• 0 Posts
  • 18 Comments
Joined 2Y ago
cake
Cake day: Aug 24, 2023

help-circle
rss

I had one of theirs like that. You could disable it instead of uninstall, and this wouldn’t happen, but you couldn’t uninstall it.


With a universal key to every single door that is easily copyable and sharable, but not really possible to know if one bad cop decides to share it for $$$$


It’s when they become loud mouth attention seekers like Musk that people begin to care. But if everyone claiming to boycott Musk products actually boycotted all the companies that have done terrible things (and way worse than musk), they’d suddenly have nothing to buy.


That said, I think the core concern can be rephrased in a way that gets at the essence, and to me there’s still a live issue that’s not relieved simply by noting that this requires probable cause.

Well ya. The whole thing is really fucked in the first place. It’s very disturbing that it was ruled they can compel biometics in any circumstance.

In a far off future, this ruling would probably even allow a mind reading device to figure out a PIN, which would be protected, because they didn’t force you to say it, and reading electrical signals isn’t really any different than reading ridges on a finger.


There’s no reason a company couldn’t release the info legally unless it was under something like AML (anti money laundering) laws and you were flagged as a criminal. They legally can’t disclose why in that case.

Using a different OS isn’t reason enough, if they were telling the truth about the legal restrictions.


It’s used to help secure the businesses app yes. It helps with things like preventing resource abuse which would cost the company money. E.g. querying mass amounts of data on a loop to increase the companies bill.


Right, but they can’t just do it without reason which he was implying, and he replied to me with

“Yea but that wasn’t the point of me pointing it out. The point was that they don’t need to resort to such measures in order to clandestinely acquire your unlocked phone.”

In this case he was on parole where they have the right to search him. That mention of blood draw etc, you’re already under arrest and they can search your person anyway.

I’m not aware of any law where a cop can walk up to you on the street and demand they unlock your phone with biometrics and search it without cause.


They need a warrant or probable cause for that, but yes they can compel it unlike a password. It’s still a search and needs to be lawfully done in the first place.


It let’s you require both?

It looks like it’s pin and optional fingerprint, not pin and fingerprint for me? On Android

This is why I always turn it off in airports though.


Just in addition to my other reply… that was assuming it’s not a government agency.

The police can just force you to do it, but they can’t force a password.

Everyone using a passkey and biometrics on their hardware is law enforcements wet dream.

Including border security where you have less rights.


It’s just much weaker than a password and passkey / security key.

Something you are can easily be taken from you. (Edit: eg lifting fingerprints can unlock things)

Something you know is harder and would escalate a situation if forced substantially.


It could be your phone or computer as well, they don’t have to be in a password manager.

And that’s often going to be the default people use.

Now it’s just your face or fingerprint, both of which are easier to bypass if it’s targeted.


I highly dislike the idea of a passkey replacing a password as it means you’ve lost the something you know and replace it only with something you have.

Passwords AND passkeys together sound great.


I feel like this would be better if the field was surrounded by a 1 foot moat, and there was a bridge.

It would take some amount of effort to step over the moat and not trip, vs just walking over the bridge.

The bridge has a small toll to help maintain it.

But bridge or no bridge you’re getting into the field.


There’s been enough zero day remote exploits that there’s bound to be more.

Pretty sure there’s more than 1 about receiving an SMS and the payload rooting the phone and you not even knowing it happened. At least 1 but I think 2 or more.

Something about a malicious image also rooting a phone.

It goes on and on and phones don’t always get security updates.

You can do your best, but then longer you use a given phone the higher the risk. That’s why people switch out phones frequently when doing shady or important shit



You don’t need a backdoor in signal to bypass its encryption.

All you need is to exploit the phone and wait for them to open or use signal.

If you think your phone is safe from the NSA or similar services, I got some bad news for you.


Signal let’s you transfer devices and their history at least on phones.

It might be different then restoring a backup, but you should be able to move to another device.

If you want 2 devices on the same account, then yes, it won’t let you transfer the data, but both will get messages moving forward.