this post was submitted on 25 Sep 2024
91 points (100.0% liked)

Technology

37702 readers
286 users here now

A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.

Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.

Subcommunities on Beehaw:


This community's icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] alyaza@beehaw.org 32 points 1 month ago (16 children)

In Riley v. California, the Supreme Court unanimously held that police need a warrant to search through cell phones, even during otherwise lawful arrests. But if you hand over your unlocked phone to a police officer and offer to show them something, “it becomes this complicated factual question about what consent you’ve granted for a search and what the limits of that are,” Brett Max Kaufman, a senior staff attorney in the ACLU’s Center for Democracy, told The Verge. “There have been cases where people give consent to do one thing, the cops then take the whole phone, copy the whole phone, find other evidence on the phone, and the legal question that comes up in court is: did that violate the scope of consent?”

If police do have a warrant to search your phone, numerous courts have said they can require you to provide biometric login access via your face or finger. (It’s still an unsettled legal question since other courts have ruled they can’t.) The Fifth Amendment typically protects giving up passcodes as a form of self-incrimination, but logging in with biometrics often isn’t considered protected “testimonial” evidence. In the words of one federal appeals court decision, it requires “no cognitive exertion, placing it firmly in the same category as a blood draw or fingerprint taken at booking.”

it's unbelievable that there is a distinction in US caselaw between giving up your biometrics and giving up your password, and your essentially unchangeable biometrics are somehow the one you're probably obliged to give to the cops if they ask. just an incredibly goofy system

[–] t3rmit3@beehaw.org 6 points 1 month ago* (last edited 1 month ago) (2 children)

Never use biometrics. It's just not worth the tradeoffs.

[–] Overzeetop@beehaw.org 1 points 1 month ago (1 children)

Something you have, something you are, something you know. Are you willing to give up proper security for your cause?

[–] t3rmit3@beehaw.org 3 points 1 month ago* (last edited 1 month ago)

When it's being employed properly, it's absolutely an important tool, but the way they're presented to most users, such as on-device biometric data stores (e.g. Apple's secure enclave, or a TPM verification), aren't the proper implementations. Nor is using biometrics as your primary auth method.

It's supposed to be "something you have and something you know and something you are", not "have or know or are".

NIST standards for biometrics require the biometric data be stored on a secure remote server, and that the scanner device check against that during auth. Putting the biometric data on the device means that you're losing a big part of your non-repudiation.

And it's even worse when you're using a secondary factor (biometric) as your primary or only factor (e.g. a phone unlock), that grants access to your other factors like password store and OTP tokens.

Biometrics are never supposed to be a single-factor auth method when used properly, but that's how most people use them now, and it degrades their security.

If your phone requires a passcode, a TOTP grant, and a biometric scan, by all means, please do employ biometrics, but if it's going to be your only factor, DO NOT.

Or, for simplicity to the average forum reader:

Never use biometrics. It’s just not worth the tradeoffs.

load more comments (13 replies)