this post was submitted on 02 Aug 2026
168 points (92.9% liked)

Cybersecurity

10375 readers
329 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 3 years ago
MODERATORS
 
top 50 comments
sorted by: hot top controversial new old
[–] neatchee@piefed.social 2 points 4 hours ago (1 children)

This has big "don't use a standard deadbolt on your front door; it's not as strong as reinforced titanium doors with time-release locks" energy

Like, not technically wrong, but does not fit the standard risk profile, it's overkill for boost situations.

Also to everyone talking about US law enforcement, this is just so easy to protect from, not worth ditching biometrics: if you see cops approaching and are worried about a device being unlocked, just reboot it. If you need to do it surreptitiously, just hold the power button to force shut it off after ~10s. This will always require a password to unlock after

[–] Rooster326@programming.dev 2 points 27 minutes ago

Okay and if you don't see the cops approaching? Because they use undercover cars, dress in plain clothes, and won't identify to anyone on demand? Yes even federal agents?

[–] FreddiesLantern@leminal.space 1 points 3 hours ago

Oh look it's opposite day again.

[–] nixukty@lemmy.zip 4 points 6 hours ago (2 children)

Do you really not use your phones fingerprint reader and type in your passcode every time?

I get that you can be compelled by law enforcement to give up your biometrics, but if you're gonna end up in that sort of situation it's 2 buttons and a tap to temporarily disable biometrics.

[–] It_is_gaslighting@discuss.tchncs.de 1 points 54 minutes ago

And then there is that one nerd taking every print of every employee doing thumb 3D prints or cashing out on it using the 'other' web. Oh way, are we still in 2026, too soon, sorry for the spoiler. /jk

[–] cantstopthesignal@sh.itjust.works 1 points 54 minutes ago* (last edited 53 minutes ago)

Do you really not use your phones fingerprint reader and type in your passcode every time?

Yes, yes I do. I like having friction between me and my addictive distraction rectangle.

[–] mp3@lemmy.ca 61 points 19 hours ago (2 children)

As soon as the word "convenient" is used, you know it will affect security.

[–] hades@feddit.uk 26 points 19 hours ago

Yep, they technically didn’t claim it was to make it more secure.

[–] NaibofTabr@infosec.pub 11 points 19 hours ago (1 children)

This is always the tradeoff. Security must always impose a cost.

[–] ricecake@sh.itjust.works 8 points 18 hours ago (2 children)

Why do you think that? Public key authentication systems are invariably more secure, and a wide variety are also simpler for the end user to use.

It's a misconception that they are in opposition to each other. Why would they be? One's about knowing who's doing something and the other is about how much effort it takes to do it.

[–] psycotica0@lemmy.ca 1 points 8 hours ago

Public key authentication is more secure than nothing, and is more convenient than shared secrets and symmetric encryption, but bit for bit the secret material necessary for public key cryptographic schemes to be secure is more data than is required for symmetric algorithms.

But more to your point, public key cryptography is basically a usability nightmare. In order to talk to anyone you need to first validate their key using an entirely out of band scheme you already trust, and if you don't do that then all the end to end encryption in the world is theatre.

Of course I'm being hyperbolic, it's the internet, but seriously there a lot of people feeling secure with public key systems that are either totally insecure, or could be insecure and they wouldn't know, or are secure to some random bystander but insecure to people and organizations that are often included in people's threat models.

[–] davidgro@lemmy.world 9 points 14 hours ago

Because in general, making things more difficult for an adverse party has great potential for also having side effects for proper users. And conversely, making things easier for proper users very often also makes it easier for adversaries.

You're right that it's not a strict 100% rule, but it's so common a pattern that keeping it in mind when making security decisions (to avoid fulfilling it or at least weigh risks) is a good practice.

[–] JRaccoon@discuss.tchncs.de 14 points 18 hours ago (3 children)

I think it depends. Some people might be inclined to use too short or simple password because they don't wanna constantly be typing a long password. It's much better to have a strong password and fingerprint/face rec for convince than just a insecure password.

[–] AmyAye@nord.pub 3 points 11 hours ago (2 children)

Cops can't force you to give up your password even if its 12345.

[–] Rooster326@programming.dev 1 points 8 minutes ago

Yes but they can guess it, and if it's 12345 then ...

[–] quick_snail@feddit.nl 1 points 10 hours ago (1 children)
[–] Honytawk@discuss.tchncs.de 1 points 4 hours ago

No, depends on the country.

[–] CubitOom@infosec.pub 16 points 18 hours ago (3 children)

In the USA, they can legally force you to unlock a device using biometrics.

Also, biometrics can be fooled in other ways.

[–] boonhet@sopuli.xyz 1 points 7 hours ago

Ah just don't go to the USA or don't take a device with information on it there.

[–] GamingChairModel@lemmy.world 3 points 14 hours ago

Law enforcement can legally trick you into giving up your password, too, and that's full access right there. Having an unlocked phone but no password isn't enough to get into certain parts of the core system/security settings, and trying to get into those will prompt a password anyway (and that generally gatekeeps the access to the phone through a physical connector plugged into the port).

