• Bytemeister@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        22 hours ago

        Cops in the US are notoriously narrow minded and lazy. They aren’t going to try 10000 PINs to get into your phone during a stop, and most phones will lock up or rate limit after enough failed attempts.

        • deliriousdreams@fedia.io
          link
          fedilink
          arrow-up
          1
          ·
          15 hours ago

          Right. But you’ll note that that laziness extends to Border Control in a very specific way.

          They are not limited by time in the same way that the regular cops are. They can detain you indefinitely. They don’t need to get your pin when they can call Google and request access to your phone’s contents.

          The only reason they tried the pin at all with the one guy was because they assumed he was giving a pin that was correct.

      • curbstickle@anarchist.nexus
        link
        fedilink
        English
        arrow-up
        4
        ·
        2 days ago

        Compared to guaranteed success, a weak password is superior.

        Youre comparing a weak password to no password here and suggesting no password is better.

        • deliriousdreams@fedia.io
          link
          fedilink
          arrow-up
          2
          arrow-down
          2
          ·
          1 day ago

          I’m not. I have never seen a device that can be set up without a password or pin in addition to face or fingerprint unlock.

          You have to have both.

          • curbstickle@anarchist.nexus
            link
            fedilink
            English
            arrow-up
            3
            ·
            edit-2
            1 day ago

            Once the biometrics are there, it replaces the pin/password in most scenarios I can think of.

            Cell phone access, logging into a PC, etc.

            Setting up both doesn’t mean that both are required for access.

            Biometrics can be compelled (forced). So face or fingerprint can be forced, making them irrelevant to security - the same as no password.

            • ricecake@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              1
              ·
              1 day ago

              I’m on a relatively boring android phone and biometrics are only available in circumstances where it’s already vaguely confident it’s you.
              Miss the fingerprint reader by too much? It’s now a pin unlock. Haven’t used pin recently enough? No biometrics.

              It’s pretty far from being replaced, considering I seem to need to use the pin on the lock screen several times a day at least.

            • deliriousdreams@fedia.io
              link
              fedilink
              arrow-up
              2
              ·
              1 day ago

              https://immpolicytracking.org/policies/ice-notice-of-intent-to-award-contract-to-cellebrite-for-smartphone-hacking-technology/

              When you go through a border crossing or go to do something that might get you on the RADAR of a police or government entity, just wipe your phone or carry a burner.

              They are looking to bypass pretty much any security you use at that point so for that threat profile and the security required to safeguard you, a password will not be sufficient and you are not going to win.

              I’m not advocating for or against passwords here. I’m pointing out that A/. you can lockdown the device with key presses to make it require a password, some devices will require a password to be entered at certain intervals and when a device is restarted, and the only time you’d really need to worry about this is when dealing with law enforcement. At which point it’s likely that your particular threat profile would require you to forego biometrics entirely.

              But it’s still not the same as no password. There’s still a barrier, but you can be coerced to remove that barrier.

              If you don’t think they can force you to give up a pin or password, i would point you to the sheer number of incarcerated people who actually have been proven innocent who admitted to a crime because the police coerced a confession.

              • curbstickle@anarchist.nexus
                link
                fedilink
                English
                arrow-up
                2
                ·
                1 day ago

                Coercion <> compelled.

                You can be forcibly restrained, and have your face or hand forcibly used to unlock and its completely legal.

                And while I completely agree a burner is a better choice, it has precisely zero bearing on a discussion about specifically biometrics, police, and privacy in the context of the US.

                • deliriousdreams@fedia.io
                  link
                  fedilink
                  arrow-up
                  2
                  ·
                  1 day ago

                  It has every single thing to do with the bearing of this conversation.

                  If the police tried to use biometrics to search my device today they would find exactly nothing.

                  On the average person’s phone they likely wouldn’t find much that’s actionable in a legal sense.

                  The average person has a threat profile where it’s much more likely that they would worry about a snooping parent, sibling, or significant other, or even coworkers over the police.

                  That is who biometrics are for.

                  For anyone else who has a threat profile that should require them to be worried about police intervention or investigation of any kind, there’s either a burner phone or a hardened OS and both of those use cases and the people using them likely aren’t using biometrics. But that doesn’t mean they have a good password either. People aim for convenience and less friction.

                  So let’s think about what I am arguing here. I am arguing that a burner phone with nothing on it is likely more useful to a person worried about the police getting access to their device than a pin or password is. And that even if you do have a password there is likely a way for them to bypass it or there will be in the future.

                  You are arguing that even a weak password is better than biometrics, but that is in a singular instance where you are detained by or investigated by the police, and in that event you probably have a threat profile that would require more than just a password lock for your devices. Especially if you’re using a weak password.

                  • curbstickle@anarchist.nexus
                    link
                    fedilink
                    English
                    arrow-up
                    2
                    arrow-down
                    2
                    ·
                    1 day ago

                    It has every single thing to do with the bearing of this conversation

                    See the OP.

                    It does not.

                    If the police tried to use biometrics to search my device today they would find exactly nothing.

                    Entirely separate from weak password vs no password (biometrics).

                    On the average person’s phone they likely wouldn’t find much that’s actionable in a legal sense.

                    Bad take.

                    Laws are poorly written, sometimes intentionally, to make them more vague.

                    I guarantee you can get arrested for something if they really want to.

                    That is who biometrics are for.

                    People who don’t want to use a password, and it will functionally behave like you don’t have any sort of restriction on your data. Yes. Agreed. Biometrics provide absolutely zero protection, as said.

                    For anyone else who has a threat profile that should require them to be worried about police intervention or investigation of any kind

                    In reality, everyone, see above.

                    there’s either a burner phone or a hardened OS

                    Separate from and entirely irrelevant to a discussion about biometrics and passwords.

                    So let’s think about what I am arguing here.

                    I have been. I’m not sure that you have, and I don’t mean that to sound like a dick, I’m saying I think you are severely underestimating the issue.

                    But that doesn’t mean they have a good password either.

                    Biometrics provide functionally zero password. That’d be the context here. A weak password is better than no password. A strong password is better than no password.

                    As biometrics means functionally no password, any password is superior.

                    You are arguing that even a weak password is better than biometrics

                    Yes, because it means no password is required at all. Even a weak password is better than no password.

                    but that is in a singular instance where you are detained by or investigated by the police

                    The context of this entire discussion. Yes.

                    and in that even you probably have a threat profile

                    Everyone. See above.

                    would require more than just a password lock for your devices. Especially if you’re using a weak password.

                    As in not biometrics, because biometrics are the same as no password. Yes.

                • atrielienz@lemmy.world
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  1 day ago

                  That’s not though?!

                  At least I’m assuming there’s a difference between wiping a device in preparation to go to a border crossing and wiping a device while in police custody/being detained for further screening by Border Patrol.

                  • queermunist she/her@lemmy.ml
                    link
                    fedilink
                    English
                    arrow-up
                    1
                    ·
                    1 day ago

                    We’ll see. This court decision will determine if distress codes are destruction of evidence, which is different, but I don’t think it’s much of a stretch to think they’d extend that to wiping your phone before traveling too. Why not? They hate you.

                    The only real defense would be having a burner, it’d break too many things to make it illegal.