Comment on Stop Using Your Face or Thumb to Unlock Your Phone

<- View Parent
ricecake@sh.itjust.works ⁨6⁩ ⁨months⁩ ago

So, it really depends on your personal threat model.

For background: the biometric data doesn’t leave the device, it uses an on-device recognition system to either unlock the device, or to gain access to a hardware security module that uses very strong cryptography for authentication.

Most people aren’t defending against an attacker who has access to them and their device at the same time, they’re defending against someone who has either the device or neither.

The hardware security module effectively eliminates the remote attacker when used with either biometric or PIN.
For the stolen or lost phone attack, biometric is slightly more secure, but it’s moot because of the pin existing for fallback.

The biggest security advantage the biometrics have to offer is that they’re very hard to forget, and very easy to use.
Ease of use means more people are likely to adopt the security features using that hardware security module provides, and that’s what’s really dialing up the security.

Passwords are most people’s biggest vulnerability.

source
Sort:hotnewtop