is I don't think this is a realistic bypass approach. Not that it was even confirmed anyway.

If they are that desperate, you’ve got bigger problems.