# Advantages of fingerprint sign in on cell phone?

**URL:** <https://boards.straightdope.com/t/advantages-of-fingerprint-sign-in-on-cell-phone/757258>\
**Category:** In My Humble Opinion\
**Created:** [June 13, 2016, 4:08pm UTC](https://boards.straightdope.com/t/advantages-of-fingerprint-sign-in-on-cell-phone/757258 "2016-06-13T16:08:37Z")\
**Posts on this page:** 20\
**Page:** 3

<div class="post-metadata">

**Author:** ![chorpler](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chorpler/32/2888_2.png) [@chorpler](https://boards.straightdope.com/u/chorpler)\
**Post date:** [June 14, 2016, 5:28am UTC](https://boards.straightdope.com/t/advantages-of-fingerprint-sign-in-on-cell-phone/757258/41 "2016-06-14T05:28:45Z")

</div>

If the phone is storing a copy of the fingerprint in any way that remote hackers can obtain it, there’s a big problem with the implementation. And in fact that’s exactly what happened in some of HTC’s [implementations](https://www.theguardian.com/technology/2015/aug/10/htc-fingerprints-world-readable-unencrypted-folder) – they left an image of the user’s fingerprint sitting in a public directory on the phone, essentially. In a better implementation, like Apple’s or (I believe) Samsung’s, there isn’t any way to remotely steal the user’s fingerprint because it never exists in the phone memory.

Android has only actually had official support for fingerprint scanners since Android 6.0 (Marshmallow) came out. Before that, it was up to the phone manufacturer (HTC or Samsung or Motorola or whoever) to implement it themselves, and apparently they don’t always do a good job with that kind of thing.

I often like to use my Bluetooth fingerprint scanner to let people scan their prints and show them actual images of the fingerprint the phone. It’s a good marketing stunt, since people like to see visual representations like that, but nobody has ever asked me if the app is saving those images. (It’s not.)

---

<div class="post-metadata">

**Author:** ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)\
**Post date:** [June 14, 2016, 1:04pm UTC](https://boards.straightdope.com/t/advantages-of-fingerprint-sign-in-on-cell-phone/757258/42 "2016-06-14T13:04:42Z")

</div>

1. _Any_ method of storing a fingerprint is _always_ a “Mathematical representation”. Raw scan, jpeg, whatever. Saying something is a Mathematical representation is a completely _meaningless_ phrase in this context. It’s no different than saying it’s “stored in bits” or some such.

You’d be astonished what crypto experts are able to divine from supposedly encoded data.

1. The fingerprint data _has_ to be able to be written and read. While a manufacturing might take extra steps to prevent simple reading of it, there are _always_ holes. Who knows if someone has found a hole to get the fingerprint from secure storage? Security is even less likely if the entire system hasn’t been publicly vetted.

You just can _never_ trust a company’s security claim on its own.

---

<div class="post-metadata">

**Author:** ![Pixel\_Dent](https://avatars.discourse-cdn.com/v4/letter/p/bc8723/32.png) [@Pixel\_Dent](https://boards.straightdope.com/u/Pixel_Dent)\
**Post date:** [June 14, 2016, 2:10pm UTC](https://boards.straightdope.com/t/advantages-of-fingerprint-sign-in-on-cell-phone/757258/43 "2016-06-14T14:10:15Z")

</div>

> [@beowulff](#):
>
> Works pretty well for me - (iPhone 6).  
> I LOVE it for Apple Pay, and for signing into my BofA and 1Password accounts.

This is my experience as well.

6 month old iPhone. Fingerprint recognition works flawlessly. About 1/3rd of my POS transactions these days are Apple Pay where I just wave the sleeping, locked phone and touch the fingerprint pad. Many but not all apps which should be locked all the time like 1Password or my bank app get unlocked via fingerprint as well. Some apps for purchasing things use Apple Pay via fingerprint as well.

I really hope this sort of thing ends up replacing credit cards entirely at some point.

---

<div class="post-metadata">

**Author:** ![Pixel\_Dent](https://avatars.discourse-cdn.com/v4/letter/p/bc8723/32.png) [@Pixel\_Dent](https://boards.straightdope.com/u/Pixel_Dent)\
**Post date:** [June 14, 2016, 2:13pm UTC](https://boards.straightdope.com/t/advantages-of-fingerprint-sign-in-on-cell-phone/757258/44 "2016-06-14T14:13:28Z")

</div>

> [@Senegoid](#):
>
> I’ve also seen it pointed out that, if your fingerprint gets hacked, you can’t just change it like you can change your password. You’re stuck with it forever, and if it’s hacked, the hacker has it forever too.  
> \

Actually I have 10 fingers each with a different fingerprint. In the unlikely case that one of my fingerprints was “hacked” on my phone I’d just delete that fingerprint from the phone and use a different finger.

---

<div class="post-metadata">

**Author:** ![Pixel\_Dent](https://avatars.discourse-cdn.com/v4/letter/p/bc8723/32.png) [@Pixel\_Dent](https://boards.straightdope.com/u/Pixel_Dent)\
**Post date:** [June 14, 2016, 2:16pm UTC](https://boards.straightdope.com/t/advantages-of-fingerprint-sign-in-on-cell-phone/757258/45 "2016-06-14T14:16:55Z")

</div>

While more complicated than simply encrypting stored passwords using a one way hash function, I’d hope that something similar is being used for the fingerprints.

E.g. the original fingerprint is encrypted via one direction encryption and stored. The current fingerprint is encrypted using the same method. Encrypted versions are compared.

---

<div class="post-metadata">

**Author:** ![TwoCarrotSnowman](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/twocarrotsnowman/32/15879_2.png) [@TwoCarrotSnowman](https://boards.straightdope.com/u/TwoCarrotSnowman)\
**Post date:** [June 14, 2016, 2:17pm UTC](https://boards.straightdope.com/t/advantages-of-fingerprint-sign-in-on-cell-phone/757258/46 "2016-06-14T14:17:11Z")

</div>

The biggest problem I have with Touch ID is that I have it on my iPhone but not my iPad. If I haven’t used the tablet in a while, I usually forget and try to unlock it with a fingerprint. 🙂

I’m a big fan of touch-to-unlock, and rarely have problems with it.  
Sent from my iPhone using Tapatalk

---

<div class="post-metadata">

**Author:** ![markn\_1](https://avatars.discourse-cdn.com/v4/letter/m/f9ae1b/32.png) [@markn\_1](https://boards.straightdope.com/u/markn_1)\
**Post date:** [June 14, 2016, 2:34pm UTC](https://boards.straightdope.com/t/advantages-of-fingerprint-sign-in-on-cell-phone/757258/47 "2016-06-14T14:34:27Z")

</div>

> [@Pixel\_Dent](#):
>
> While more complicated than simply encrypting stored passwords using a one way hash function, I’d hope that something similar is being used for the fingerprints.
> 
> E.g. the original fingerprint is encrypted via one direction encryption and stored. The current fingerprint is encrypted using the same method. Encrypted versions are compared.

Unfortunately it can’t work that way because the fingerprint reader doesn’t produce the exact same bit-for-bit identical image every time it scans a finger. The software needs to do a fuzzy match on the two images to see if they are similar, not identical. Hashing would not allow that kind of matching. It works for passwords but not for images.

–Mark

---

<div class="post-metadata">

**Author:** ![Rachellelogram](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/rachellelogram/32/8689_2.png) [@Rachellelogram](https://boards.straightdope.com/u/Rachellelogram)\
**Post date:** [June 14, 2016, 2:35pm UTC](https://boards.straightdope.com/t/advantages-of-fingerprint-sign-in-on-cell-phone/757258/48 "2016-06-14T14:35:25Z")

</div>

> [@Arcite](#):
>
> Yeah, the disadvantage is that it doesn’t work. I have this feature turned off on both my Samsung Galaxy S6, and my Ipad. When I first register my fingerprint, it works, but its ability to recognize my fingerprint somehow decays over a few days, so that I have to re-register it.

Likewise on my Galaxy S7. I tried it the first day, took me 3 tries to get it unlocked after I set my thumbprint. I disabled the feature out of fear of locking myself out of my own damn phone.

---

<div class="post-metadata">

**Author:** ![Pixel\_Dent](https://avatars.discourse-cdn.com/v4/letter/p/bc8723/32.png) [@Pixel\_Dent](https://boards.straightdope.com/u/Pixel_Dent)\
**Post date:** [June 14, 2016, 3:29pm UTC](https://boards.straightdope.com/t/advantages-of-fingerprint-sign-in-on-cell-phone/757258/49 "2016-06-14T15:29:26Z")

</div>

> [@markn\_1](#):
>
> Unfortunately it can’t work that way because the fingerprint reader doesn’t produce the exact same bit-for-bit identical image every time it scans a finger. The software needs to do a fuzzy match on the two images to see if they are similar, not identical. Hashing would not allow that kind of matching. It works for passwords but not for images.
> 
> –Mark

A trivial google revealed plenty of white papers on fuzzy comparisons of fingerprints after the application of non-invertible transforms. I don’t know that Apple does it this way, but there is both a theoretical basis and working models for it.

---

<div class="post-metadata">

**Author:** ![scr4](https://avatars.discourse-cdn.com/v4/letter/s/59ef9b/32.png) [@scr4](https://boards.straightdope.com/u/scr4)\
**Post date:** [June 14, 2016, 3:38pm UTC](https://boards.straightdope.com/t/advantages-of-fingerprint-sign-in-on-cell-phone/757258/50 "2016-06-14T15:38:59Z")

</div>

> [@Rachellelogram](#):
>
> Likewise on my Galaxy S7. I tried it the first day, took me 3 tries to get it unlocked after I set my thumbprint. I disabled the feature out of fear of locking myself out of my own damn phone.

There’s no danger of that, you can always bypass the fingerprint scanner and unlock it with a password or PIN.

---

<div class="post-metadata">

**Author:** ![Colibri](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/colibri/32/1841_2.png) [@Colibri](https://boards.straightdope.com/u/Colibri)\
**Post date:** [June 14, 2016, 3:58pm UTC](https://boards.straightdope.com/t/advantages-of-fingerprint-sign-in-on-cell-phone/757258/51 "2016-06-14T15:58:37Z")

</div>

This is probably better suited to IMHO.

Colibri  
General Questions Moderator

---

<div class="post-metadata">

**Author:** ![iamthewalrus\_3](https://avatars.discourse-cdn.com/v4/letter/i/258eb7/32.png) [@iamthewalrus\_3](https://boards.straightdope.com/u/iamthewalrus_3)\
**Post date:** [June 14, 2016, 6:18pm UTC](https://boards.straightdope.com/t/advantages-of-fingerprint-sign-in-on-cell-phone/757258/52 "2016-06-14T18:18:27Z")

</div>

> [@Pixel\_Dent](#):
>
> Actually I have 10 fingers each with a different fingerprint. In the unlikely case that one of my fingerprints was “hacked” on my phone I’d just delete that fingerprint from the phone and use a different finger.

That doesn’t solve the problem, though, it just delays it. You are going to run out of fingers at some point, and then what?

My guess is that the issue of not being able to change your biometrics will be solved by ever-higher resolution scanners. Sure, you can’t get a new retina or fingerprint to scan, but if the next generation of scanners can pick up things that the previous generation didn’t, then it should be able to stay ahead of the copies for a while. So, biometrics will be subject to cat and mouse tactics and arms races just like pretty much every other security technology.

I also expect that the severed finger/eyeball risk will remain slim. When I go to doctor, they put a little thing on my finger that measures my blood oxygen content with light transmission. Surely it’s not _that hard_ to make a scanner that can tell if the finger/eyeball is attached to a live body.

---

<div class="post-metadata">

**Author:** ![beowulff](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/beowulff/32/542_2.png) [@beowulff](https://boards.straightdope.com/u/beowulff)\
**Post date:** [June 14, 2016, 6:32pm UTC](https://boards.straightdope.com/t/advantages-of-fingerprint-sign-in-on-cell-phone/757258/53 "2016-06-14T18:32:29Z")

</div>

> [@iamthewalrus\_3](#):
>
> That doesn’t solve the problem, though, it just delays it. You are going to run out of fingers at some point, and then what?
> 
> My guess is that the issue of not being able to change your biometrics will be solved by ever-higher resolution scanners. Sure, you can’t get a new retina or fingerprint to scan, but if the next generation of scanners can pick up things that the previous generation didn’t, then it should be able to stay ahead of the copies for a while. So, biometrics will be subject to cat and mouse tactics and arms races just like pretty much every other security technology.
> 
> I also expect that the severed finger/eyeball risk will remain slim. When I go to doctor, they put a little thing on my finger that measures my blood oxygen content with light transmission. Surely it’s not _that hard_ to make a scanner that can tell if the finger/eyeball is attached to a live body.

I still don’t understand what the supposed threat is.  
Having your fingerprint doesn’t do a hacker any good, unless he also has your phone.  
If you get your phone stolen, you can wipe it remotely, certainly long before anyone would be able to print a copy of your fingerprint and unlock it.  
Also, 99.99% of phones are stolen to re-sell. Only people like James Bond need to worry about a targeted attack.

---

<div class="post-metadata">

**Author:** ![harmonicamoon](https://avatars.discourse-cdn.com/v4/letter/h/65b543/32.png) [@harmonicamoon](https://boards.straightdope.com/u/harmonicamoon)\
**Post date:** [June 14, 2016, 7:28pm UTC](https://boards.straightdope.com/t/advantages-of-fingerprint-sign-in-on-cell-phone/757258/54 "2016-06-14T19:28:09Z")

</div>

> [@Colibri](#):
>
> This is probably better suited to IMHO.
> 
> Colibri  
> General Questions Moderator

I opened this thread in GQ because I wanted factual answers. I got them. Thank you everyone.

I also learned that a keyboard entry can override the print ID. This is good because, if I should move on, my daughter can have my iPhone.

Again, thank you for your replies.

---

<div class="post-metadata">

**Author:** ![Arcite](https://avatars.discourse-cdn.com/v4/letter/a/67e7ee/32.png) [@Arcite](https://boards.straightdope.com/u/Arcite)\
**Post date:** [June 15, 2016, 1:23am UTC](https://boards.straightdope.com/t/advantages-of-fingerprint-sign-in-on-cell-phone/757258/55 "2016-06-15T01:23:10Z")

</div>

> [@scr4](#):
>
> Works fine on _my_ Galaxy S6. I think the important thing is to hold the phone the same way when you register your fingerprint & when you unlock it every time. This makes sure the same part of your thumb gets scanned. The sensor is fairly small.
> 
> The downside is it doesn’t work with gloves on.

> [@Cyros](#):
>
> I have a Nexus 5x and the fingerprint sensor works very well. It is very convenient to be able to pick up the phone and have it turn on and sign in. The Nexus takes several different samples of your fingerprint so you don’t have to be careful to hold it the same way each time.

> [@SpeedwayRyan](#):
>
> As a counterpoint, I’ve used the feature on my last two iPhones and have never once had this problem, and I’ve never had to re-register/setup the fingerprint scan.
> 
> On an unrelated note, I always scan both thumbs and both index fingers at a minimum…that way it works in either hand, works when sitting on a table or holding something and an index finger is more convenient than a thumb, etc. Takes a couple of minutes up front and makes it even more convenient to use.

> [@rbroome](#):
>
> I have had my iPhone 6 since they came out. I have never had to register my fingerprint. My wife has her print encoded in the phone and she uses that feature about once every six months. Never had a problem.

Well, despite that Rachellelogram and markn+ have had the same experience as I, you guys have inspired me to try it again. I’m not optimistic, though. When I’ve tried it before, I have registered my print multiple times, and it works at first, but it’s a gradual decline. After a few days, it starts taking several tries, then it gradually starts taking more and more tries with each passing day, until eventually it doesn’t work at all. I think I get a little dry skin, the skin on my fingertips gets a little flaky or something, and the print is just too different.

---

<div class="post-metadata">

**Author:** ![carnivorousplant](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/carnivorousplant/32/3563_2.png) [@carnivorousplant](https://boards.straightdope.com/u/carnivorousplant)\
**Post date:** [June 15, 2016, 1:52am UTC](https://boards.straightdope.com/t/advantages-of-fingerprint-sign-in-on-cell-phone/757258/56 "2016-06-15T01:52:59Z")

</div>

> [@Arcite](#):
>
> Well, despite that Rachellelogram and markn+ have had the same experience as I, you guys have inspired me to try it again. I’m not optimistic, though. When I’ve tried it before, I have registered my print multiple times, and it works at first, but it’s a gradual decline. After a few days, it starts taking several tries, then it gradually starts taking more and more tries with each passing day, until eventually it doesn’t work at all. I think I get a little dry skin, the skin on my fingertips gets a little flaky or something, and the print is just too different.

If your fingerprints change over time, you should consider a career as a master thief, a Second Story Man.

---

<div class="post-metadata">

**Author:** ![iamthewalrus\_3](https://avatars.discourse-cdn.com/v4/letter/i/258eb7/32.png) [@iamthewalrus\_3](https://boards.straightdope.com/u/iamthewalrus_3)\
**Post date:** [June 15, 2016, 6:08pm UTC](https://boards.straightdope.com/t/advantages-of-fingerprint-sign-in-on-cell-phone/757258/57 "2016-06-15T18:08:13Z")

</div>

> [@beowulff](#):
>
> I still don’t understand what the supposed threat is.  
> Having your fingerprint doesn’t do a hacker any good, unless he also has your phone.  
> If you get your phone stolen, you can wipe it remotely, certainly long before anyone would be able to print a copy of your fingerprint and unlock it.  
> Also, 99.99% of phones are stolen to re-sell. Only people like James Bond need to worry about a targeted attack.

The use of fingerprint biometrics will probably not be limited to phones, though. And now that someone has your fingerprint data, not just your current phone, but everything that will ever be secured by your fingerprint is at risk.

Yes, right now only James Bond needs to worry about a targeted attack. But you’re not considering the future. Right now, on the internet, people are buying and selling huge databases of credit card numbers and ATM card numbers and pins and social security numbers and tax return information. All of which can be used to commit fraud. But at least we can get new numbers for all those things, which makes the old data not useful for fraud.

Can’t get new fingerprints. So if your fingerprint is stolen once, then it’s stolen forever.

If you travel internationally, your fingerprint is probably on file in every country you’ve visited in the last few years (and will visit in the future). How comfortable would you be giving all those governments your phone password as a requirement for entry? And, not just one that’s good on your current phone, but every phone you’ll ever have.

---

<div class="post-metadata">

**Author:** ![beowulff](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/beowulff/32/542_2.png) [@beowulff](https://boards.straightdope.com/u/beowulff)\
**Post date:** [June 15, 2016, 6:14pm UTC](https://boards.straightdope.com/t/advantages-of-fingerprint-sign-in-on-cell-phone/757258/58 "2016-06-15T18:14:57Z")

</div>

> [@iamthewalrus\_3](#):
>
> The use of fingerprint biometrics will probably not be limited to phones, though. And now that someone has your fingerprint data, not just your current phone, but everything that will ever be secured by your fingerprint is at risk.
> 
> Yes, right now only James Bond needs to worry about a targeted attack. But you’re not considering the future. Right now, on the internet, people are buying and selling huge databases of credit card numbers and ATM card numbers and pins and social security numbers and tax return information. All of which can be used to commit fraud. But at least we can get new numbers for all those things, which makes the old data not useful for fraud.
> 
> Can’t get new fingerprints. So if your fingerprint is stolen once, then it’s stolen forever.
> 
> If you travel internationally, your fingerprint is probably on file in every country you’ve visited in the last few years (and will visit in the future). How comfortable would you be giving all those governments your phone password as a requirement for entry? And, not just one that’s good on your current phone, but every phone you’ll ever have.

That’s a theoretical risk I’ll worry about when it becomes an actual one.

---

<div class="post-metadata">

**Author:** ![MacSpon](https://avatars.discourse-cdn.com/v4/letter/m/34f0e0/32.png) [@MacSpon](https://boards.straightdope.com/u/MacSpon)\
**Post date:** [June 16, 2016, 3:02am UTC](https://boards.straightdope.com/t/advantages-of-fingerprint-sign-in-on-cell-phone/757258/59 "2016-06-16T03:02:36Z")

</div>

The big advantage of having a fingerprint reader is that it makes it _easy_ to have reasonable protection on your device, while still being able to unlock it quickly.

Does it give you _high_ security? No. As many have noted, it’s possible to lift a fingerprint and fool the fingerprint reader.

Nevertheless, for the vast majority of people, it’s _good enough_ security. And it’s so easy to use that you might as well use it…unlike, say, a good passphrase, which makes it such a pain in the ass to unlock your phone that most people won’t bother.

---

<div class="post-metadata">

**Author:** ![OffByOne](https://avatars.discourse-cdn.com/v4/letter/o/45deac/32.png) [@OffByOne](https://boards.straightdope.com/u/OffByOne)\
**Post date:** [June 17, 2016, 2:22pm UTC](https://boards.straightdope.com/t/advantages-of-fingerprint-sign-in-on-cell-phone/757258/60 "2016-06-17T14:22:51Z")

</div>

I have had exactly three experiences with fingerprint identification:

At a contract at Microsoft, my phone used fingerprint security. I slowly swiped my fingertip over the scanner a few times to “train” it, then swiped my fingertip to use the phone. That worked OK.

At a contract at Dish Networks, the entryway into the building used both card scanners and fingerprint scanners. I “trained” the system in the guard station office while I was getting my picture ID. That took a lot longer than usual, trying different fingers, until they found one that “worked.” We were supposed to use the fingerprint scanner first, and then swipe our card, but that never worked for me, so I started swiping my card first, reducing the time it took me to get in the building to (usually) under a minute.

At my current contract, we have a snack sales system that can use either our card or our fingerprint. I never have to remember to bring my fingerprints with me, so that is what I use most often. Scan my purchase, tap the “Account” icon, the position my thumb over the scanner. “Account not found.” Reposition thumb on scanner. “Account not found.”

Rinse and repeat.

[Previous page](https://boards.straightdope.com/t/advantages-of-fingerprint-sign-in-on-cell-phone/757258.md?page=2)

[Next page](https://boards.straightdope.com/t/advantages-of-fingerprint-sign-in-on-cell-phone/757258.md?page=4)
