this post was submitted on 02 Aug 2026
157 points (91.1% liked)

Cybersecurity

10398 readers
91 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 3 years ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments
[–] twjolson@lemmy.world 15 points 2 days ago (5 children)

I can't speak for OP, but in the US, you can be compelled to unlock a phone via fingerprint or face ID. You can't be compelled to give over your PIN. That violates the right against self incriminating.

[–] picnic@lemmy.dbzer0.com 2 points 1 day ago

I travel a few times a month to US, China, Hong Kong etc.

I shut down my grapheneos phone on the border. Graphene also allows you to set auto reboot to phone if unlocked from 10mins to like 72 hours.

I do use biometrics on my device. I think its a tradeoff I'm willing to make.

[–] atrielienz@lemmy.world 0 points 23 hours ago (1 children)

I love this "in the US" thing. Like we're the only country where that's true and there aren't whole European countries doing the exact same thing.

While I admit nothing exists in a vacuum and there's a lot of push toward a police state in the US, we also aren't the only country doing that, by far. We're just more open about it since Cheeto in Chief took office again.

[–] twjolson@lemmy.world 0 points 23 hours ago (1 children)

Or maybe I don't have knowledge and experience in EU law and didn't want to pretend I do.

[–] atrielienz@lemmy.world 0 points 22 hours ago (1 children)

It's not just you. There's quite a few people who keep saying this. You'll note that they don't chime in to mention that Norway or Germany.

It's dystopian as fuck that this is where we're at, but I don't think it's a good idea to pretend this is strictly a US thing.

[–] twjolson@lemmy.world 1 points 21 hours ago* (last edited 21 hours ago) (1 children)

Nobody did. You're arguing against a point nobody made.

[–] atrielienz@lemmy.world 0 points 5 hours ago (1 children)
[–] twjolson@lemmy.world 1 points 5 hours ago

Yea, ok bud. Go argue the obvious with someone else.

[–] ricecake@sh.itjust.works 9 points 2 days ago (1 children)

Totally true. That's not the common threat most people need to guard against however. Additionally, at least on Android, the device is relatively eager to force pin usage if the stars don't align for biometrics

[–] 0x0@infosec.pub 5 points 2 days ago (2 children)

Almost any user are much more likely to encounter a situation where their biometrics are forced and not their password. Passing a border for example.

Biometrics should never be used instead of a password, only as usernames. A password can be changed, your thumbs can't.

[–] ricecake@sh.itjust.works 6 points 1 day ago* (last edited 1 day ago)

Have you ever had your phone searched by the police or at the border? I haven't, but I have had someone try to unlock my phone before.

I'd contend most people have a threat model that puts opportunistic access by household members or someone watching them enter their passcode and then snatching the phone and running above border patrol search.

While you can't change your biometrics, walk me through why that matters. I'm not sharing my biometrics outside of the device, and you can't submit them remotely, so if you lift a print off of something it doesn't really get you much without also taking the phone. Once you're there, you're a bit beyond the typical phone thief in terms of threat.

The most common vulnerability is having an absurdly weak password, pin or unlock pattern. For those people biometrics is a vast improvement specifically because it's both secure against likely threats, and it's just as easy as hitting 5 four times in a row.

Every method has trade offs, and there's nothing to gain by pretending otherwise. Likewise, I don't think I would ever say "never use something", except for some contrived examples.

[–] Viceversa@lemmy.world 4 points 1 day ago* (last edited 1 day ago)

Almost any user are much more likely to encounter a situation where their biometrics are forced and not their password. Passing a border for example.

That's valid only for americans. And even then: how many of them are crossing country borders regularly?

[–] deliriousdreams@fedia.io 2 points 1 day ago (1 children)

Which means it's not secure against the authorities but probably is secure against the average thief and or snooping younger sibling/spouse. So, your threat profile and the use of biometrics/vs password may vary.

[–] twjolson@lemmy.world 3 points 1 day ago (2 children)

Definitely not. The average thief can get you to unlock it with your face or finger far easier than get your PIN.

[–] ricecake@sh.itjust.works 2 points 1 day ago (1 children)

If you point a weapon at me in a way that would compel me to help you unlock my phone with fingerprint or face unlock, I promise you it would not be any harder for you to get me to unlock the device with the pin.

[–] twjolson@lemmy.world 3 points 1 day ago (1 children)

You assume that you are conscious, or even alive in your scenario.

[–] ricecake@sh.itjust.works 3 points 1 day ago

If I'm not alive I don't really care if they get the contents of my phone. My survivors can go through the same process I would for reversing a fraudulent transaction.

