Slashdot Mirror


Feds Can't Force You To Unlock Your iPhone With Finger Or Face, Judge Rules (forbes.com)

A California judge has ruled that American cops can't force people to unlock a mobile phone with their face or finger. The ruling goes further to protect people's private lives from government searches than any before and is being hailed as a potentially landmark decision. From a report: Previously, U.S. judges had ruled that police were allowed to force unlock devices like Apple's iPhone with biometrics, such as fingerprints, faces or irises. That was despite the fact feds weren't permitted to force a suspect to divulge a passcode. But according to a ruling uncovered by Forbes, all logins are equal. The order came from the U.S. District Court for the Northern District of California in the denial of a search warrant for an unspecified property in Oakland. The warrant was filed as part of an investigation into a Facebook extortion crime, in which a victim was asked to pay up or have an "embarassing" video of them publicly released. The cops had some suspects in mind and wanted to raid their property. In doing so, the feds also wanted to open up any phone on the premises via facial recognition, a fingerprint or an iris.

6 of 172 comments (clear)

  1. I can't imagine... by cayenne8 · · Score: 2, Insightful
    ...why anyone would want to use biometric passcodes to unlock anything so private as a cell phone is today.

    I know, most people don't seem to value privacy, but if you have any at all, doing biometric should be a no go from the start.

    --
    Light travels faster than sound. This is why some people appear bright until you hear them speak.........
    1. Re:I can't imagine... by Pascoea · · Score: 1, Insightful

      ...why anyone would want to use biometric passcodes to unlock anything so private as a cell phone is today. I know, most people don't seem to value privacy, but if you have any at all, doing biometric should be a no go from the start.

      Because I don't want to type in a password every time I look at my phone. I don't keep anything in the general storage that I don't want someone else to see. That "stuff" gets relegated an encrypted actual password protected "storage locker".

    2. Re:I can't imagine... by sexconker · · Score: 3, Insightful

      Biometrics are trash from every angle.

      They're incredibly fuzzy, which leads them to being easy to fool. Users can't reset their biometrics when they're compromised. And the biometrics can be used to identify an individual. You can either use a shitty biometric device that records the data directly, or compromise a trusted one to do so, thus letting you go from the "secure" element to the user. OR you can identify a suspected user (or as they tried to do in this case, a swath of them) and then force them to use biometrics to generate a hash and determine if it's a match or not.

      Passwords win out always.

  2. Can't force but... by the_skywise · · Score: 1, Insightful

    It's going to be really hard not to look at your iPhone if they hold it up quickly.

    1. Re:Can't force but... by captaindomon · · Score: 4, Insightful

      Yep and then in both of these cases the evidence will be thrown out of court. The point isn't to stop the police from being physically able to do something, it's to take away the incentive. If using the fingerprints they gathered when they booked you to unlock your phone results in the whole case being thrown out of court for lack of admissible evidence, and a civil counter-suit quickly filed by the person who was arrested, the police are going to stop doing that. Quickly. As someone once said on this board, it's the Judicial version of "Judge Hulk SMASH."

      --
      Just because I can hook a shark from a boat, I do no offer to wrestle it in the water.
  3. Not likely to make its way through appeals by Headw1nd · · Score: 5, Insightful

    I seriously doubt this is going to survive appeal. Providing your fingers and face, for fingerprints and lineups respectively, is already considered non-testimonial and well accepted. That providing these to unlock a phone is objectively the same as a passcode is irrelevant, a physical key such as a dongle would have the same purpose and it seems to be established that you could be compelled to hand it over to the police. In fact it seems in this case that the law is specifically unconcerned with the objective, and only concerned about the means.

    This does invalidate an earlier comment I made concerning using 3D sculpting to fool face recognition, I guess the government might need to look into it now. If this leads to a ridiculous chain where you cannot be compelled to look at your phone to unlock it, but you can be compelled to have your face 3D scanned so that a copy can be made and used to unlock your phone, then I will be disappointed but not surprised.