5 points

This is the best summary I could come up with:


Last week, the 9th Circuit Court of Appeals in California released a ruling that concluded state highway police were acting lawfully when they forcibly unlocked a suspect’s phone using their fingerprint.

The case didn’t get a lot of coverage, especially because the courts weren’t giving a blanket green light for every cop to shove your thumb to your screen during an arrest.

The ruling was also complicated by the fact that Payne was on parole at the time, back in 2021, when he was stopped by California Highway Patrol where he allegedly had a stash of narcotics including fentanyl, fluoro-fentanyl, and cocaine.

However, the panel said the evidence from his phone was lawfully acquired “because it required no cognitive exertion, placing it in the same category as a blood draw or a fingerprint taken at booking, and merely provided [police] with access to a source of potential information.”

The Electronic Frontier Foundation, a digital rights group, has offered guides for best practices when attending protests, and one of those is to turn off your thumbprint or face unlock before you hit the street.

“The general consensus has been that there is more Fifth Amendment protection for passwords than there is for biometrics,” Andrew Crocker, the Surveillance Litigation Director at the EFF, told Gizmodo in a phone interview.


The original article contains 988 words, the summary contains 217 words. Saved 78%. I’m a bot and I’m open source!

permalink
report
reply
-6 points

Thank you.

permalink
report
reply
31 points

I’ve avoided willingly using biometrics so far. Though I’m sure our faces, gaits, body shapes, etc, are all stored somewhere, willingly or not.

Say no to biometrics. It’s like having a password you can never change.

permalink
report
reply
27 points

Password you can never change

Not with that attitude! You can absolutely change your face. its rather inadvisable

permalink
report
parent
reply
19 points

Face… off…

permalink
report
parent
reply
5 points
*

permalink
report
parent
reply
6 points

Joke’s on them. My yo-yo diet keeps me safe from accurate body shape biometrics.

permalink
report
parent
reply
10 points

it’s not a password; it’s closer to a username.

but realistically it’s not in my personal threat model to be ready to get tied down and forced to unlock my phone. everyone with windows on their house should know that security is mostly about how far an adversary is willing to go to try to steal from you.

personally, i like the natural daylight, and i’m not paranoid enough to brick up my windows just because it’s a potential ingress.

permalink
report
parent
reply
3 points

It’s not a great analogy. Your house and its windows are exposed to your neighborhood/community. Your internet device is adjacent to every hacker on the web.

permalink
report
parent
reply
6 points

it’s an analogy that applies to me. tldr worrying about having my identity stolen via physical access to my phone isn’t part of my threat model. i live in a safe city, and i don’t have anything the police could find to incriminate me. everyone is going to have a different threat model. some people need to brick up their windows

permalink
report
parent
reply
2 points

That’s why I put Linux on my house.

permalink
report
parent
reply
36 points

So, it really depends on your personal threat model.

For background: the biometric data doesn’t leave the device, it uses an on-device recognition system to either unlock the device, or to gain access to a hardware security module that uses very strong cryptography for authentication.

Most people aren’t defending against an attacker who has access to them and their device at the same time, they’re defending against someone who has either the device or neither.

The hardware security module effectively eliminates the remote attacker when used with either biometric or PIN.
For the stolen or lost phone attack, biometric is slightly more secure, but it’s moot because of the pin existing for fallback.

The biggest security advantage the biometrics have to offer is that they’re very hard to forget, and very easy to use.
Ease of use means more people are likely to adopt the security features using that hardware security module provides, and that’s what’s really dialing up the security.

Passwords are most people’s biggest vulnerability.

permalink
report
parent
reply
1 point

I’ve read all this before. If you believe the people who designed and implemented the device and its myriad layers of firmware and software were 1. All acting in good faith and 2. Knew WTF they were doing… then: yes, sure.

Unfortunately that’s way too many strangers for me. Hundreds of people design and code these things. Meanwhile, every week there’s a clever new breach somewhere.

permalink
report
parent
reply
6 points

While I do respect that viewpoint, there’s a lot more independent scrutiny of the hardware modules than there are around the parts that would handle any other authentication mechanism you might use.

Pixel phone example iPhone example

Just because something isn’t perfect doesn’t mean we should keep using the less good thing that it replaces.

