Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Qualcomm is apparently the main difficulty : https://arstechnica.com/gadgets/2021/03/the-fairphone-2-hits...

Fairphone do manage to keep up tho. The Fairphone 3 was updated to android 13 a few month ago.

https://support.fairphone.com/hc/en-us/articles/997918043739...



I didn't upgrade yet to 13 because they said the vendor for the fingerprint reader in the FP3 has not registered/validated/whatever for Google's security standards on Android 13 yet, thus possibly causing issues with apps that require strong security (banking apps, for example). What is strange though is that if a banking app can't use the fingerprint reader on 13, it will then default to PINs - aren't PINs weaker security-wise than biometric logins?


>aren't PINs weaker security-wise than biometric logins?

Depends on how you look at it. I'll focus on fingerprint here.

Sure, there are far more possible fingerprint features that can be identified for accept/decline decision "Does this match a registered fingerprint", than 1,0000 PIN combinations (4 digits).

But if the fingerprint reader is too lax in matching, it's possibly worse.

If you can crash the fingerprint reader system, which then accepts all future patterns, that's worse.

If you can trick the system into revealing all the biometric data it's collected, and then replay it directly without using the sensor using their debugging interface, that's worse.

That's not to say defaulting to PINs is or isn't the "least bad" option. Just that it's more complicated than the question makes it look.

There are other issues around your question in general that aren't particularly relevant in context:

You can't reasonably change or revoke your PIN.

Your device is likely covered in your fingerprints.


> You can't reasonably change or revoke your PIN.

i can, have, and will

> Your device is likely covered in your fingerprints.

true, fingerprints are not (a) secret


Sorry, that was a typing error, you obviously can do that with a PIN. Which was the point I was trying to make.

I meant you can't reasonably change or revoke your fingerprints!

Changing your actual fingerprints, while possible, is usually painful and done accidentally.

(The best you can do is change from which fingers the prints will accepted. And at best, you only have a couple of handfuls of options there.)


Thanks for the explanation. I really didn't understand it but figured there is something I was missing here.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: