• neatchee@piefed.social
    link
    fedilink
    English
    arrow-up
    12
    arrow-down
    4
    ·
    edit-2
    7 hours ago

    This has big “don’t use a standard deadbolt on your front door; it’s not as strong as reinforced titanium doors with time-release locks” energy

    Like, not technically wrong, but does not fit the standard risk profile, it’s overkill for most situations.

    Also to everyone talking about US law enforcement, this is just so easy to protect from, not worth ditching biometrics: if you see cops approaching and are worried about a device being unlocked, just reboot it. If you need to do it surreptitiously, just hold the power button to force shut it off after ~10s. This will always require a password to unlock after

    • CubitOom@infosec.pubOP
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      5
      ·
      9 hours ago

      In this analogy, it would be more like a PSA to not use the deadbolt, and to make it more convenient to get in and out, just leave your backdoor unlocked. Then if you see someone walking up, you can simply lock your backdoor.

      A password is a standard feature on phones, nothing to install. Avoiding biometrics is simply avoiding a bad practice.

      • schipelblorp@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        4
        ·
        2 hours ago

        People used to use a PIN to get into their phones. Those are obnxiously easy to shoulder surf. A fingerprint is much better in any situation where you can’t be compelled to give it.

      • neatchee@piefed.social
        link
        fedilink
        English
        arrow-up
        3
        ·
        7 hours ago

        You’ve misunderstood my analogy.

        Most people don’t need the strongest form of protection. It’s about risk profile.

        Also biometrics don’t replace passwords. They supplement them. They allow certain features to be accessible with reduced security, if that fits your risk profile, while maintaining the high security of passwords for specific functionality.

        • CubitOom@infosec.pubOP
          link
          fedilink
          English
          arrow-up
          4
          arrow-down
          7
          ·
          6 hours ago

          I haven’t misunderstood anything.

          Biometrics is a compromise between security and convenience. It is a bad practice for anyone actually concerned with their security, and who values security over convenience.

          You can use biometrics if you want. However, if you are going to craft analogies, try to depict the situation more accurately.

          • neatchee@piefed.social
            link
            fedilink
            English
            arrow-up
            8
            arrow-down
            3
            ·
            5 hours ago

            The analogy is perfectly accurate.

            An imperfect, simpler form of security vs a higher, more cumbersome form of security.

            Where is the problem with that analogy?

            Biometrics are not “bad practice for anyone concerned about security”. They are one type of security that is sufficient and effective for certain risk profiles but not others. Users should make informed decisions based on their needs and the features of the security implementations they are considering.

            Your hyperbole is, in fact, dangerous as it pushes people who do not understand security to blindly accept policies that are not good for their risk profile. We have proof that proper usage of biometrics is more consistent with end-users than proper usage of passwords. It’s not just about convenience. It’s also about adoption and proper compliance.

            Absolutist policies and positions like yours do harm. Just look at how NIST recommendations have moved away from things like frequent password change enforcement because it leads to bad behavior (writing down passwords, etc)

    • Rooster326@programming.dev
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      1
      ·
      11 hours ago

      Okay and if you don’t see the cops approaching? Because they use undercover cars, dress in plain clothes, and won’t identify to anyone on demand? Yes even federal agents?

      • neatchee@piefed.social
        link
        fedilink
        English
        arrow-up
        2
        ·
        7 hours ago

        Again it’s about risk profile. if you believe there is a chance that will happen to you, then go ahead.

        Personally I just turn my personal phone off when approaching a border or attending a rally and that covers me. I’m not really worried about getting mugged from behind by a federal agent.