124
you are viewing a single comment's thread
view the rest of the comments
[-] ricecake@sh.itjust.works 10 points 6 hours ago

Why?

It's not like they're literally using your face or fingerprint as a password. They're not even storing them, just a hash tied to an hsm key.

[-] No1@aussie.zone 3 points 4 hours ago

When I rob you, I hold the phone up to your face to unlock it, then I cut off your finger to use it on your banking and crypto apps to transfer all your money.

/s

[-] twjolson@lemmy.world 12 points 6 hours ago

I can't speak for OP, but in the US, you can be compelled to unlock a phone via fingerprint or face ID. You can't be compelled to give over your PIN. That violates the right against self incriminating.

[-] deliriousdreams@fedia.io 1 points 2 hours ago

Which means it's not secure against the authorities but probably is secure against the average thief and or snooping younger sibling/spouse. So, your threat profile and the use of biometrics/vs password may vary.

[-] twjolson@lemmy.world 1 points 2 hours ago

Definitely not. The average thief can get you to unlock it with your face or finger far easier than get your PIN.

[-] deliriousdreams@fedia.io 1 points 2 hours ago

Doubtful. The average thief isn't robbing you at gunpoint. They grab the phone out of your hand and book it.

But even if they did stick around for that, most people use a 4 number pin and that's basically just as easy as face or fingerprint unlock. Its an additional maybe 2 seconds.

If they can force you to put your finger on the sensor they can force you to give them the pin.

[-] Viceversa@lemmy.world 1 points 3 hours ago

You can't be compelled to give over your PIN. That violates the right against self incriminating.

Is that valid only to USA citizens or foreigners can use that trick too?

[-] deliriousdreams@fedia.io 2 points 2 hours ago

It's valid for anyone visiting the US. Even if they do so illegally. Its a right given by the constitution and it's amendments and those apply to everyone in the US. Importantly, people often forget that the Constitution isn't a limiting document for the people. It's a limiting document for the government.

[-] ricecake@sh.itjust.works 4 points 6 hours ago

Totally true. That's not the common threat most people need to guard against however. Additionally, at least on Android, the device is relatively eager to force pin usage if the stars don't align for biometrics

[-] 0x0@infosec.pub 3 points 6 hours ago

Almost any user are much more likely to encounter a situation where their biometrics are forced and not their password. Passing a border for example.

Biometrics should never be used instead of a password, only as usernames. A password can be changed, your thumbs can't.

[-] ricecake@sh.itjust.works 4 points 3 hours ago* (last edited 3 hours ago)

Have you ever had your phone searched by the police or at the border? I haven't, but I have had someone try to unlock my phone before.

I'd contend most people have a threat model that puts opportunistic access by household members or someone watching them enter their passcode and then snatching the phone and running above border patrol search.

While you can't change your biometrics, walk me through why that matters. I'm not sharing my biometrics outside of the device, and you can't submit them remotely, so if you lift a print off of something it doesn't really get you much without also taking the phone. Once you're there, you're a bit beyond the typical phone thief in terms of threat.

The most common vulnerability is having an absurdly weak password, pin or unlock pattern. For those people biometrics is a vast improvement specifically because it's both secure against likely threats, and it's just as easy as hitting 5 four times in a row.

Every method has trade offs, and there's nothing to gain by pretending otherwise. Likewise, I don't think I would ever say "never use something", except for some contrived examples.

[-] Viceversa@lemmy.world 2 points 3 hours ago* (last edited 3 hours ago)

Almost any user are much more likely to encounter a situation where their biometrics are forced and not their password. Passing a border for example.

That's valid only for americans. And even then: how many of them are crossing country borders regularly?

this post was submitted on 02 Aug 2026
124 points (93.7% liked)

Cybersecurity

10375 readers
283 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 3 years ago
MODERATORS