• fyf@lemmy.world
    link
    fedilink
    English
    arrow-up
    23
    ·
    1 day ago

    I can’t speak for OP, but in the US, you can be compelled to unlock a phone via fingerprint or face ID. You can’t be compelled to give over your PIN. That violates the right against self incriminating.

    • atrielienz@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 hours ago

      I love this “in the US” thing. Like we’re the only country where that’s true and there aren’t whole European countries doing the exact same thing.

      While I admit nothing exists in a vacuum and there’s a lot of push toward a police state in the US, we also aren’t the only country doing that, by far. We’re just more open about it since Cheeto in Chief took office again.

      • fyf@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        2 hours ago

        Or maybe I don’t have knowledge and experience in EU law and didn’t want to pretend I do.

        • atrielienz@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          54 minutes ago

          It’s not just you. There’s quite a few people who keep saying this. You’ll note that they don’t chime in to mention that Norway or Germany.

          It’s dystopian as fuck that this is where we’re at, but I don’t think it’s a good idea to pretend this is strictly a US thing.

    • picnic@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      3
      ·
      9 hours ago

      I travel a few times a month to US, China, Hong Kong etc.

      I shut down my grapheneos phone on the border. Graphene also allows you to set auto reboot to phone if unlocked from 10mins to like 72 hours.

      I do use biometrics on my device. I think its a tradeoff I’m willing to make.

    • ricecake@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      12
      ·
      1 day ago

      Totally true. That’s not the common threat most people need to guard against however. Additionally, at least on Android, the device is relatively eager to force pin usage if the stars don’t align for biometrics

      • 0x0@infosec.pub
        link
        fedilink
        English
        arrow-up
        9
        arrow-down
        5
        ·
        1 day ago

        Almost any user are much more likely to encounter a situation where their biometrics are forced and not their password. Passing a border for example.

        Biometrics should never be used instead of a password, only as usernames. A password can be changed, your thumbs can’t.

        • ricecake@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          8
          ·
          1 day ago

          Have you ever had your phone searched by the police or at the border? I haven’t, but I have had someone try to unlock my phone before.

          I’d contend most people have a threat model that puts opportunistic access by household members or someone watching them enter their passcode and then snatching the phone and running above border patrol search.

          While you can’t change your biometrics, walk me through why that matters. I’m not sharing my biometrics outside of the device, and you can’t submit them remotely, so if you lift a print off of something it doesn’t really get you much without also taking the phone. Once you’re there, you’re a bit beyond the typical phone thief in terms of threat.

          The most common vulnerability is having an absurdly weak password, pin or unlock pattern. For those people biometrics is a vast improvement specifically because it’s both secure against likely threats, and it’s just as easy as hitting 5 four times in a row.

          Every method has trade offs, and there’s nothing to gain by pretending otherwise. Likewise, I don’t think I would ever say “never use something”, except for some contrived examples.

        • Viceversa@lemmy.world
          link
          fedilink
          English
          arrow-up
          6
          arrow-down
          1
          ·
          edit-2
          1 day ago

          Almost any user are much more likely to encounter a situation where their biometrics are forced and not their password. Passing a border for example.

          That’s valid only for americans. And even then: how many of them are crossing country borders regularly?

    • deliriousdreams@fedia.io
      link
      fedilink
      arrow-up
      3
      ·
      1 day ago

      Which means it’s not secure against the authorities but probably is secure against the average thief and or snooping younger sibling/spouse. So, your threat profile and the use of biometrics/vs password may vary.

      • fyf@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        1
        ·
        1 day ago

        Definitely not. The average thief can get you to unlock it with your face or finger far easier than get your PIN.

        • ricecake@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          6
          ·
          20 hours ago

          If you point a weapon at me in a way that would compel me to help you unlock my phone with fingerprint or face unlock, I promise you it would not be any harder for you to get me to unlock the device with the pin.

          • fyf@lemmy.world
            link
            fedilink
            English
            arrow-up
            4
            arrow-down
            1
            ·
            13 hours ago

            You assume that you are conscious, or even alive in your scenario.

            • ricecake@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              3
              ·
              12 hours ago

              If I’m not alive I don’t really care if they get the contents of my phone. My survivors can go through the same process I would for reversing a fraudulent transaction.

              And you’re picturing a criminal subduing me and then just crouching over my body and figuring out what financial apps I have and how to use them?
              What’s their game plan here? Most stolen phones are resold, not used to access their contents.

