• deliriousdreams@fedia.io
    link
    fedilink
    arrow-up
    0
    ·
    1 month ago

    It has every single thing to do with the bearing of this conversation.

    If the police tried to use biometrics to search my device today they would find exactly nothing.

    On the average person’s phone they likely wouldn’t find much that’s actionable in a legal sense.

    The average person has a threat profile where it’s much more likely that they would worry about a snooping parent, sibling, or significant other, or even coworkers over the police.

    That is who biometrics are for.

    For anyone else who has a threat profile that should require them to be worried about police intervention or investigation of any kind, there’s either a burner phone or a hardened OS and both of those use cases and the people using them likely aren’t using biometrics. But that doesn’t mean they have a good password either. People aim for convenience and less friction.

    So let’s think about what I am arguing here. I am arguing that a burner phone with nothing on it is likely more useful to a person worried about the police getting access to their device than a pin or password is. And that even if you do have a password there is likely a way for them to bypass it or there will be in the future.

    You are arguing that even a weak password is better than biometrics, but that is in a singular instance where you are detained by or investigated by the police, and in that event you probably have a threat profile that would require more than just a password lock for your devices. Especially if you’re using a weak password.

    • curbstickle@anarchist.nexus
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      It has every single thing to do with the bearing of this conversation

      See the OP.

      It does not.

      If the police tried to use biometrics to search my device today they would find exactly nothing.

      Entirely separate from weak password vs no password (biometrics).

      On the average person’s phone they likely wouldn’t find much that’s actionable in a legal sense.

      Bad take.

      Laws are poorly written, sometimes intentionally, to make them more vague.

      I guarantee you can get arrested for something if they really want to.

      That is who biometrics are for.

      People who don’t want to use a password, and it will functionally behave like you don’t have any sort of restriction on your data. Yes. Agreed. Biometrics provide absolutely zero protection, as said.

      For anyone else who has a threat profile that should require them to be worried about police intervention or investigation of any kind

      In reality, everyone, see above.

      there’s either a burner phone or a hardened OS

      Separate from and entirely irrelevant to a discussion about biometrics and passwords.

      So let’s think about what I am arguing here.

      I have been. I’m not sure that you have, and I don’t mean that to sound like a dick, I’m saying I think you are severely underestimating the issue.

      But that doesn’t mean they have a good password either.

      Biometrics provide functionally zero password. That’d be the context here. A weak password is better than no password. A strong password is better than no password.

      As biometrics means functionally no password, any password is superior.

      You are arguing that even a weak password is better than biometrics

      Yes, because it means no password is required at all. Even a weak password is better than no password.

      but that is in a singular instance where you are detained by or investigated by the police

      The context of this entire discussion. Yes.

      and in that even you probably have a threat profile

      Everyone. See above.

      would require more than just a password lock for your devices. Especially if you’re using a weak password.

      As in not biometrics, because biometrics are the same as no password. Yes.

      • deliriousdreams@fedia.io
        link
        fedilink
        arrow-up
        1
        ·
        1 month ago

        I’m not responding to the post. I’m responding specifically to your comment (where you did not give context but made a definitive statement). That’s on you.

        You can’t be compelled to give up your password.

        OP IS USING A GOOGLE ACCOUNT WITH GOOGLES BIOMETRICS BEING SUGGESTED TO THEM.

        The police will bypass you to get that data and Google will likely give it to them without a subpoena. And even if they don’t, it’s likely that given the state of the justice system in this country they will be able to subpoena that information anyway, assuming they don’t just break into your phone (see link I posted in this comment thread a few comments back).

        Laws are poorly written, sometimes intentionally, to make them more vague.

        I guarantee you can get arrested for something if they really want to.

        They will do this with or without access to your device and it will more than likely be with access regardless of what kind of security you use.

        Separate from and entirely irrelevant to a discussion about biometrics and passwords.

        You haven’t explained how.

        I have been. I’m not sure that you have, and I don’t mean that to sound like a dick, I’m saying I think you are severely underestimating the issue.

        Clearly not.

        Biometrics provide functionally zero password. That’d be the context here. A weak password is better than no password. A strong password is better than no password.

        Nope. You clearly didn’t read the entirety of what I said, but I guess I’ll explain. If I’m not using a password my behavior on that device reflects that. Often meaning I’m not logged into anything, clear browser history and don’t download anything. That’s basically a burner phone at the point. Because there is no expectation of privacy or security.

        As biometrics means functionally no password, any password is superior.

        I can tell you didn’t click the link. False sense of security ahoy!

        Yes, because it means no password is required at all. Even a weak password is better than no password.

        A person who isn’t using a password does not have the expectation that their device is secure. A person using a password has the expectation that their device is secured, but with a weak password that doesn’t mean it actually is. Biometrics mean that your device is secure against the average individual (because you know, that’s what locks are for, to keep honest people honest).

        The context of this entire discussion. Yes.

        And in that event you can force Android and IOS devices to require a password. So biometrics wouldn’t allow them to force you to use biometrics to unlock the device.

        Everyone. See above.

        Not everyone. Most Americans never leave the country. EVEN when you consider international airports, most Americans don’t fly regularly and even if they did, see my above comments about burner phones because (see my above comments about brute forcing devices or subpoenaing the data on those devices) that’s pretty much the only way to be sure.

        As in not biometrics, because biometrics are the same as no password. Yes.

        You keep saying that word but I don’t think you know what it means.

        If you had said using biometrics is like using a TSA approved luggage lock I might be inclined to agree with you. But what you said was that "you can be compelled to give up biometrics to unlock your device) and what I said was, a weak password is not better.

        You can continue to argue but you seem to keep missing context here. A weak password is what most people use. That’s why there’s a top 1000 passwords in use news article every couple of years.

        Your birthday or anniversary is not better than biometrics. Say whatever else you want here. You haven’t actually proven a point but I’m over it.