This has big “don’t use a standard deadbolt on your front door; it’s not as strong as reinforced titanium doors with time-release locks” energy
Like, not technically wrong, but does not fit the standard risk profile, it’s overkill for most situations.
Also to everyone talking about US law enforcement, this is just so easy to protect from, not worth ditching biometrics: if you see cops approaching and are worried about a device being unlocked, just reboot it. If you need to do it surreptitiously, just hold the power button to force shut it off after ~10s. This will always require a password to unlock after
In this analogy, it would be more like a PSA to not use the deadbolt, and to make it more convenient to get in and out, just leave your backdoor unlocked. Then if you see someone walking up, you can simply lock your backdoor.
A password is a standard feature on phones, nothing to install. Avoiding biometrics is simply avoiding a bad practice.
People used to use a PIN to get into their phones. Those are obnxiously easy to shoulder surf. A fingerprint is much better in any situation where you can’t be compelled to give it.
Most people don’t need the strongest form of protection. It’s about risk profile.
Also biometrics don’t replace passwords. They supplement them. They allow certain features to be accessible with reduced security, if that fits your risk profile, while maintaining the high security of passwords for specific functionality.
Biometrics is a compromise between security and convenience. It is a bad practice for anyone actually concerned with their security, and who values security over convenience.
You can use biometrics if you want. However, if you are going to craft analogies, try to depict the situation more accurately.
An imperfect, simpler form of security vs a higher, more cumbersome form of security.
Where is the problem with that analogy?
Biometrics are not “bad practice for anyone concerned about security”. They are one type of security that is sufficient and effective for certain risk profiles but not others. Users should make informed decisions based on their needs and the features of the security implementations they are considering.
Your hyperbole is, in fact, dangerous as it pushes people who do not understand security to blindly accept policies that are not good for their risk profile. We have proof that proper usage of biometrics is more consistent with end-users than proper usage of passwords. It’s not just about convenience. It’s also about adoption and proper compliance.
Absolutist policies and positions like yours do harm. Just look at how NIST recommendations have moved away from things like frequent password change enforcement because it leads to bad behavior (writing down passwords, etc)
Okay and if you don’t see the cops approaching? Because they use undercover cars, dress in plain clothes, and won’t identify to anyone on demand? Yes even federal agents?
Again it’s about risk profile. if you believe there is a chance that will happen to you, then go ahead.
Personally I just turn my personal phone off when approaching a border or attending a rally and that covers me. I’m not really worried about getting mugged from behind by a federal agent.
This has big “don’t use a standard deadbolt on your front door; it’s not as strong as reinforced titanium doors with time-release locks” energy
Like, not technically wrong, but does not fit the standard risk profile, it’s overkill for most situations.
Also to everyone talking about US law enforcement, this is just so easy to protect from, not worth ditching biometrics: if you see cops approaching and are worried about a device being unlocked, just reboot it. If you need to do it surreptitiously, just hold the power button to force shut it off after ~10s. This will always require a password to unlock after
In this analogy, it would be more like a PSA to not use the deadbolt, and to make it more convenient to get in and out, just leave your backdoor unlocked. Then if you see someone walking up, you can simply lock your backdoor.
A password is a standard feature on phones, nothing to install. Avoiding biometrics is simply avoiding a bad practice.
People used to use a PIN to get into their phones. Those are obnxiously easy to shoulder surf. A fingerprint is much better in any situation where you can’t be compelled to give it.
You’ve misunderstood my analogy.
Most people don’t need the strongest form of protection. It’s about risk profile.
Also biometrics don’t replace passwords. They supplement them. They allow certain features to be accessible with reduced security, if that fits your risk profile, while maintaining the high security of passwords for specific functionality.
I haven’t misunderstood anything.
Biometrics is a compromise between security and convenience. It is a bad practice for anyone actually concerned with their security, and who values security over convenience.
You can use biometrics if you want. However, if you are going to craft analogies, try to depict the situation more accurately.
The analogy is perfectly accurate.
An imperfect, simpler form of security vs a higher, more cumbersome form of security.
Where is the problem with that analogy?
Biometrics are not “bad practice for anyone concerned about security”. They are one type of security that is sufficient and effective for certain risk profiles but not others. Users should make informed decisions based on their needs and the features of the security implementations they are considering.
Your hyperbole is, in fact, dangerous as it pushes people who do not understand security to blindly accept policies that are not good for their risk profile. We have proof that proper usage of biometrics is more consistent with end-users than proper usage of passwords. It’s not just about convenience. It’s also about adoption and proper compliance.
Absolutist policies and positions like yours do harm. Just look at how NIST recommendations have moved away from things like frequent password change enforcement because it leads to bad behavior (writing down passwords, etc)
Okay and if you don’t see the cops approaching? Because they use undercover cars, dress in plain clothes, and won’t identify to anyone on demand? Yes even federal agents?
Again it’s about risk profile. if you believe there is a chance that will happen to you, then go ahead.
Personally I just turn my personal phone off when approaching a border or attending a rally and that covers me. I’m not really worried about getting mugged from behind by a federal agent.