To secure a device you need a password.
Basics: something you are (iris scan, fingerprint), something you have (2fa token, usb unlock key), something you know (password).
One out of 3 is probably not very secure.
To secure a device you need a password.
Basics: something you are (iris scan, fingerprint), something you have (2fa token, usb unlock key), something you know (password).
One out of 3 is probably not very secure.
Iris scanning or fingerprints are easy for determined attacker, but I would say they are hard for somebody who just grabs your phone. Vice versa for the pin code.
I think a good balance between security and usability would be to allow fingerprint or iris scan when the phone has been constantly in my proximity but require a pin (password) if the phone is taken away. The proximity could be determined for example by pairing the phone with smart watch.
Should be significantly more secure than Mifare though. Ideally something like a contactless OpenGPG card or similar.
Recently I searched for passive NFC ICs that'd be suitable for implementing that, but came up empty. Usecase was exactly that: A NFC device located at about the wrist. My laptop has a NFC reader at just the right place of the handrest to read it. And I'd probably transplant a NFC reader into my desktop computer's keyboard for the same purpose.
But first I'd need that NFC thingy.
Just found this also in my search while typing this comment.
Looks like it might be open source as well?
https://github.com/mclear/NFC_Ring_Control
Might be something to keep check on, it supposedly doesn't release until mid 2017.
EDIT: Just thought about if this is open source, anyone could possibly tie it in with automation apps such as Tasker and really do neat stuff.
Quoting GP: I think a good balance between security and usability would be to allow fingerprint or iris scan when the phone has been constantly in my proximity but require a pin (password) if the phone is taken away. The proximity could be determined for example by pairing the phone with smart watch.
When combined with a fingerprint sensor, smart lock keeps the device completely unlocked while "triggered" (by being on-body, or close to a trusted BT device, etc), and the fingerprint unlocks it while not triggered. It doesn't ever escalate to requiring the pin/password/pattern. Please correct me if I'm wrong, because I'd like to be.
Definitely not a perfect system. I wish that I could set timeouts and map the power button to do an admin lock. Also, having to use a 3rd party app for this is quite likely its own threat vector.
[1] https://play.google.com/store/apps/details?id=com.katecca.sc...
I'd love to have features where the fingerprint is only good enough under certain circumstances, such when the phone hasn't been idle for too long, or when combined with an RFID tag.
I'm glad it's not every few hours because my iPhone password is quite long.
Why complicate things with 2fa tokens. Something you have: the phone! However I agree with something you know being missing.
And unless you regularly leave you phone lying around, you'll realize this is pretty much a requirement for breaking into your phone anyway.
Something you have: phone
You can't log in remotely with an iris or fingerprint.