Fingerprints are a nice way to keep almost everyone out of your device. And for the rest, well, I really doubt some other locking mechanism would've kept them out.
Fingerprints are a nice way to keep almost everyone out of your device. And for the rest, well, I really doubt some other locking mechanism would've kept them out.
One theft isn't practical? How about a million? Driven by a never-ending pursuit of monetary gain via crime; with criminals always happy to conquer the latest technology wave. There's absolutely no reason to think that criminals won't amass substantial finger print records just like they do any other intimate information they can get their hands on, from SS numbers to passwords. It's not a question of if, but when this starts becoming common.
All it requires is linking finger prints to something valuable at a mass market scale, and that will drive an unlimited criminal demand for finger prints.
It's not about the iPhone. It's about a consumer shift to finger prints as a primary security feature, and whether that is sane (with the iPhone potentially setting the trend given its cultural status).
> It's about a consumer shift to finger prints as a primary
> security feature
No. It's about shift from zero security (no passcode lock) to some security (fingerprint). Yes it can be fooled but it is effective enough to stop casual attacks. Just like lock on the most doors — no problem for a determined robber but good enough protection from the opportunistic thief.Now, in that world, what will criminals use the fake fingerprints for?
The CCC could have used a stray fingerprint (say on a glass or the phone itself) but didn't. I suspect they would have demo'd that if they could have made it work reliably or even at all.
Your slippery slope argument seems faith-based and doesn't answer the big questions I posed above. I don't see Samsung or Moto going fingerprints anytime soon - and if they do, Apple is there with patented tech waiting to sue them if it's at all similar. Widely varying implementations of the same thing with possibly different exploit angles - does that seem like a security epidemic to you?
Most of us don't live in a James Bond movie.
(1) If someone has my fingerprints they still need my phone to do anything.
(2) Even with my phone there's a good chance it's worthless unless they also have my pin.
(3) Stealing my phone has also become worth much less unless you have my prints and the followthrough to make fake ones and again they'll want my pin in most cases because you only get 5 failed attempts with your fake prints.
(4) All of that takes time, during which I may be able to remote wipe my phone, making the whole exercise worth even less. And it takes money, again lowering potential returns.
It's easy to imagine (numbers pulled out of ass) that a thief could get a few hundred bucks for a 5C (no touch id) but say half that for the more expensive 5S. Maybe that won't hold up for various reasons (hey thieves will work hard to make those stolen 5s's worth more) but the principle behind multi-factor is sound.
It would probably take a few tries, but seems well within a person-sized budget.
It's cute. Honestly I don't see what this adds over face unlock which is reasonably mature now and equally yawnworthy IMHO.
Face unlock is very fast - generally I turn device towards me to start using it and face unlock has unlocked it before I even realise it was locked (less than half a second).
When it fails to recognise you, you can enter a pin/password/pattern. There is a menu option to 'Improve Matches' so it can pick up whatever is different this time. Every release has improved dramatically. After my most recent Android reinstall I recall only ever improving matches once.
It doesn't work in low light which fingerprints will.
I know that Picasa's face detection works even if I am wearing sunglasses... thats the only reason I ask.
He asks: "I don't see what this adds over face unlock."
I answer: "You can use Touch ID to buy things."
If the fingerprint is the identification that is used to then trigger decryption of securely stored data, it's a lot less secure of a mechanism than a fingerprint AND a password.
There was a good recent discussion that fingerprints also do not enjoy the same protection as passwords, as the fingerprint is not a "content of your mind". Here's the wired article on this: http://www.wired.com/opinion/2013/09/the-unexpected-result-o...
It was also discussed at length on HN, but I can't find the thread.
I agree that the touchID shouldn't be used for authentication with everything and I think Apple agrees, which is why they haven't opened it up to 3rd party developers.
I'd suggest that someone would just access the data storage, bypassing the fingerprint mechanism.
I can think of some examples:
* jealous spouses who want to look at call logs, emails, text histories
* unscrupulous managers looking to see if you've been talking to headhunters, competitors, etc.
* stalker coworkers who are looking for "private selfies"
* frenemies who want to post inflammatory messages using one of your social media accounts
Keep in mind that if these criminals can't figure it out by googling it, they will give up and move on. The typical phone thief isn't a security expert with the knowledge to invent a previously unknown exploit.