Hacker News new | ask | show | jobs
by Cider9986 14 days ago
I appreciate there is still some stigma around facial-recognition in the U.S. I will not visit the U.K. until they fix their shit.

I've always been fine using Face ID or Touch ID because it's stored on device, but I'm curious if normies using it know that or they're okay with their biometrics being sent off their device.

2 comments

I've never understood why anyone would be comfortable with Face ID or Touch ID given all the possible attacks. Just use a PIN. You'll end up knowing it as a kinesthetic reflexive action anyways.
On GrapheneOS you can use a long passphrase for your primary unlock which you have to enter after a restart and for changing important settings, and a fingerprint+pin for 2fa as the secondary unlock. This is a great balance imo.
There were arguments against biometric authentication when touchID was added. It removes any plausible deniability that it wasn't you using the device.
To obtain plausible deniability you would have to take immense steps and need specific knowledge like using gloves and avoiding surveillance cameras, so I don't think anyone that is going for that would be affected by the option to use biometrics.