Pages:
Author

Topic: Apple wants to replace all passwords with biometrics (Read 368 times)

full member
Activity: 952
Merit: 105
So, if I want to share my password with someone I would need to cut my head or fingers and pass it over?  Grin

Biometrics is considered as of now slightly less secure than other methods of protection, I would not like to loose my user / pass access, old style, that, until now, has given me zero problems other than an occasional need to reset the passwords and the like.
If apple makes it a rule - than obviously people will do it.
But I am not sure why would they want to go to biometric since that might not be possible for the other regions. However may be in coming future they manage to do it.
legendary
Activity: 2310
Merit: 1598
Do not die for Putin
So, if I want to share my password with someone I would need to cut my head or fingers and pass it over?  Grin

Biometrics is considered as of now slightly less secure than other methods of protection, I would not like to loose my user / pass access, old style, that, until now, has given me zero problems other than an occasional need to reset the passwords and the like.
hero member
Activity: 1792
Merit: 507

Apple invests a ton into cybersecurity R&D but no system is impenetrable. Biometrics being stored locally isn't enough if someone were to get hold of the device (ie law enforcement) and bypass any security measures. I wouldn't be concerned about the ordinary person who doesn't have the resources to bypass Apple's own security measures -- law enforcement could probably seek legal avenues to have biometrics scrapped from the device, forcing Apple to cooperate.
These technical inventions are good but than to implement them globally is not an easy task. My office started a project of an app - that was huge problem implementing it in other country because of the change in the systems. Maybe in near future this issue will get resolved but not in the near future.
legendary
Activity: 2828
Merit: 1514
Governments can get a warrant through the judicial system and physically force you to give up your thumb print to unlock a device. Face ID would work the same way. They're not safe for the user.

I wonder how they plan to make the system secure against malware and similar attacks. I'd assume maybe a separate chip would be the best way to go with this but that might eat into their profits so they'll probably find a way that's less secure but still robust against attackers (eg a space away from where a normal user or app would be able to access).

I'd be surprised if this hasn't already been attempted or already been done with this already, I think this technology could be made more secure if an nfc card was also used to offer an extra key to decrypt the password database (eg the main encryption key as you won't get much with that alone - they can also likely already be made more secure as bank cards have already had to be).

Apple invests a ton into cybersecurity R&D but no system is impenetrable. Biometrics being stored locally isn't enough if someone were to get hold of the device (ie law enforcement) and bypass any security measures. I wouldn't be concerned about the ordinary person who doesn't have the resources to bypass Apple's own security measures -- law enforcement could probably seek legal avenues to have biometrics scrapped from the device, forcing Apple to cooperate.
hero member
Activity: 2114
Merit: 618
With improving technology each day I am sure they will improve and will be in a state where they give zero errors. However I feel there is a bigger threat with biometrics kicking in which is sensitivity of our data. This is giving our facial metrics info and fingerprint scans to a private body, who we don't know what will do with this data point? Today it's not that difficult to fabricate a false fingerprint On a crime scene but I am pretty sure same won't be the case 10 years from now.
legendary
Activity: 2408
Merit: 1102
Leading Crypto Sports Betting & Casino Platform
I don't like and don't use Apple, but I think decisions like this should be based on the desires of users. Do the majority of users support the switch to biometrics?
I personally tend to use passwords and find it a bit unsettling when my own body is used to open things, apps and stuff like that. Also, from fingerprint lock on the phone, I know that it often doesn't read well, and it can be annoying when you need access to something but the fingerprint is read incorrectly many times. Not to mention that yes, there's plenty of hardware that doesn't have fingerprint support, so it's very elitist, like Apple always is.

I am using some apple products, it really gives a better experience than others. But I agree with the tendency to use passwords like you do, using fingerprint lock or face recognition is really convenient and fast for users. But I feel there is too much risk when someone attacks and hijacks our phones, they don't need to ask for a password, just a few simple steps of putting the phone on our face, they have can be unlocked easily. I am using an old iphone with fingerprint lock function but for the most part I prefer to use passwords for my important apps.
legendary
Activity: 1722
Merit: 5937
Attempting to replace passwords with fingerprints && facial recognition is never going to succeed, no matter who tries. There will always be a voiceforous population using the devices that will never consent to using these methods of authentication for privacy or usability reasons (e.g. what happens when you're wearing gloves during winter, or sunglasses), and since Apple is the one implementing this, it's guarranteed to fail because they never look beyond their own product ecosystem.
Hah, I wish I share your optimism. The one thing I know about people is that majority will always choose convenience over safety and I already see people all around me using fingerprint scanner instead passwords whenever they can, and the only reason why it hasn't spread more is because its mostly reserved to more expensive mobile phones&laptops  and other tech but soon enough it will spread to lower end and then everyone will use it.