Use the PIN if that’s more your cup of tea, just so long as you move away from passwords, since it’s the HSM that’s the protection, not the biometrics. Those are just to make it easier than passwords.

permalink
report
parent
reply
4 points

If you’re that afraid if the people who build phones, why are you ok with using any device that can access the internet?

permalink
report
parent
reply
2 points

Same here. Still using the pattern lock. I’ve never used fingerprint not to even mention face scan.

permalink
report
parent
reply
202 points

Last week, the 9th Circuit Court of Appeals in California released a ruling that concluded state highway police were acting lawfully when they forcibly unlocked a suspect’s phone using their fingerprint.

You can turn that and Face ID off on iOS by mashing the power button 5 times- it locks everything down.

permalink
report
reply
4 points

On Graphene/Calyx you can auto-restart the phone after a given time period if it hasn’t been interacted with. Recommend turning this on for all users.

permalink
report
parent
reply
3 points

What’s the name of this feature for GrapheneOS? I’m not finding it.

permalink
report
parent
reply
3 points

Try searching for auto reboot, or some sort of extra security settings menu.

permalink
report
parent
reply
57 points

Android has a similar feature. It’s called “Lockdown mode” on the shutdown menu. Locks the phone and turns off any biometric unlocks.

permalink
report
parent
reply
34 points

Except it doesn’t activate by mashing the power button 5 times. On my Pixel 8, that activates the emergency dialer that will automatically call 911 if you don’t cancel the prompt in 5 seconds. I did not know that before. Probably a better use for that feature. It also points out the different ideologies of Apple vs Android.

permalink
report
parent
reply
18 points

It does the same thing on iOS, but face/Touch ID is disabled after.

permalink
report
parent
reply
7 points

On iOS, for SOS, Medical ID, and “slide to power off” you hold power and a volume button. That also disables biometric ID.

permalink
report
parent
reply
12 points

My wife’s pixel 3(?) with a flaky power button had us wake up to cops knocking on the door because of that feature.

permalink
report
parent
reply
5 points

Push and hold to get the power menu on my 7.

permalink
report
parent
reply
2 points

I was mowing my lawn and learned about that feature. A nice ladies voice came through my bluetooth headphones asking if I needed help lol. You can change what the button spam does and I changed it to call my mom instead.

permalink
report
parent
reply
3 points

On my Pixel 7 Pro, I press the power and volume up buttons simultaneously, then I can click Lockdown. Now my passcode is required to unlock the phone.

permalink
report
parent
reply
22 points
*

That’s terrifying. So once we have tech to forcibly see inside the brain, that will be legal too?

permalink
report
parent
reply
8 points
*

You think it wouldn’t xD?

permalink
report
parent
reply
3 points

Probably. Wouldn’t it be good to have the truth during investigations?

However I think that we really need refine when warrantless searches can occur. Right now many searches seem to be done with very little evidence to justify them. I think this protection should apply to your mind and phone just like it applies to your house. This probably also needs to be considered at border crossings. Right now they have basically unlimited rights for searching what you have on you with little to no evidence.

We should probably also rethink about how the information is shared when there is a warrant. Right now during a trial a huge amount of personal information can be made available. Maybe if it was easier to get precise information less would be needed.

permalink
report
parent
reply
7 points

Wouldn’t it be good to have the truth during investigations?

Well, yeah, but the mind is fallible. That’s why eye witness testimony usually only gets a case so far, people tend to forget specifics and fill in the gaps without realizing they did.

permalink
report
parent
reply
2 points

However I think that we really need refine when warrantless searches can occur. Right now many searches seem to be done with very little evidence to justify them. I think this protection should apply to your mind and phone just like it applies to your house. This probably also needs to be considered at border crossings. Right now they have basically unlimited rights for searching what you have on you with little to no evidence.

to be fair to the current justice system, a lot of times you can just hit the courts with “excuse me sir, this was unwarranted” and assuming it was actually unwarranted, they should overthrow it immediately.

permalink
report
parent
reply
1 point

Not if it comes with a level of invasiveness that is unforgivable it wouldn’t be.