        • deliriousdreams@fedia.io
          link
          fedilink
          arrow-up
          2
          ·
          1 day ago

          Doubtful. The average thief isn’t robbing you at gunpoint. They grab the phone out of your hand and book it.

          But even if they did stick around for that, most people use a 4 number pin and that’s basically just as easy as face or fingerprint unlock. Its an additional maybe 2 seconds.

          If they can force you to put your finger on the sensor they can force you to give them the pin.

          • fyf@lemmy.world
            link
            fedilink
            English
            arrow-up
            4
            arrow-down
            1
            ·
            13 hours ago

            Do any phones even allow 4 digit Pins? Apple doesn’t, and my Samsung doesn’t.

            No one can force you to give up the PIN. They can threaten, and you may give in to that threat. But that isn’t forcing, that isn’t against your will.

            But, a criminal can get you to unlock your phone with biometrics against your will easily enough - brute strength, render you unconscious, or even dead.

            • ricecake@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              3
              arrow-down
              1
              ·
              12 hours ago

              No one can force you to give up the PIN. They can threaten, and you may give in to that threat. But that isn’t forcing, that isn’t against your will.

              That’s called force, and against your will.

              That’s just fundamentally not understanding how the terms work. A coerced action, or one taken under duress, is not taken of ones own free will.

              https://www.law.cornell.edu/wex/duress

              • fyf@lemmy.world
                link
                fedilink
                English
                arrow-up
                2
                arrow-down
                1
                ·
                8 hours ago

                My comment was in reply to another saying a bad guy can force you to put your finger on the unlock sensor. There is no equivalent for pins.

                They can threaten, yes, and you can give into that threat. Yes, that would be against your will, but it still requires you to acquiesce or cooperate was my point. The can’t get the pin without you giving it.

                • ricecake@sh.itjust.works
                  link
                  fedilink
                  English
                  arrow-up
                  2
                  ·
                  8 hours ago

                  Yeah, and if you’re being robbed they’ll probably fuck you up pretty badly if you don’t. While not mind readers, they don’t have to be.

                  In most cases anyone who wants to beat your pin will just watch you unlock your phone. They don’t need to see the exact numbers: you can pick most of it up just based on relative finger motion. Looking at screen smudges gives another set of hints that are pretty trivial to extract.

                  If your goal is to keep it from the police, your best bet is to use an entirely different system than rely on your phones lock screen.

                  I can’t think of a scenario where I’m thinking both “biometrics are insufficient to safeguard this data” and “it’s appropriate to keep this data on my telephone”.

                  • fyf@lemmy.world
                    link
                    fedilink
                    English
                    arrow-up
                    1
                    ·
                    6 hours ago

                    You aren’t wrong, but this discussion is mostly about edge cases. The average person, yea, they won’t have anything that is end of their world if a bad guy accesses it. But, that does mean there aren’t many phones that contain significantly more important data than you have.

            • deliriousdreams@fedia.io
              link
              fedilink
              arrow-up
              1
              ·
              11 hours ago

              My pixel allows a 4 digit pin. Mine is 7 digits but I also don’t use biometrics.

              Just had a look and it’s Face/Fingerprint/Pin/Swipe/Pattern/Password.

    • Viceversa@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 day ago

      You can’t be compelled to give over your PIN. That violates the right against self incriminating.

      Is that valid only to USA citizens or foreigners can use that trick too?

      • Bytemeister@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        11 hours ago

        Take this with a grain of salt, considering the actions of the current administration…

        But the US Constitution doesn’t make that many distinctions between citizens and non-citizens, especially in the bill of rights, where most individual protections are laid out. The 4th amendment protects you from unwarranted search and seizure, and makes no restrictions based on nationality.

        There are some “exceptions” to the 4th amendment, but those specifically have to do with protecting the borders and inspecting imports and exports. IMHO, those exceptions should be unconstitutional, but I’m not a bought and paid for SC justice, so fuck my opinion.

      • deliriousdreams@fedia.io
        link
        fedilink
        arrow-up
        3
        ·
        1 day ago

        It’s valid for anyone visiting the US. Even if they do so illegally. Its a right given by the constitution and it’s amendments and those apply to everyone in the US. Importantly, people often forget that the Constitution isn’t a limiting document for the people. It’s a limiting document for the government.