this post was submitted on 02 Aug 2026
242 points (91.4% liked)

Cybersecurity

10398 readers
101 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 3 years ago
MODERATORS
 
top 50 comments
sorted by: hot top controversial new old
[–] neatchee@piefed.social 13 points 1 day ago* (last edited 1 day ago) (6 children)

This has big "don't use a standard deadbolt on your front door; it's not as strong as reinforced titanium doors with time-release locks" energy

Like, not technically wrong, but does not fit the standard risk profile, it's overkill for most situations.

Also to everyone talking about US law enforcement, this is just so easy to protect from, not worth ditching biometrics: if you see cops approaching and are worried about a device being unlocked, just reboot it. If you need to do it surreptitiously, just hold the power button to force shut it off after ~10s. This will always require a password to unlock after

[–] Rooster326@programming.dev 3 points 1 day ago (1 children)

Okay and if you don't see the cops approaching? Because they use undercover cars, dress in plain clothes, and won't identify to anyone on demand? Yes even federal agents?

[–] neatchee@piefed.social 4 points 1 day ago

Again it's about risk profile. if you believe there is a chance that will happen to you, then go ahead.

Personally I just turn my personal phone off when approaching a border or attending a rally and that covers me. I'm not really worried about getting mugged from behind by a federal agent.

load more comments (5 replies)
[–] mp3@lemmy.ca 91 points 2 days ago (2 children)

As soon as the word "convenient" is used, you know it will affect security.

[–] hades@feddit.uk 35 points 2 days ago (2 children)

Yep, they technically didn’t claim it was to make it more secure.

load more comments (2 replies)
[–] NaibofTabr@infosec.pub 16 points 2 days ago (4 children)

This is always the tradeoff. Security must always impose a cost.

load more comments (4 replies)
[–] nixukty@lemmy.zip 11 points 1 day ago (5 children)

Do you really not use your phones fingerprint reader and type in your passcode every time?

I get that you can be compelled by law enforcement to give up your biometrics, but if you're gonna end up in that sort of situation it's 2 buttons and a tap to temporarily disable biometrics.

[–] cantstopthesignal@sh.itjust.works 7 points 1 day ago* (last edited 1 day ago)

Do you really not use your phones fingerprint reader and type in your passcode every time?

Yes, yes I do. I like having friction between me and my addictive distraction rectangle.

[–] CubitOom@infosec.pub 4 points 1 day ago (1 children)

Yes, strong password and no biometrics is basic security practice.

[–] Appoxo@lemmy.dbzer0.com 2 points 1 day ago* (last edited 20 hours ago)

The grid pattern is way better than any password in terms of reasonable password lengths

[–] LordCrom@lemmy.world 1 points 1 day ago

Yes, I type in a password each time.

load more comments (2 replies)
[–] DudleyMason@lemmy.ml 3 points 1 day ago

And typing in a password every time is the opposite of usability..

[–] ricecake@sh.itjust.works 18 points 2 days ago (2 children)

Why?

It's not like they're literally using your face or fingerprint as a password. They're not even storing them, just a hash tied to an hsm key.

[–] twjolson@lemmy.world 27 points 2 days ago (23 children)

I can't speak for OP, but in the US, you can be compelled to unlock a phone via fingerprint or face ID. You can't be compelled to give over your PIN. That violates the right against self incriminating.

[–] atrielienz@lemmy.world 2 points 1 day ago (1 children)

I love this "in the US" thing. Like we're the only country where that's true and there aren't whole European countries doing the exact same thing.

While I admit nothing exists in a vacuum and there's a lot of push toward a police state in the US, we also aren't the only country doing that, by far. We're just more open about it since Cheeto in Chief took office again.

[–] twjolson@lemmy.world 3 points 1 day ago (1 children)

Or maybe I don't have knowledge and experience in EU law and didn't want to pretend I do.

[–] atrielienz@lemmy.world 1 points 1 day ago (1 children)

It's not just you. There's quite a few people who keep saying this. You'll note that they don't chime in to mention that Norway or Germany.

It's dystopian as fuck that this is where we're at, but I don't think it's a good idea to pretend this is strictly a US thing.

[–] twjolson@lemmy.world 2 points 1 day ago* (last edited 1 day ago) (1 children)

Nobody did. You're arguing against a point nobody made.

[–] atrielienz@lemmy.world 1 points 10 hours ago (1 children)

Not the time or the crayons.

[–] twjolson@lemmy.world 1 points 10 hours ago (1 children)

Yea, ok bud. Go argue the obvious with someone else.

[–] atrielienz@lemmy.world 1 points 8 hours ago

You're arguing with me at this point.

[–] picnic@lemmy.dbzer0.com 3 points 1 day ago

I travel a few times a month to US, China, Hong Kong etc.

I shut down my grapheneos phone on the border. Graphene also allows you to set auto reboot to phone if unlocked from 10mins to like 72 hours.

I do use biometrics on my device. I think its a tradeoff I'm willing to make.

load more comments (21 replies)
load more comments (1 replies)
[–] JRaccoon@discuss.tchncs.de 17 points 2 days ago (9 children)

I think it depends. Some people might be inclined to use too short or simple password because they don't wanna constantly be typing a long password. It's much better to have a strong password and fingerprint/face rec for convince than just a insecure password.

[–] CubitOom@infosec.pub 18 points 2 days ago (30 children)

In the USA, they can legally force you to unlock a device using biometrics.

Also, biometrics can be fooled in other ways.

load more comments (30 replies)
load more comments (8 replies)
[–] unknownuserunknownlocation@kbin.earth 14 points 2 days ago (4 children)

Hot take: biometrics are often criticized for being less secure, but that ignores the deficiencies of passwords. Especially on phones, it's very doable to look over someone's shoulder while they're unlocking their phone or do the same with a camera. You can't do that with a fingerprint, at least not nearly as easily.

And yes, I understand that in the US (amongst others?) the legal situations with passwords and biometrics are different, but IMO that's more of a legal question, and not everyone lives in the US.

Android also has an "emergency lockdown" option, which disables biometrics for unlocking your phone - or you can shut it down (worst case scenario force shut down with a long hold on the power button) to get it into a BFU state, which is much harder to crack.

load more comments (4 replies)

Oh look it's opposite day again.

load more comments
view more: next ›