frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Stop Using Face ID

https://www.pcmag.com/explainers/why-you-should-stop-using-face-id-right-now?test_uuid=04IpBmWGZleS0I0J3epvMrC&test_variant=B
28•speckx•2h ago

Comments

runjake•1h ago
If you have Face ID enabled, you can put your iPhone in hard-lock mode and require a passcode by pressing and holding the side (aka power) button and either of the volume buttons for a couple seconds.

It will pop up an emergency screen, but just tap the power button once more to cancel it.

I'm fortunate to be in a position where I don't attract negative attention from law enforcement, but this is still muscle memory to me.

Edit: You can also do the same thing by quickly pressing the side button alone five times.

Edit 2: mcc1ane beat me while I was editing!

mcc1ane•1h ago
or 5 times the lock (power) button only
tessela•1h ago
… or you can just close your eyes, and move your face around. The device will not unlock if you're not looking at it and after 3 or 4 tries will ask for the password.
runjake•19m ago
Right, there’s a multitude of ways to trigger a passcode requirement, but the point here is quick/immediate procedures that can be learned into muscle memory.
telotortium•1h ago
Both of these methods have an undesirable side effect for me, which is that it immediately pops up the passcode dialog saying that a passcode is required to activate Face ID. Depending on the situation, that could be construed as an attempt to actively interfere with a police investigation, which could bring consequences of its own. It would be better if it silently dropped you to the normal lock screen, and only showed the passcode dialog when you attempt to unlock the phone normally.

Another thing I've often wished for with kids is a mode that removes all notifications and widgets from the lock screen - the only things you should be able to do is to unlock the phone and emergency calls. You can remove most notifications with the right Focus, but not notifications to control playing music/video apps, for example, nor any other widgets you happen to put on your lock screen.

willio58•39m ago
> Depending on the situation, that could be construed as an attempt to actively interfere with a police investigation

IANAL but I highly doubt this would hold up in court with even mildly competent attorneys. Anyone can easily accidentally trigger it, I do all the time.

runjake•21m ago
100%. But important to caveat that not everyone here falls under US jurisdiction.
scottiebarnes•27m ago
The same passcode prompt appears after software updates, multiple previous failed Face ID login attempts, and maybe more.

Not a lawyer, but everyone has a password locked phone and its standard practice for device security. I'm not optimistic for a prosecutor winning on an interference charge.

reflexe•1h ago
Or even better: turn off the device. Cracking cold/BFU (before first unlock) devices is not supported in many cases by tools like Cellebrite [1].

[1] https://discuss.privacyguides.net/t/updated-cellebrite-iphon... : support matrix from 2024, in many cases only AFU (after first unlock) is supported.

autoexec•1h ago
Stop using biometrics generally.
MattDamonSpace•1h ago
Too useful
10729287•55m ago
And also more secure unfortunately, when you need to unlock your phone in public for example.
autoexec•46m ago
The same public where you're constantly leaving your fingerprints, where your face is being constantly recorded and scanned into multiple facial recognition systems, where your DNA is being constantly shed? When everything needed to unlock your phone can be taken off of your corpse or just reconstructed from what you leave everywhere you go you're not really "secure".
nathanaldensr•44m ago
Exactly! Biometrics have never been less secure than they are now. It's approaching Social Security number levels of insecure. LOL
autoexec•26m ago
It's like using a password that can never be reset, writing it on a stack of post-it notes, then tearing one off and throwing it over your shoulder every 10 feet you travel
gruez•54m ago
No, because for most people, the alternative to "no biometrics" isn't "secure password/pin", it's a weak password (eg. 1234 or the S pattern that half the people with a pattern lock uses) because the ergonomics of a secure password are terrible.
autoexec•42m ago
Bad security, either in the form of weak passwords or biometrics is a choice.
nathanaldensr•46m ago
This is the advice I give to everyone who comes to me for digital security advice. I let them know that building habits of using lengthy PINs (my own personal PIN is far more than four or six digits) takes some time to get used to but makes them immune to device seizure followed by law enforcement-compelled or court-ordered biometric unlock (this is specific to US law).
samename•49m ago
How many times do you unlock your phone a day? For some people it’s over 100+ times a day Face ID is convenient, useful and secure. The alternative? People will use short numeric passcodes that are easy to bypass with devices like Cellulite.

