Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yeah just fingerprint means someone could use your finger to unlock the phone while you're asleep in a cell / drugged / restrained / knocked out.


/ in the morgue


OK everyone, walk back from that ledge. Someone with the resources and motiviation to drug/kidnap/kill/amputate to get access to a biometric scan is going to be well-equipped just to steal the device and read the flash out via JTAG.

Screen locks do not provide meaningful security vs. a determined attacker, and never will no matter what the unlock mechanism is. Unless you encrypt all storage with a strong password (not a 6-digit PIN) and a good PBKDF, all you get from this stuff is protection against casual snooping.


Or it's just the cops, and unlike a password or pin or pattern, they can actually physically force your authentication out of you with a single finger press.


Theoretically you can do some liveness checks (work better on retina/iris than on fingerprint), but basically everything related to fingerprints is easy to forge outright, let alone making a dead man's finger appear live.


You're all assuming the finger is still attached to the rest of the body.


Every time fingerprint scanners are mentioned, people start talking about cutting off fingers. Guess what: the people making the scanners have considered this scenario. All of their clients have nagged them about it continously for decades. It's fun to talk about, but it won't work.


It'll work fine if the scanner isn't fancy enough to include "live finger" detection tech like matching the veins beneath the skin's surface (https://en.wikipedia.org/wiki/Finger_Vein_recognition).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: