this post was submitted on 02 Aug 2026
182 points (92.5% liked)

Cybersecurity

10390 readers
376 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 3 years ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments
[–] 0x0@infosec.pub 7 points 21 hours ago* (last edited 21 hours ago) (2 children)

A normal user will most likely never encounter a situation where their weak password would be at risk, but are much more likely to having their biometrics forced by law enforcement or border control.

They will rip your bandaid off and force your finger or face to scan while holding your device.

Any weak password at all would have been better in a situation like that.

[–] Viceversa@lemmy.world 3 points 19 hours ago (1 children)

Any weak password at all would have been better in a situation like that.

How?

[–] curbstickle@anarchist.nexus 2 points 18 hours ago (1 children)

You can't be compelled to give up your password.

[–] deliriousdreams@fedia.io 1 points 18 hours ago (2 children)

A weak password they can guess.

[–] Bytemeister@lemmy.world 1 points 4 hours ago

Cops in the US are notoriously narrow minded and lazy. They aren't going to try 10000 PINs to get into your phone during a stop, and most phones will lock up or rate limit after enough failed attempts.

[–] curbstickle@anarchist.nexus 3 points 18 hours ago* (last edited 18 hours ago) (1 children)

Compared to guaranteed success, a weak password is superior.

Youre comparing a weak password to no password here and suggesting no password is better.

[–] deliriousdreams@fedia.io 1 points 18 hours ago (1 children)

I'm not. I have never seen a device that can be set up without a password or pin in addition to face or fingerprint unlock.

You have to have both.

[–] curbstickle@anarchist.nexus 2 points 17 hours ago* (last edited 17 hours ago) (2 children)

Once the biometrics are there, it replaces the pin/password in most scenarios I can think of.

Cell phone access, logging into a PC, etc.

Setting up both doesn't mean that both are required for access.

Biometrics can be compelled (forced). So face or fingerprint can be forced, making them irrelevant to security - the same as no password.

[–] ricecake@sh.itjust.works 1 points 13 hours ago

I'm on a relatively boring android phone and biometrics are only available in circumstances where it's already vaguely confident it's you.
Miss the fingerprint reader by too much? It's now a pin unlock. Haven't used pin recently enough? No biometrics.

It's pretty far from being replaced, considering I seem to need to use the pin on the lock screen several times a day at least.

[–] deliriousdreams@fedia.io 1 points 17 hours ago (2 children)

https://immpolicytracking.org/policies/ice-notice-of-intent-to-award-contract-to-cellebrite-for-smartphone-hacking-technology/

When you go through a border crossing or go to do something that might get you on the RADAR of a police or government entity, just wipe your phone or carry a burner.

They are looking to bypass pretty much any security you use at that point so for that threat profile and the security required to safeguard you, a password will not be sufficient and you are not going to win.

I'm not advocating for or against passwords here. I'm pointing out that A/. you can lockdown the device with key presses to make it require a password, some devices will require a password to be entered at certain intervals and when a device is restarted, and the only time you'd really need to worry about this is when dealing with law enforcement. At which point it's likely that your particular threat profile would require you to forego biometrics entirely.

But it's still not the same as no password. There's still a barrier, but you can be coerced to remove that barrier.

If you don't think they can force you to give up a pin or password, i would point you to the sheer number of incarcerated people who actually have been proven innocent who admitted to a crime because the police coerced a confession.

[–] curbstickle@anarchist.nexus 2 points 17 hours ago (1 children)

Coercion <> compelled.

You can be forcibly restrained, and have your face or hand forcibly used to unlock and its completely legal.

And while I completely agree a burner is a better choice, it has precisely zero bearing on a discussion about specifically biometrics, police, and privacy in the context of the US.

[–] deliriousdreams@fedia.io 2 points 17 hours ago (1 children)

It has every single thing to do with the bearing of this conversation.

If the police tried to use biometrics to search my device today they would find exactly nothing.

On the average person's phone they likely wouldn't find much that's actionable in a legal sense.

The average person has a threat profile where it's much more likely that they would worry about a snooping parent, sibling, or significant other, or even coworkers over the police.

That is who biometrics are for.

For anyone else who has a threat profile that should require them to be worried about police intervention or investigation of any kind, there's either a burner phone or a hardened OS and both of those use cases and the people using them likely aren't using biometrics. But that doesn't mean they have a good password either. People aim for convenience and less friction.

