My bank emailed me the other day with an announcement that I could access my account through their app via my fingerprint. WTF? My text messages are one thing by now my money is protected by just my fingerprint? I took my bank to task because they allowed my username to be twice as long as the allowed characters in my password. Someone at the bank said, "Hey, all these new-fangled phones have fingerprint readers, why don't we tap into that and sell it as a feature?" When everyone is doing it, no one is going to stop and ask if they should, it's just a race to incorporate the newest features. Normal people aren't asking if this is secure, they are buying into the marketing copy pushed on them, so they start thinking that it has to be secure, because why would my bank not have my interests in mind?
Otherwise the data is still there in the plain, accessible by anyone who can read the flash.
Android 5 has full disk encryption but was disabled by default on the Nexus 5 (and most other phones) due to performance issues.
I didn't notice any mention of those, specially because they failed miserably last year parading full disk encryption on Nexus 6 and got bitten when reviews showed the performance degradation and lack of hardware encryption.
If it's not, then Google are starting to take the piss..
http://www.theguardian.com/technology/2015/sep/23/us-governm...
I think this misses the point. Accessing a device using a "cloned finger" (not tremendously difficult) can be done without the target ever knowing it has happened.
The wrench technique, less so.
Whyever not? They might have a copy of it lying around. http://www.theguardian.com/technology/2015/sep/23/us-governm...
> Yes, but is it worth spending the required resources?
When it becomes easy - and it will become easy, there's nothing basically hard about printing out some ridged plastic - it will become commonplace. And unlike stolen passwords, an attacker can be fairly sure that you haven't changed your fingers.
There's a legal difference in some places between having your phone secured by a fingerprint and a password. If your phone is secured by a password, then in some places you cannot be obliged to provide the password, but a fingerprint you can.
There was a bunch of reporting in the past few days that a Federal District Court in Pennsylvania found that Fifth Amendment rights apply to smartphone passcodes.
Random link: http://www.digitaltrends.com/mobile/why-the-government-cant-...
That same protection doesn't seem to apply to fingerprints. Random link: http://time.com/3558936/fingerprint-password-fifth-amendment...
Again, I'm not a lawyer, but that seems to be how the law falls out on that issue.
Whether that's an issue for you, personally - no idea. It might be a factor for some.
One of the neat things about encryption, historically, is that the government couldn't force decryption even if it were willing to break the law in doing so. That's why there were export controls and demands for backdoors in the '90s, and that's why there are demands for backdoors today. Fingerprint locks may mathematically involve encryption, but they don't have this property.
In my mind, the only reasons tech giants continue to force centralization on their users are PRISM and data mining. Today’s devices have sizable internal drives, so all personal data could realistically be stored and processed locally; and secure, distributed systems have been proven to work for data transfer (BitTorrent), monetary transactions (Bitcoin), message boards (Aether—sort of), and more. Hopefully solutions like Copperhead OS and Blackphone that secure our mobile devices and communication channels, respectively, make it to the mainstream.
1. Attacker sees random data.
2. Attacker knows you might be smart enough to use a plausible deniability file system.
3. Attacker starts beating you with the wrench.
At this point, there are several possibilities that could happen:
1. You give up the secret and give the attacker what he wants. The beating continues after this point, because the attacker really has no idea if you've given up the right secret.
2. You give up a fake secret and give the attacker what he thinks he wants. The beatings continue. See possibility #1.
3. You don't give up the secret and he continues beating you with the wrench anyway to try to get you to reveal the secret.
4. You're not using a plausible deniability encryption at all, and it truly is random data, and he continues to beat you with the wrench to make sure.
As you can see, the wrench doesn't give two shits about your plausible deniability.
NOW GIMME MY SHITS