While two factor auth is probably overkill for just unlocking a device to many people, I would like to at least have the option.
One of my concerns is that if your device is ever taken by an organization that has the ability to command your fingerprints then they can quite easily unlock your device negating any encryption.
Also while I think its unlikely right now for criminals to make fake fingerprints in order to steal financial transactions, its a flaw and ApplePay is going to financially motivate those criminals to look into ways to refine the process and make it easier to do.
Two-factor authentication would need to rely upon a much more reliable criteria than Touch ID.
Also while we are on the subject using a short pincode to unlock the device is asking for trouble. While the device ID is tied to the decryption and there is no way to extract it yet I have no confidence that it will remain that way forever. At which point the ability to crack a short pin off the device means the pin will get cracked in seconds.
In both cases, the phone will require a passphrase for unlocking (if you configure one as opposed to just a simple code, of course).
Having a really long passphrase and the ability to very quickly render the fingerprint reader useless is a huge improvement in security over previous touchid-less phones.
Having to both type a code and using my fingerprint (in that case, in addition to a very long passphrase, which would be difficult to explain to users how that works) would be very annoying, at least for me.
In fact, if you look at one of the cracking tools that law enforcement is known to use [1], iOS8 looks to have made things more difficult:
"iOS 8
Currently under version 4.0 Advanced logical extraction will extract less data compare to previous iOS versions."
[1] http://releases.cellebrite.com/releases/ufed-release-notes-4...
Short period of time - touchid to unlock. Medium period of time (adjustable) - touchID+Pin Long period of time - (adjustable) - passcode
Different people could set the values as appropriate. For me, it would be < 5 minutes touch ID, < 1 hours touchID+Pin, > 1 hours passcode.
The nice thing is iOS 8 seems to encourage people to use alphanumeric passcodes by default. This is a big change. I guess they're pushing people to touchid primary, complex passphrase backup, vs. making touchid or numeric passcode the same.
EDIT: Oops, that's not right — the PIN by itself (or in conjunction with TouchID) still has that property. I meant it the other way around: Apple probably wants to make sure that the TouchID sensor is reliable enough to never lock people out, because if even one person has that problem, they won't be able to recover their data. Right now, the PIN is a failsafe; with TouchID/PIN, if TouchID fails, there isn't one.
The objective should be PIN+fpr for routine use, and a longer password when that doesn't work (or on system boot). I'd be fine with PIN || fpr sometimes when it's even lower risk (e.g. when connected to your home wifi).
I agree that its only likely as a targeted attack though. This isn't the sort of thing you will see street criminals doing.
A skilled person or organization yes. Obtaining the latent prints probably isn't the hard part, I imagine stealing someones trash would be enough for that.
The tricky part is making a clone accurate and detailed enough that it works in less than 6 attempts.