TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

That Thumbprint Thing on Your Phone Is Useless Now

29 pointsby rbcabout 9 years ago

10 comments

mikeashabout 9 years ago
The one on <i>my</i> phone isn&#x27;t useless now, because my fingerprint data wasn&#x27;t stolen in the OPM breach (and nobody else has it either).<p>Even if my fingerprint data were out there, that doesn&#x27;t really help get into my phone if it&#x27;s casually stolen. The thief won&#x27;t know who I am, so they won&#x27;t know which fingerprint to try out of the millions of possibilities. They only get five attempts.<p>As always, you have to define your threat model. My phone&#x27;s fingerprint reader protects me against common thieves. It also protects me against the authorities to a pretty large extent. As long as I have the opportunity to turn my phone off beforehand (I always do this when going through customs, for example) then the fingerprint no longer works to unlock my phone. The ease of use that the fingerprint reader provides for most usage allows me to have a much stronger password on the device than I would have otherwise, so I&#x27;m pretty sure it&#x27;s a strong net gain.<p>It doesn&#x27;t protect me against a determined adversary who targets me specifically, but then I already knew that. Fingerprint authentication is far from perfect, but it&#x27;s not meant to be anything else.
评论 #11250453 未加载
gueloabout 9 years ago
No. This article is clickbait. Chinese hackers might have your fingerprint if you worked for the US government. But they don&#x27;t have your phone. If you&#x27;re a high value spy or something where the Chinese government is going to target you, steal your phone and match it with the fingerprint database you might be in trouble. Otherwise, the fingerprint+pin is still going to work great at keeping your significant other from seeing your flirty texts and your porn browsing history, or whatever.
评论 #11250365 未加载
xlaynabout 9 years ago
Somewhere here on HN I read that fingerprints are not passwords but user ids.<p>So your fingerprint authenticates you to provide your password.<p>Right now implementations are for fingerprints as passwords.
评论 #11251661 未加载
gtf21about 9 years ago
It&#x27;s unfortunate that so much emphasis has been placed on biometrics (especially fingerprints) as a security measure, more so because of their convenience which lulls users into a false sense of security.<p>Not only can biometrics not be changed, unlike a password, but they cannot be withheld from a would-be accessor in the way that a password can (until mind reading becomes a thing, that is).<p>I don&#x27;t know how true this is, but it feels like biometric authentication for consumers has sucked the oxygen out of attempts to create convenient but secure authentication that doesn&#x27;t have the same flaws (I don&#x27;t know what a potential system would be, but there have to be better alternatives). Lazy reliance on biometrics will, I think, make us all a lot less secure.
评论 #11250355 未加载
davideeabout 9 years ago
Hyperbole and extremism in info-sec publishing. Film at 11.
taneqabout 9 years ago
Fingerprints are a terrible form of authentication anyway. They&#x27;re irrevocable, and you inherently leave copies of them everywhere just by touching things (unless you take special precautions). Same goes for DNA. Biometrics just aren&#x27;t very good as shared secrets.
valineabout 9 years ago
The title should read: &quot;Thumbprint thing may be useless for authentication&quot;. There are other uses for it outside of security. I have a cydia tweak on my phone that will open different apps based on which finger I press to the home button.
评论 #11250371 未加载
abrookewoodabout 9 years ago
This is the reason you should only ever use biometric data as a replacement for your Username - NEVER as a replacement for your Password!
Finnucaneabout 9 years ago
I suppose the next step would be to see how hard it would be to lift a usable fingerprint from a stolen phone. Would that be good enough?
akmarinovabout 9 years ago
In other news - doors are useless! All someone has to do is steal your key and find your house.