Maybe they get a few million people to use it, but nobody is going to be able to not only force websites to implement such an authentication BUT SIMULTANEOUSLY force users to change their passwords at the same time.
These things don't happen overnight, they are playing the long game.

legendary
Activity: 3234
Merit: 1399
Join the world-leading crypto sportsbook NOW!
I don't like and don't use Apple, but I think decisions like this should be based on the desires of users. Do the majority of users support the switch to biometrics?
I personally tend to use passwords and find it a bit unsettling when my own body is used to open things, apps and stuff like that. Also, from fingerprint lock on the phone, I know that it often doesn't read well, and it can be annoying when you need access to something but the fingerprint is read incorrectly many times. Not to mention that yes, there's plenty of hardware that doesn't have fingerprint support, so it's very elitist, like Apple always is.
hero member
Activity: 1764
Merit: 696
[Nope]No hype delivers more than hope
What makes Apple customers confident that they can even protect themselves? especially when they are carrying their device in a semi-conscious state due to the influence of drugs and alcohol at a party, biometrics are even easier to hack imo. Instead of learning hacking techniques, you just need to learn basic pharmacy science to anesthetize Apple users.

Now with AI technology can replicate a person's face that is close to the original.
sr. member
Activity: 1890
Merit: 252
The OGz Club
I think it's Simple and secure by describing the Password Lock technology. A passkey increases your security by eliminating the need to store and use passwords. That's a good thing because passwords are notoriously insecure. Many people use phrases that are easy to remember and can be guessed easily. So what Apple has done is an incremental act of upgrading, then hackers will be harder to break into
What Apple has done we need to appreciate and indeed there have been many cases of security using compromised passwords,
sometimes when we use phrases that are difficult to guess, things like that still happen because hackers are also very skilled at doing that
legendary
Activity: 1568
Merit: 6660
bitcoincleanup.com / bitmixlist.org
...So how does it work? Passkeys replace your tired old passwords by creating new digital keys using Touch ID or Face ID, Apples vice president of internet technologies, Darin Adler, explained at WWDC. When you are creating an online account with a website, you can use a Passkey instead of a password. To create a Passkey, just use Touch ID or Face ID to authenticate, and youre done, Adler said...

One word is enough to summarize this proposal: HA!

Attempting to replace passwords with fingerprints && facial recognition is never going to succeed, no matter who tries. There will always be a voiceforous population using the devices that will never consent to using these methods of authentication for privacy or usability reasons (e.g. what happens when you're wearing gloves during winter, or sunglasses), and since Apple is the one implementing this, it's guarranteed to fail because they never look beyond their own product ecosystem.

Maybe they get a few million people to use it, but nobody is going to be able to not only force websites to implement such an authentication BUT SIMULTANEOUSLY force users to change their passwords at the same time.

Talk about a fighter jet that's blown up before it even takes off... Roll Eyes




You want true alternatives to passwords, at least for desktop logins? Then use an adapation of SSH, a proven method of authentication (no-one has ever been able to crack a 4096-bit RSA key yet). Adapt it by putting them on USB sticks, memory cards, and other portable media with a special filesystem. Then when the device is inserted into the computer, the OS automatically sees the private key, and mashes it against the public key and authenticates you.

For added security, use modifications of seed phrases or diceware as a secondary login method, where the user can input 8-12 words words from a fixed bank of 10,000 or so words that users are advised to write down and store in a safe place like a wallet (yes this will make this login method vulnerable to theft, but it makes the most prevalent method of break-ins - remote brute-forcing - impossible! Smiley)


Last method can be ported to mobile devices, and so can the first one if such a standard is adapted to authenticate using a Bluetooth private key authentication device as well! (Just hold the device anywhere near the lock screen while pressing a certain "Authenticate" button on the key device.)
sr. member
Activity: 2492
Merit: 277
Hire Bitcointalk Camp. Manager @ r7promotions.com
Biometric security actually sucks, recently I watched a video in the YouTube not sure about the device they used but it is recently launched and successful so probably Samsung if I am not wrong. While scanning the finger print in the first place we need to scan multiple times atleast 5 before setting up the finger print so they decided to scan five people's thumb for the one finger print but the result is five people managed to unlock the device with only one finger print setup.

So its less secure than passwords so don't go for it and I don't think they will enforce it completely to go with only biometric security system for their devices.
legendary
Activity: 1162
Merit: 2025
Leading Crypto Sports Betting & Casino Platform
Btw
Would you be okey using biometrics to lock-unlock your personal devices if your data were localy stored instead in custody of a big tech company?
_______________________________________________________________________________ _
-snip-

Privacy concerns aside, people would most likely use this feature simply because it's far easier to use and the fact that the typical person doesn't need to remember passwords. This is the main reason why these companies win a lot of users while privacy freaks are very low in population — simply because these companies know how to nail UI/UX.

That is part of the essence of human advance through history, after all: seeking comfort and ease. I'd dare to say that in the end, science and engineering ultimate goal is to put laws of the universe at the service of humanity to make our short lifespan as comfortable as possible, of course this is the ideal point of view, we know there are hidden interests and wishes for massive profits.

