Android P Will Encourage OEMs to Adopt Stronger Biometric Systems

The three authentication factors. (Image credit: Google)

Starting with Android P, device makers will have to pass new security-focused benchmarks for their biometric authentication systems if they want their customers to have a better biometric authentication experience.

Latest Videos FromTom's Hardware
Contributor

Lucian Armasu is a Contributing Writer for Tom's Hardware US. He covers software news and the issues surrounding privacy and security.

  • InvalidError
    I personally don't care how strong biometrics are: no matter how good they are, relying on biometrics mean you can be strong-harmed into unlocking your devices against your will. With reasonably strong passwords only known to you on a secure device, your data is as safe as you are willing it to be.
    Reply
  • mrjhh
    INVALIDERROR - And you think a password is safe from a strong-arm approach? Passwords can also be captured from taking a video of you entering the password. This is why a strong authentication is recommended to have two factors from the three options of what you know, what you have, and biometrics. But, with strong authentication, bad guys look for weaker links, like someone at your bank who uses a password of abc123.
    Reply
  • TJ Hooker
    @InvalidError If an attack is willing/able to grab you, force your eye/face/thumb up to your phone and steal your device, I wouldn't put it past that person to just beat any password out of you instead if required. Unless you're including 'standing up to torture' as part of "as safe as you are willing it to be".
    Reply
  • InvalidError
    21080311 said:
    Unless you're including 'standing up to torture' as part of "as safe as you are willing it to be".
    I was.

    With biometrics only, you have very limited capability of preventing forceful unlock and once your biometrics are compromised by whatever means, you can't change them either. With passwords or "things only you know", you have the option of taking your passwords and your data all the way to the grave if you want to.

    Personally, I would be mainly concerned with warrantless searches. If police wants to break into my phone, I'll have them produce proof of plausible cause before I give them access.
    Reply
  • randomizer
    21080518 said:
    With biometrics only, you have very limited capability of preventing forceful unlock and once your biometrics are compromised by whatever means, you can't change them either.
    I think this is the biggest issue with biometrics. They're convenient but they're basically static. It's comparable to using the same password everywhere and being unable to change it when it's compromised.

    21080518 said:
    With passwords or "things only you know", you have the option of taking your passwords and your data all the way to the grave if you want to.
    It's a nice option to have but in practice few people would take it. I only need one of your fingers to pass the biometric scan. I can use the other nine to extract the password from your head. :)
    Reply
  • InvalidError
    21083666 said:
    It's a nice option to have but in practice few people would take it. I only need one of your fingers to pass the biometric scan. I can use the other nine to extract the password from your head. :)
    For people who are mainly concerned about resisting warrantless searches, the torture option is generally not available to law enforcement in civilized countries :)
    Reply
  • DotNetMaster777
    Biometric API wow !!
    Reply
  • Mr5oh
    21079595 said:
    I personally don't care how strong biometrics are: no matter how good they are, relying on biometrics mean you can be strong-harmed into unlocking your devices against your will. With reasonably strong passwords only known to you on a secure device, your data is as safe as you are willing it to be.

    Not to mention in the US, you can plead the 5th on a password, you can not on a fingerprint. You can be forced to unlock your phone by finger print if it will. At least this has been the way this has gone down historically.
    Reply
  • InvalidError
    21087686 said:
    Not to mention in the US, you can plead the 5th on a password, you can not on a fingerprint. You can be forced to unlock your phone by finger print if it will. At least this has been the way this has gone down historically.
    Pleading the fifth only comes after you have been indicted and are facing possible criminal charges. With biometric unlock, police can perform multiple breaches of due process such as wrongful arrest, arrest under false pretense and warrantless search, then charge you of other stuff based on what it finds on your devices, then you have tons of extra accusations to deal with while building your violation of due process case to get the whole thing thrown out of court.

    With a strong password, the police will have to prove just cause to want your devices decrypted before there are any consequences to denying access and you have a fair chance of not getting to the point of needing to plead the fifth. (At least not for reasons completely unrelated to your original arrest.)

    Got to love how the privately run prison system in the USA has corrupted or is colluding with large chunks of the legal system to imprison as many people as possible for as long as possible for profit.
    Reply
  • electronicbineries
    What difference does it make when all the CPU's in the market are plagued with security holes that allows hackers to steal passwords and encryption keys.
    Reply