So let's think about what I am arguing here. I am arguing that a burner phone with nothing on it is likely more useful to a person worried about the police getting access to their device than a pin or password is. And that even if you do have a password there is likely a way for them to bypass it or there will be in the future.

You are arguing that even a weak password is better than biometrics, but that is in a singular instance where you are detained by or investigated by the police, and in that event you probably have a threat profile that would require more than just a password lock for your devices. Especially if you're using a weak password.

[–] curbstickle@anarchist.nexus 0 points 17 hours ago (1 children)

It has every single thing to do with the bearing of this conversation

See the OP.

It does not.

If the police tried to use biometrics to search my device today they would find exactly nothing.

Entirely separate from weak password vs no password (biometrics).

On the average person's phone they likely wouldn't find much that's actionable in a legal sense.

Bad take.

Laws are poorly written, sometimes intentionally, to make them more vague.

I guarantee you can get arrested for something if they really want to.

That is who biometrics are for.

People who don't want to use a password, and it will functionally behave like you don't have any sort of restriction on your data. Yes. Agreed. Biometrics provide absolutely zero protection, as said.

For anyone else who has a threat profile that should require them to be worried about police intervention or investigation of any kind

In reality, everyone, see above.

there's either a burner phone or a hardened OS

Separate from and entirely irrelevant to a discussion about biometrics and passwords.

So let's think about what I am arguing here.

I have been. I'm not sure that you have, and I don't mean that to sound like a dick, I'm saying I think you are severely underestimating the issue.

But that doesn't mean they have a good password either.

Biometrics provide functionally zero password. That'd be the context here. A weak password is better than no password. A strong password is better than no password.

As biometrics means functionally no password, any password is superior.

You are arguing that even a weak password is better than biometrics

Yes, because it means no password is required at all. Even a weak password is better than no password.

but that is in a singular instance where you are detained by or investigated by the police

The context of this entire discussion. Yes.

and in that even you probably have a threat profile

Everyone. See above.

would require more than just a password lock for your devices. Especially if you're using a weak password.

As in not biometrics, because biometrics are the same as no password. Yes.

[–] deliriousdreams@fedia.io 2 points 17 hours ago (1 children)

I'm not responding the post. I'm responding specifically to your comment (where you did not give context but made a definitive statement). That's on you.

You can't be compelled to give up your password.

OP IS USING A GOOGLE ACCOUNT WITH GOOGLES BIOMETRICS BEING SUGGESTED TO THEM.

The police will bypass you to get that data and Google will likely give it to them without a subpoena. And even if they don't, it's likely that given the state of the justice system in this country they will be able to subpoena that information anyway, assuming they don't just break into your phone (see link I posted in this comment thread a few comments back).

Laws are poorly written, sometimes intentionally, to make them more vague.

I guarantee you can get arrested for something if they really want to.

They will do this with or without access to your device and it will more than likely be with access regardless of what kind of security you use.

Separate from and entirely irrelevant to a discussion about biometrics and passwords.

You haven't explained how.

I have been. I'm not sure that you have, and I don't mean that to sound like a dick, I'm saying I think you are severely underestimating the issue.

Clearly not.

Biometrics provide functionally zero password. That'd be the context here. A weak password is better than no password. A strong password is better than no password.

Nope. You clearly didn't read the entirety of what I said, but I guess I'll explain. If I'm not using a password my behavior on that device reflects that. Often meaning I'm not logged into anything, clear browser history and don't download anything. That's basically a burner phone at the point. Because there is no expectation of privacy or security.

As biometrics means functionally no password, any password is superior.

I can tell you didn't click the link. False sense of security ahoy!

Yes, because it means no password is required at all. Even a weak password is better than no password.

A person who isn't using a password does not have the expectation that their device is secure. A person using a password has the expectation that their device is secured, but with a weak password that doesn't mean it actually is. Biometrics mean that your device is secure against the average individual (because you know, that's what locks are for, to keep honest people honest).

The context of this entire discussion. Yes.

And in that event you can force Android and IOS devices to require a password. So biometrics wouldn't allow them to force you to use biometrics to unlock the device.

Everyone. See above.

Not everyone. Most Americans never leave the country. EVEN when you consider international airports, most Americans don't fly regularly and even if they did, see my above comments about burner phones because (see my above comments about brute forcing devices or subpoenaing the data on those devices) that's pretty much the only way to be sure.

As in not biometrics, because biometrics are the same as no password. Yes.

You keep saying that word but I don't think you know what it means.