Forcibly invading someone’s mind after they were convicted beyond reasonable doubt would make you a monster.

permalink
report
parent
reply
6 points

“You shouldn’t be worried if you have nothing to hide” 🤷‍♂️

Tap for spoiler

/s

permalink
report
parent
reply
13 points

Do you have to mash it? Or will pressing it normally work?

permalink
report
parent
reply
4 points
*

NO

permalink
report
parent
reply
25 points

The only thing I’ll mash is that subscribe button

permalink
report
parent
reply
-3 points

Pretty sure Apple would replace the buttons with pressure sensors – not for user comfort but so that they are no longer replaceable with OEM parts and can be serialized. They did literally this with Macbook sleep sensors.

permalink
report
parent
reply
9 points

Assuming you have the access to do this, e.g. awake, conscious, not handcuffed, etc. It’s safer to just always use a PIN in the first place.

permalink
report
parent
reply
0 points

Came here to say that! Glad it’s getting around.

permalink
report
parent
reply
95 points

I’ve always wanted a setting to create a lockdown key and an unlock key. So something like middle-finger to unlock but index-finger to force it into PIN/password only mode. So you can have some convenience of a quick unlock but if an authority figure asks or forces you to unlock it you can one-tap lock it down.

permalink
report
parent
reply
10 points

That would be awesome.

permalink
report
parent
reply
8 points

In GrapheneOS, a single wrong fingerprint disables fingerprint unlock until the password is entered.

permalink
report
parent
reply
32 points

In a getting pulled over situation, this works. But do it before you go protest anything. Or better yet, leave your phone at home. You don’t want to be reaching for something while a cop is pointing a gun at you and saying “Hands up!”

permalink
report
parent
reply
30 points

Not to mention it’s pretty regular to track who is participating by checking the towers in the zone all the people are participating.

permalink
report
parent
reply
7 points

Or get a geofence warrant

permalink
report
parent
reply
11 points

☞ EFF / Surveillance Self-Defense / Attending a Protest

permalink
report
parent
reply
2 points

Didn’t know EFF had this, neat

permalink
report
parent
reply
80 points

⚠️ WARNING: On android, mashing the power button 5 times calls emergency services…

permalink
report
parent
reply
-14 points
*

Not on my Pixel 6. 🤷‍♂️ It just does what I told it to do, namely to open the camera.

Edit: these are some Reddit down votes. I just didn’t know I had this feature, and I apparently have disabled it, but I don’t remember doing so. Oh well.

permalink
report
parent
reply
26 points

Cool, you disabled the gesture. Clearly the default SO setting doesn’t apply to you…

permalink
report
parent
reply
6 points

Have to tried? On my Samsung pressing twice does the camera (as I’ve set it to) but doing 5 times tries to call emergency services.

permalink
report
parent
reply
44 points

On android you can add a ‘lockdown’ mode to the power menu.

permalink
report
parent
reply
1 point

on my phone lockdown mode is found by pressing side button and power up at the same time, then selection lockdown from the menu

permalink
report
parent
reply
2 points

Thanks for this, didn’t know this was an option.

permalink
report
parent
reply
9 points

There are two ways you can do this on Android currently, but they’re not as quick. You can try to unlock with the wrong finger 5 times and it will stop allowing fingerprint unlocks. Or, you can hold down the power button for 10 seconds and the phone will reboot and also disable fingerprint unlocking.

permalink
report
parent
reply
9 points

You can also just long press a volume button with the lock button (with a FaceID phone). I find this harder to mess up under stress.

permalink
report
parent
reply
0 points

Just hold volume up and power for 3 seconds.

permalink
report
parent
reply
61 points
*

## How to disable Face ID through the Power Off screen

  1. Hold down both the Side Button and either Volume Button at the same time for three seconds.
  2. The Power Off slider should appear. Tap Cancel.

You actually don’t need to hit cancel, you can just hit lock, so you can do this whole thing with your phone in your pocket.

https://appleinsider.com/inside/iphone/tips/how-to-quickly-disable-face-id

This is easier and less intrusive than the lock-button-5-times method because it doesn’t start making a phone call that you have to quickly cancel.

permalink
report
reply
2 points

Real MVP right here. Good to know!

permalink
report
parent
reply
1 point

This also encrypts your data.

permalink
report
parent
reply
1 point
*
Deleted by creator
permalink
report
parent
reply
14 points

This is the advice people (with iOS) should follow, not disabling biometrics altogether. Using FaceID or TouchID prevents shoulder surfing to find out what the password to your phone is. When local passwords have so much control over a device, using biometrics to prevent anyone from seeing what your passcode is is very useful.

permalink
report
parent
reply
3 points

Those settings can also be altered under Settings > Emergency SOS

permalink
report
parent
reply

Technology

!technology@lemmy.world

Create post

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


Community stats

  • 17K

    Monthly active users

  • 12K

    Posts

  • 555K

    Comments