What i am trying to say is that Apple knows that anything that makes users lifes at least a lil bit easier has a high chance to succeed, even though, people ignore they are giving up part of their identity in exchange of saving a few seconds to type a password/use two factor authentication.

hero member
Activity: 1288
Merit: 504
What is wrong with these guys @Apple, that a user chooses what is secure for him or her and it happens to be 12344 or 123456789, what then is there concerns about it. Should they go "*÷€÷&fsjvcak÷*÷^:÷fdgebrova&"$×( only to forget it Immediately after they've created it? They ought to live users to decide what is convenient for them. Bes the know, they are offering the service and users makes use of it the way that suits best with them.

Biometrics isn't a 100% as there could be fowl play and some smarty pants will surely come up with ways to cheat the system which I think, would be all too easy compared to password combinations. Apple uses mainly passcode in place of password, they should ensure proper passwords that are supposed to be Alphanumeric.
copper member
Activity: 2856
Merit: 3071
https://bit.ly/387FXHi lightning theory
I wonder how they plan to make the system secure against malware and similar attacks.

Isnt their system already secure enough? I havent read any news about Apple biometrics being hacked. I remember there were few cases when Apple added face id in 2017. But that these cases were exceptions and in most cases, people did not figure out till the end how system works and raised panic. Right now, Apple biometrics systems looks like most secure. If a user sets face ID security or a password, even Apple cant crack it.

I think there's less of an incentive to hack the current biometrics used though (unless you mean by bypassing them - and I think there are still vulnerabilities that are found in their login process, a 6 digit pin in fairly easy to crack though if you've got another device to host the bruteforce attack - I don't think it's possible to use biometrics as soon as you turn on most devices for example and with apple, you can't use biometrics if you've held down the power button for a long enough time to end up on the confirm shutdown screen).

Being able to get access to every account somenoe has is a lot more useful to an attacker than gaining biometric info.

full member
Activity: 994
Merit: 105
I think it's Simple and secure by describing the Password Lock technology. A passkey increases your security by eliminating the need to store and use passwords. That's a good thing because passwords are notoriously insecure. Many people use phrases that are easy to remember and can be guessed easily. So what Apple has done is an incremental act of upgrading, then hackers will be harder to break into
full member
Activity: 616
Merit: 100
Despite of biometrics solutions being better than passwords, they are still vulnerable to theft of data, the biometric information can be stolen.
I'd rather an approach where people started to use universal small cryptographic devices which would work in a similar way Trezor T does to login through U2F, maybe even combine both approaches to harden the security of the accounts.

In the end, we can change our passwords but we cannot change our fingerprints, our iris or face so easily...
Indeed, it is enough that once your biometric data falls into the hands of scammers, and this is where your privacy will end. I'd rather change my password than give my biometrics to some scammer. And I'm not one of those people who put passwords like 12345 and so on. Crazy people. 
hero member
Activity: 2884
Merit: 794
I am terrible at Fantasy Football!!!
This should succeed in the future since this is the only solution to secure accounts compared to using a password that is vulnerable to any attacks like phishing, brute-force attacks and etc...

Biometrics is already been tested for many years not just on Apple devices but also on Android devices. I have my phone not apple but Samsung the Iris scanner for my pattern or passwords looks the best Biometrics that I have ever experienced.
 
But I hope they don't totally remove the password login because if the owner or a user accidentally has a broken/missing finger or had scars on their face they can't easily access their account and it may become an unrecoverable account.

So owners/users should still have an alternative way to log in like passwords or recovery seed for emergency cases.
Without a doubt those which have no problems with a private company having all their biometric information or that are not worried about such information getting leaked are free to use a service like that, however the issue is that now it seems passwords are not going to be an option in the future, when passwords have many advantages, not only they can be incredibly secure you can use a lot of them which means that if one account is compromised you only lose whatever was in that account and not everything as it will be the case with biometrics.
member
Activity: 1232
Merit: 12
Security issues are increasing because more and more data theft, this has become the most important thing for many companies so that various ways are done to ensure data security, what Apple is actually doing is not the first idea, because I've heard many companies have ideas for security, namely by biometrics for PIN or password.
sr. member
Activity: 2366
Merit: 448
Reward: 10M Sheen (Approx. 5000 BNB) Bounty
Biometrics are just as effective as passwords, but for security there are special features like those found in Apple's biometric sensors. That is, it will not work if the subject dies.
and the mechanism can be said to be difficult, there is a weak current sensor that distinguishes living and dead body tissues. What is clear, surely the price of research and production is expensive.
If commonly used biometrics are relied on as privacy protections, then the vulnerability of crime increases, perpetrators could cut a finger or kill to forcibly unlock on condition that the account holder refuses to log in although it is unlikely, but reasonable if possible. something.
and on the other hand it is very dangerous in terms of cybersecurity, because if our data is hacked then hackers can ensure the validity of our data very accurately because biometric login and lock out activities can only be carried out by the subject recognized by the device.
There will be good and bad sides depending on who uses it whether it is important or not and whether we have to keep something valuable in it.
Pages:
Jump to: