Example of why you should not use FaceID to unlock your phone, this time from Norway: in 2022, a 28yo man filmed a uniformed police officer assault his two 26yo friends. The officer took his phone, turned it towards him to unlock it and deleted the video. https://www.vg.no/nyheter/innenriks/i/8J7A5w/politivolden-i-kongsberg-dette-vet-vi
Politivolden i Kongsberg: Dette vet vi

Minst 21 slag, sletting av bevis og slag med batong. Få oversikt over politivold-saken i Kongsberg her.

VG
@runasand that’s what the 5 power button press are for, not the best solution but that allows you to instantly force the pin!
@fuomag9 @runasand Five power button presses is for an emergency call. To lock the device and require a passcode to unlock, just press and hold the power button and one of the volume buttons simultaneously. That’s really quick and easy to do.
@thomasareed @fuomag9 @runasand I thought you could also just close your eyes
@ShaneB @thomasareed @runasand Yes, but I'd guess that in a case like this you'd probably would not want to close them
@ShaneB @fuomag9 @runasand In theory… though, that’s something that could be coerced, and it’s also not 100% reliable. I have unlocked my own phone with my eyes closed before.
@thomasareed @ShaneB @fuomag9 @runasand It's hard to think of an unlock method that couldn't be coerced. If somebody points a gun at you and tells you to type in your passcode...
@ShaneB @thomasareed @fuomag9 @runasand keeping your eyes closed prevents faceid but when you open your eyes then faceid will unlock. Just tested this.
@ShaneB @thomasareed @fuomag9 @runasand in my own experiments, it – disappointingly – unlocks with my eyes closed. It does not unlock if my eyes are open but I don't look at the screen. (There's a "Require Attention for FaceID" setting.)
@thomasareed @runasand They both work, so even more choice! And I guess also calling for help here wouldn't be bad, if it were a third party instead of the police
@fuomag9 @runasand Unfortunately, in this case, I don’t think that would be great. At least in the US, it’s an emergency call via 911, which would ultimately go to the local police… probably the dude’s buddies. I’d assume it would go to the equivalent of 911 in other countries as well.

@thomasareed @fuomag9 @runasand

Is that iOS, Android, or both?

@atatassault @fuomag9 @runasand This is specifically iOS we’re talking about. Any facial recognition an Android device has is not the same as Face ID, and will not work the same.
@runasand but if you do want the convenience of FaceID, practice the 5 rapid clics on right button in any tense situation and it will disable faceid instantly
@runasand This is why I unlock my phone with an actual password (not a pin), even though it's really inconvenient. It also protects you and your digital life if your phone gets snatched by a thief.
@runasand It's also a flaw in deletion workflow.

@runasand The problem is, a PIN wouldn’t be any better, as the officer could have coerced him to enter it. Or he could simply smash the phone in hopes that the video had not yet been synced to iCloud, or that the device wasn’t set to sync to iCloud… both potentially reasonable expectations.

There’s no security that can entirely protect against this kind of situation. In contrast, though, using Face ID or Touch ID absolutely does protect against someone shoulder-surfing your PIN, then stealing your phone, unlocking it, and getting your phone plus capturing your Apple ID a bonus.

@runasand @cstross

Pro tips:

1) You can quickly disable biometrics on iPhone by pressing the sleep/wake button 5x (disable ‘call with 5 buttons’ under Settings -> Emergency SOS to prevent iPhone calling emergency services when you do this).

2) you can (unless you’ve disabled it) access your camera from the lock screen and record pics/videos without having to unlock first.

3) Have photos turned on for iCloud and images and videos you shoot get uploaded, hopefully faster than a LEO might destroy a phone.

@Sonikku @runasand @cstross 1 and 2 are excellent tips, but I would like to note that by default if you delete something from an iPhone it will also be deleting from iCloud and other devices.
@glindsey @runasand @cstross true, but if you’re recording from the lock screen camera shortcut you can’t get to the deleting without authenticating first
@runasand if you put a gun to the phone owner's head, you can bypass any security on the phone. Although you could argue that it's easier with face id
@runasand @cstross I never use biometrics for anything, because I never want to give anyone extra incentive to value parts of my body more highly than I do.
@runasand, yup. Thats why you should have Face ID with MANDATORY focus turned on. Then you just have not to look on the phone. Stop posting bullshit hints.
@runasand That's why I always advise that when filming the #police, #record not only locally but #stream to some #secure server that the authorities won't be able to easily block or demand removal. I, for example, have set my phone to stream to my #peertube server, which I can turn on with one key and the stream keeps running even with locked phone.
@miklo Cool, what apps are you using for streaming and one-key access?
@kuba #LarixBroadcaster for #peertube streaming, peertube setup for permanent/recurring live and #KeyMapper to assign phone hardware key to application
How to quickly disable Face ID and force iPhone to require passcode

Sometimes in an emergency you might want to disable Face ID. It's easy to do this on the latest iPhones and all it takes is just one step...

PhoneArena

@runasand
And in the USA, a PIN or password are protected by the 5th amendment / miranda rights. No one can legally force you to give them.

However, they can legally force you to *act*. To press your finger on the sensor, to stand in front of your phone for FaceID.

@runasand Using a Passcode is hugely more insecure than Face ID in public settings. Can be eavesdropped. In the situation you linked, simply making a funny/weird face has Face ID stop working. Make it a few times and it deactivates Face ID.

@runasand Also: if you enable fingerprint unlock, don't use your index finger. Probably don't even use your thumb.

I wouldn't even have my lock screen fingerprint enabled if enabling biometrics for apps didn't have that as a side effect.

@runasand 👏 ALDRI 👏 BRUK 👏 BIOMETRI 👏 PÅ 👏 TELEFONEN
@runasand

If this happens to you, hold the power button to quickly turn off face id

Not to victim blame because sometimes that's not possible.

https://idiomdrottning.org/acab 🚨
An even-handed and restrained criticism of police

@runasand ngl I wouldn't let them do that to me
@runasand I'd go a step farther and remind people NOT to bring their regular personal devices to protests and such. Bring a burner or old phone if you must. It won't matter then if you don't activate FaceID, even if the burner has that option. #privacy #security
@zachvat @runasand this was definitely the case with both Antifa and Jan 6, people who were there with their phones got arrested later.

@runasand THIS is why any video you take of police should be done on Facebook live feed.

"Officer, you're already a star, and nothing you do to me will change that."

@runasand the fact this happened in Norway of all places
@runasand I keep seeing press power five times to force a passcode. Though, holding volume up and power would be quicker/more reliable vs a miscount to five

@runasand

Hmm, I don't use phone assistants AT ALL, but this seems like a good case for having it on only so you can shout the phrase "Hey Siri/Google, Lock my phone." which would put it into a password/pin only state.

@runasand

Good call on this. If you have a fingerprint sensor, use that. That's the most secure.