Neither pathway is perfect but I think for real world usage and real world adversaries (not just law enforcement, but also criminal thieves/scammers/hackers, and governmental adversaries that aren't bound by legal limits, like foreign intelligence agencies), it's better to have biometrics so that you are physically punching in your PIN/password much less frequently. Especially on modern systems that get spooked easily and require a password anyway when the phone has been idle too long or when the wrong face looks at it too many times.

[–] JRaccoon@discuss.tchncs.de 7 points 18 hours ago (3 children)

Yes, but that's besides the point. If the convenient options for a normie user are

  • Having a weak password
  • Having a strong password and a fingerprint

Out of those the fingerprint with a strong password is way better option, imo.

In the USA, they can legally force you to unlock a device using biometrics.

Also, how does that work? Can't they legally force you to enter your password too? Or can you claim you don't remember it? If that works, can't you just have a band-aid on your finger or something? Surely they cannot force you to take it off and risk getting an infection on the large wound you just happened to get yesterday...?

[–] queermunist@lemmy.ml 14 points 17 hours ago* (last edited 17 hours ago) (1 children)

Also, how does that work? Can’t they legally force you to enter your password too?

No, because forcing someone to enter a password is "compelled speech" and against the 1st Amendment. It's also testimonial, which means compelling that speech would also be self incrimination, which is against the 5th Amendment.

Don't ask me why forcing someone to make a hand gesture is not also compelled speech and not testimonial. The Constitution is mostly nonsense being interpreted by life appointed morons who interpret things however they like.

load more comments (1 replies)
[–] curbstickle@anarchist.nexus 3 points 14 hours ago

'Or' not 'and'. Fingerprint replaces the password for access.

A bandaid would simply be removed. No you can't just say "no". A password is protected though.

[–] 0x0@infosec.pub 7 points 17 hours ago* (last edited 17 hours ago) (20 children)

A normal user will most likely never encounter a situation where their weak password would be at risk, but are much more likely to having their biometrics forced by law enforcement or border control.

They will rip your bandaid off and force your finger or face to scan while holding your device.

Any weak password at all would have been better in a situation like that.

load more comments (20 replies)
[–] GamingChairModel@lemmy.world 9 points 16 hours ago (1 children)

The other underappreciated threat model is shoulder surfing, especially in an age of ubiquitous high resolution cameras. Punching in a numerical PIN within view of a camera potentially leaks that secret, and some high resolution cameras can even pick up letters and symbols from the on screen keyboards.

Being compelled to give biometrics doesn't do enough for an adversary (including government adversaries) to do everything with a phone, the way having the password or PIN does, and I would argue that governments would be better at tricking people into inadvertently giving up their PINs and passwords than they'd be at compelling biometrics within the time window that they still work (before the phones lockout biometrics as a valid unlocking method), or being able to do stuff to exploit extraction tools past the lock screen.

So the threat model needs to be understood for what it is.

[–] imadethis@fedinsfw.app 1 points 10 hours ago

Hell, I still sometimes think about the research team that tried to make a camera in a bus (so at the front pointed towards the faces of riders) obtain passwords from the reflections off of sunglasses. They collectively facepalmed when they tried it with their test subject, but accidentally picked up the passwords of several others on the bus that were not part of the experiment.

That was something like 8-12 years ago... Capabilities now are likely insane.

[–] ricecake@sh.itjust.works 13 points 18 hours ago (2 children)

Why?

It's not like they're literally using your face or fingerprint as a password. They're not even storing them, just a hash tied to an hsm key.

[–] twjolson@lemmy.world 13 points 18 hours ago (13 children)

I can't speak for OP, but in the US, you can be compelled to unlock a phone via fingerprint or face ID. You can't be compelled to give over your PIN. That violates the right against self incriminating.

[–] ricecake@sh.itjust.works 6 points 18 hours ago (3 children)

Totally true. That's not the common threat most people need to guard against however. Additionally, at least on Android, the device is relatively eager to force pin usage if the stars don't align for biometrics

load more comments (3 replies)
load more comments (12 replies)
load more comments (1 replies)
[–] umbrella@lemmy.ml 5 points 15 hours ago

normies will believe it tho

[–] unknownuserunknownlocation@kbin.earth 10 points 18 hours ago (4 children)

Hot take: biometrics are often criticized for being less secure, but that ignores the deficiencies of passwords. Especially on phones, it's very doable to look over someone's shoulder while they're unlocking their phone or do the same with a camera. You can't do that with a fingerprint, at least not nearly as easily.

And yes, I understand that in the US (amongst others?) the legal situations with passwords and biometrics are different, but IMO that's more of a legal question, and not everyone lives in the US.

Android also has an "emergency lockdown" option, which disables biometrics for unlocking your phone - or you can shut it down (worst case scenario force shut down with a long hold on the power button) to get it into a BFU state, which is much harder to crack.

load more comments (4 replies)
load more comments
view more: next ›