• CubitOom@infosec.pubOP
    link
    fedilink
    English
    arrow-up
    17
    ·
    3 天前

    In the USA, they can legally force you to unlock a device using biometrics.

    Also, biometrics can be fooled in other ways.

    • JRaccoon@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      8
      ·
      3 天前

      Yes, but that’s besides the point. If the convenient options for a normie user are

      • Having a weak password
      • Having a strong password and a fingerprint

      Out of those the fingerprint with a strong password is way better option, imo.

      In the USA, they can legally force you to unlock a device using biometrics.

      Also, how does that work? Can’t they legally force you to enter your password too? Or can you claim you don’t remember it? If that works, can’t you just have a band-aid on your finger or something? Surely they cannot force you to take it off and risk getting an infection on the large wound you just happened to get yesterday…?

        • JRaccoon@discuss.tchncs.de
          link
          fedilink
          English
          arrow-up
          2
          ·
          2 天前

          Haha, reading some of the responses in this thread actually reminded me of that xkcd but I couldn’t immediately find it. Thanks!

      • queermunist she/her@lemmy.ml
        link
        fedilink
        English
        arrow-up
        17
        ·
        3 天前

        Also, how does that work? Can’t they legally force you to enter your password too?

        No, because forcing someone to enter a password is “compelled speech” and against the 1st Amendment. It’s also testimonial, which means compelling that speech would also be self incrimination, which is against the 5th Amendment.

        Don’t ask me why forcing someone to make a hand gesture is not also compelled speech and not testimonial. The Constitution is mostly nonsense being interpreted by life appointed morons who interpret things however they like.

        • Viceversa@lemmy.world
          link
          fedilink
          English
          arrow-up
          4
          ·
          3 天前

          Constitution is mostly nonsense being interpreted by life appointed morons who interpret things however they like.

          Bible / Quran, is that you?

      • 0x0@infosec.pub
        link
        fedilink
        English
        arrow-up
        10
        arrow-down
        1
        ·
        3 天前

        A normal user will most likely never encounter a situation where their weak password would be at risk, but are much more likely to having their biometrics forced by law enforcement or border control.

        They will rip your bandaid off and force your finger or face to scan while holding your device.

        Any weak password at all would have been better in a situation like that.

        • JRaccoon@discuss.tchncs.de
          link
          fedilink
          English
          arrow-up
          5
          ·
          3 天前

          Oh wow, things really have gotten bad over there. For me personally, the much greater risk is that I forget my phone somewhere or someone steals it and in that scenario a weak password is the larger issue.

          It seems there isn’t a single correct answer here. The threat model is different for everyone.

          • CubitOom@infosec.pubOP
            link
            fedilink
            English
            arrow-up
            4
            ·
            3 天前

            I think the correct answer is that your device shouldn’t suggest you to have a weak password work around, it should suggest a stronger password

              • Bytemeister@lemmy.world
                link
                fedilink
                English
                arrow-up
                2
                ·
                2 天前

                Cops in the US are notoriously narrow minded and lazy. They aren’t going to try 10000 PINs to get into your phone during a stop, and most phones will lock up or rate limit after enough failed attempts.

                • deliriousdreams@fedia.io
                  link
                  fedilink
                  arrow-up
                  1
                  ·
                  2 天前

                  Right. But you’ll note that that laziness extends to Border Control in a very specific way.

                  They are not limited by time in the same way that the regular cops are. They can detain you indefinitely. They don’t need to get your pin when they can call Google and request access to your phone’s contents.

                  The only reason they tried the pin at all with the one guy was because they assumed he was giving a pin that was correct.

              • curbstickle@anarchist.nexus
                link
                fedilink
                English
                arrow-up
                4
                ·
                3 天前

                Compared to guaranteed success, a weak password is superior.

                Youre comparing a weak password to no password here and suggesting no password is better.

                • deliriousdreams@fedia.io
                  link
                  fedilink
                  arrow-up
                  2
                  arrow-down
                  2
                  ·
                  3 天前

                  I’m not. I have never seen a device that can be set up without a password or pin in addition to face or fingerprint unlock.

                  You have to have both.

                  • curbstickle@anarchist.nexus
                    link
                    fedilink
                    English
                    arrow-up
                    3
                    ·
                    edit-2
                    3 天前

                    Once the biometrics are there, it replaces the pin/password in most scenarios I can think of.

                    Cell phone access, logging into a PC, etc.

                    Setting up both doesn’t mean that both are required for access.

                    Biometrics can be compelled (forced). So face or fingerprint can be forced, making them irrelevant to security - the same as no password.

      • curbstickle@anarchist.nexus
        link
        fedilink
        English
        arrow-up
        4
        ·
        3 天前

        ‘Or’ not ‘and’. Fingerprint replaces the password for access.

        A bandaid would simply be removed. No you can’t just say “no”. A password is protected though.

    • boonhet@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      3
      ·
      2 天前

      Ah just don’t go to the USA or don’t take a device with information on it there.

    • GamingChairModel@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      3 天前

      Law enforcement can legally trick you into giving up your password, too, and that’s full access right there. Having an unlocked phone but no password isn’t enough to get into certain parts of the core system/security settings, and trying to get into those will prompt a password anyway (and that generally gatekeeps the access to the phone through a physical connector plugged into the port).

      Neither pathway is perfect but I think for real world usage and real world adversaries (not just law enforcement, but also criminal thieves/scammers/hackers, and governmental adversaries that aren’t bound by legal limits, like foreign intelligence agencies), it’s better to have biometrics so that you are physically punching in your PIN/password much less frequently. Especially on modern systems that get spooked easily and require a password anyway when the phone has been idle too long or when the wrong face looks at it too many times.