And you're picturing a criminal subduing me and then just crouching over my body and figuring out what financial apps I have and how to use them?
What's their game plan here? Most stolen phones are resold, not used to access their contents.

[–] deliriousdreams@fedia.io 1 points 1 day ago (1 children)

Doubtful. The average thief isn't robbing you at gunpoint. They grab the phone out of your hand and book it.

But even if they did stick around for that, most people use a 4 number pin and that's basically just as easy as face or fingerprint unlock. Its an additional maybe 2 seconds.

If they can force you to put your finger on the sensor they can force you to give them the pin.

[–] twjolson@lemmy.world 1 points 1 day ago (2 children)

Do any phones even allow 4 digit Pins? Apple doesn't, and my Samsung doesn't.

No one can force you to give up the PIN. They can threaten, and you may give in to that threat. But that isn't forcing, that isn't against your will.

But, a criminal can get you to unlock your phone with biometrics against your will easily enough - brute strength, render you unconscious, or even dead.

[–] ricecake@sh.itjust.works 2 points 1 day ago (1 children)

No one can force you to give up the PIN. They can threaten, and you may give in to that threat. But that isn't forcing, that isn't against your will.

That's called force, and against your will.

That's just fundamentally not understanding how the terms work. A coerced action, or one taken under duress, is not taken of ones own free will.

https://www.law.cornell.edu/wex/duress

[–] twjolson@lemmy.world 0 points 1 day ago (1 children)

My comment was in reply to another saying a bad guy can force you to put your finger on the unlock sensor. There is no equivalent for pins.

They can threaten, yes, and you can give into that threat. Yes, that would be against your will, but it still requires you to acquiesce or cooperate was my point. The can't get the pin without you giving it.

[–] ricecake@sh.itjust.works 2 points 1 day ago (1 children)

Yeah, and if you're being robbed they'll probably fuck you up pretty badly if you don't. While not mind readers, they don't have to be.

In most cases anyone who wants to beat your pin will just watch you unlock your phone. They don't need to see the exact numbers: you can pick most of it up just based on relative finger motion. Looking at screen smudges gives another set of hints that are pretty trivial to extract.

If your goal is to keep it from the police, your best bet is to use an entirely different system than rely on your phones lock screen.

I can't think of a scenario where I'm thinking both "biometrics are insufficient to safeguard this data" and "it's appropriate to keep this data on my telephone".

[–] twjolson@lemmy.world 1 points 1 day ago (1 children)

You aren't wrong, but this discussion is mostly about edge cases. The average person, yea, they won't have anything that is end of their world if a bad guy accesses it. But, that does mean there aren't many phones that contain significantly more important data than you have.

[–] ricecake@sh.itjust.works 1 points 1 day ago (1 children)

Given we're in a thread about biometrics being the opposite of privacy and security, it really does seem relevant to me that the threat model where they would be insufficient and the one where that would matter is basically empty.

If your thought process is "I need to protect this from the police and a determined or sophisticated criminal, but I can't be bothered to use anything more than my lock screen on my phone"... Well, you're already starting from a pretty bad place.

[–] twjolson@lemmy.world -1 points 1 day ago

Nothing in that reply is even close to anything I've said. Don't waste my time with stupidity or strawmen.

[–] deliriousdreams@fedia.io 1 points 1 day ago

My pixel allows a 4 digit pin. Mine is 7 digits but I also don't use biometrics.

Just had a look and it's Face/Fingerprint/Pin/Swipe/Pattern/Password.

[–] Viceversa@lemmy.world 0 points 1 day ago (2 children)

You can't be compelled to give over your PIN. That violates the right against self incriminating.

Is that valid only to USA citizens or foreigners can use that trick too?

[–] Bytemeister@lemmy.world 2 points 1 day ago

Take this with a grain of salt, considering the actions of the current administration...

But the US Constitution doesn't make that many distinctions between citizens and non-citizens, especially in the bill of rights, where most individual protections are laid out. The 4th amendment protects you from unwarranted search and seizure, and makes no restrictions based on nationality.

There are some "exceptions" to the 4th amendment, but those specifically have to do with protecting the borders and inspecting imports and exports. IMHO, those exceptions should be unconstitutional, but I'm not a bought and paid for SC justice, so fuck my opinion.

[–] deliriousdreams@fedia.io 3 points 1 day ago

It's valid for anyone visiting the US. Even if they do so illegally. Its a right given by the constitution and it's amendments and those apply to everyone in the US. Importantly, people often forget that the Constitution isn't a limiting document for the people. It's a limiting document for the government.