you are viewing a single comment's thread
view the rest of the comments
[–] 36 points 2 years ago (8 children)

So, it really depends on your personal threat model.

For background: the biometric data doesn't leave the device, it uses an on-device recognition system to either unlock the device, or to gain access to a hardware security module that uses very strong cryptography for authentication.

Most people aren't defending against an attacker who has access to them and their device at the same time, they're defending against someone who has either the device or neither.

The hardware security module effectively eliminates the remote attacker when used with either biometric or PIN.
For the stolen or lost phone attack, biometric is slightly more secure, but it's moot because of the pin existing for fallback.

The biggest security advantage the biometrics have to offer is that they're very hard to forget, and very easy to use.
Ease of use means more people are likely to adopt the security features using that hardware security module provides, and that's what's really dialing up the security.

Passwords are most people's biggest vulnerability.

  • source
  • parent
  • hideshow 8 child comments
  • [+] 1 point 2 years ago (7 children)
  • [–] 6 points 2 years ago (2 children)

    While I do respect that viewpoint, there's a lot more independent scrutiny of the hardware modules than there are around the parts that would handle any other authentication mechanism you might use.

    Pixel phone example iPhone example

    Just because something isn't perfect doesn't mean we should keep using the less good thing that it replaces.

    Use the PIN if that's more your cup of tea, just so long as you move away from passwords, since it's the HSM that's the protection, not the biometrics. Those are just to make it easier than passwords.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 4 points 2 years ago (3 children)

    If you're that afraid if the people who build phones, why are you ok with using any device that can access the internet?

  • source
  • parent
  • hideshow 3 child comments
  • [+] 0 points 2 years ago (2 children)
  • [–] 1 point 2 years ago*

    You should be more worried about your local doctor's office contracting some cheap-ass company to handle your data and ending up in a branch than being concerned about biometrics.

    Or hell, Experian had that insane breach of basically everyone's information years ago. Biometrics are not the problem, it's smaller companies that you have to deal with all the time skimping on security because they think they can't afford it.

    And then companies even more shady than Google and Apple and Samsung (loan companies, health systems contractors, banks, credit card companies, insurance companies) have all your data and are more likely to be involved in a data breach.

  • source
  • parent