If you had said using biometrics is like using a TSA approved luggage lock I might be inclined to agree with you. But what you said was that "you can be compelled to give up biometrics to unlock your device) and what I said was, a weak password is not better.

You can continue to argue but you seem to keep missing context here. A weak password is what most people use. That's why there's a top 1000 passwords in use news article every couple of years.

Your birthday or anniversary is not better than biometrics. Say whatever else you want here. You haven't actually proven a point but I'm over it.

[–] curbstickle@anarchist.nexus 1 points 16 hours ago* (last edited 16 hours ago)

I'm not responding the post. I'm responding specifically to your comment (where you did not give context but made a definitive statement). That's on you.

Which is part of a thread with context.

OP IS USING A GOOGLE ACCOUNT WITH GOOGLES BIOMETRICS BEING SUGGESTED TO THEM.

The police will bypass you to get that data and Google will likely give it to them without a subpoena.

Still requires way more than making you look toward a screen or holding your finger onto part of one.

Also takes a lot more time than grabbing you and forcing it.

Also requires google to provide it without a subpoena.

You really think thats somehow easier than biometrics for them?

See the OP.

It does not.

I really dont understand how you can come to that conclusion that for "biometrics make it less secure given what we know is protected and what is not".

You keep saying that word but I don't think you know what it means.

Quite confidently, I do. And its clearer and clearer that you just aren't thinking this through.

If you had said using biometrics is like using a TSA approved luggage lock I might be inclined to agree with you. But what you said was that "you can be compelled to give up biometrics to unlock your device) and what I said was, a weak password is not better.

And again, no password is in no way better than a weak password.

What are you having trouble with here?

You can continue to argue but you seem to keep missing context here.

Clearly, thats not an issue for me. You seem confused about the most basic part of this.

A weak password is what most people use. That's why there's a top 1000 passwords in use news article every couple of years.

Do you really think the idiots stopping you on a sidewalk or at an airport or in your car are aware for the most common passwords? Or that being brought to a police station and put under a full investigation is the only way this can happen?

[Spoiler]
Its not.

Your birthday or anniversary is not better than biometrics. Say whatever else you want here.

See previous comment. In every way, shape, and form it requires more time, effort, and knowledge than immediately forcing you to unlock your phone by showing it at your face or restraining you and grabbing your finger.

In what possible way could it not?

You haven't actually proven a point but I'm over it.

Repeatedly. I'd recommend reading again, because you are missing the incredibly obvious and I don't understand how you could be missing any of it.

[–] queermunist@lemmy.ml 1 points 16 hours ago (1 children)

just wipe your phone

They're testing that in court right now. That might be "destruction of evidence" after all.

[–] atrielienz@lemmy.world 1 points 16 hours ago (1 children)

That's not though?!

At least I'm assuming there's a difference between wiping a device in preparation to go to a border crossing and wiping a device while in police custody/being detained for further screening by Border Patrol.

[–] queermunist@lemmy.ml 1 points 15 hours ago* (last edited 15 hours ago) (1 children)

We'll see. This court decision will determine if distress codes are destruction of evidence, which is different, but I don't think it's much of a stretch to think they'd extend that to wiping your phone before traveling too. Why not? They hate you.

The only real defense would be having a burner, it'd break too many things to make it illegal.

[–] atrielienz@lemmy.world 1 points 15 hours ago

The only reason it's considered destruction of evidence is because he was "allegedly" under investigation.

I think what the other guy is saying is when you are traveling, wiping your device before you go to the airport, rather than doing so once you are essentially in custody.

I think it was stupid to give the distress pin when Graphene is already hardened unless he had something specific he was looking to hide, but I also recognize that ICE don't need a warranty to search you and they can keep you indefinitely. So the other guy is also probably right that cops have a lot of time and resources. A password isn't a good lock.

I also think nobody has thought about the fact that they want people to think that they have something to hide. They want us to be afraid. I think this drama about biometrics is a really good example. Scare people away from biometrics. Scare people away from Graphene OS. Leave us in the hands of tech corps who will hand over whatever they ask for.

[–] JRaccoon@discuss.tchncs.de 3 points 21 hours ago (1 children)

Oh wow, things really have gotten bad over there. For me personally, the much greater risk is that I forget my phone somewhere or someone steals it and in that scenario a weak password is the larger issue.

It seems there isn't a single correct answer here. The threat model is different for everyone.

[–] CubitOom@infosec.pub 2 points 19 hours ago* (last edited 19 hours ago)

I think the correct answer is that your device shouldn't suggest you to have a weak password work around, it should suggest a stronger password