Instead, we should push for laws and protections around our private devices. The 4th Amendment actually protects our personal effects and imo this biometric loophole is illegal.

As the other commenter pointed out, in the meantime, practice how to quickly lock your phone - and better yet, when in dangerous situations, leave it behind or turn it off.

willio58•44m ago
Does anyone know how devices like Cellebrite work? Like high level I assume it taps the numbers and has some algorithm that prioritizes common passcode patterns.

But how does it not get locked out the same way we do when we fail our passcode 5+ times in a row? Is it just super easy to get around that exponential lock-out for iOS?

snailmailman•16m ago
It is not super easy to get around that tech. It used to be easier a long time ago. Apple patches the methods every time they can, and have made hardware adjustments in attempt to make it as hard as possible. A lot of these methods involve tricking the counter so it doesnt increment at all, or somehow rolling it back. If the phone isnt set to wipe after 10 attempts, tricking the timer that time has passed would be enough.

Im not sure if anyone other than Cellebrite knows the exact details of what they are doing. (If they can even unlock latest iPhones that are properly secured. I’m seeing a recent article that implies recently unlocked iPhones had biometrics enabled) I wouldn’t be surprised if their techniques involved disassembling the phone, and tampering with every connection of the chips involved, or depowering them in weird ways as they are counting attempts, or even desoldering and transferring the chips to other boards. I suspect that if apple knew and could patch the method, they would.

It’s impressive that it is so hard to get into iPhones imo. People use 6 digit passcodes to lock their entire digital life. That would be considered horrendously insecure for anything that isn’t an iPhone. You can (and should) increase it to a full password. But a lot of people don’t.

eddyg•22m ago
The iPhone automatically goes into BFU (Before First Unlock) after 72 hours of inactivity (it actually reboots the phone). This can’t be disabled.

In addition, there are additional restrictions where your passcode will be required. For example, if the passcode has not been used to unlock the device in the last six days and Face ID has not unlocked the device in the last eight hours, then you must use a passcode to access the device (in other words, biometric unlock is automatically disabled).

If you've ever wondered why you've had to enter your passcode after a good night's sleep and haven't entered your passcode recently, that's probably why!

Given these built-in precautions, a click-bait headline like this is a bit excessive for most people.

jiggawatts•11m ago
To me this article is “meta” and tells a very different story: “America is an authoritarian hellhole where trivial matters such as how you lock your phone can put you in real danger. Not from gangs, but from the government.”

I went to the US on holidays recently and several people sat me down before I left to give me a very serious talk warning me about the police being deadly dangerous to anyone that doesn’t behave “just right”. You know: show your hands, don’t reach for things unless prompted, that kind of thing that I just don’t have to worry about over here — where “here” is most of the rest of the Planet.

The last time I felt like this — that I had to worry about the police as a law abiding citizen — was in communist behind the iron curtain.

You’ve all managed to turn the “land of the free” into a copy of the enemy you made fun of.

I guess Trump is right: the US and Russia should be friends. You’re more similar than different.

Vouch

https://github.com/mitchellh/vouch
267•chwtutha•16h ago•121 comments

I put a real-time 3D shader on the Game Boy Color

https://blog.otterstack.com/posts/202512-gbshader/
148•adunk•3h ago•12 comments

The Little Bool of Doom

https://blog.svgames.pl/article/the-little-bool-of-doom
40•pocksuppet•2h ago•7 comments

Roundcube Webmail: SVG feImage bypasses image blocking to track email opens

https://nullcathedral.com/posts/2026-02-08-roundcube-svg-feimage-remote-image-bypass/
44•nullcathedral•1h ago•9 comments

Show HN: I created a Mars colony RPG based on Kim Stanley Robinson's Mars books

https://underhillgame.com/
57•ariaalam•2h ago•22 comments

GitHub Agentic Workflows

https://github.github.io/gh-aw/
132•mooreds•6h ago•68 comments

RFC 3092 – Etymology of "Foo" (2001)

https://datatracker.ietf.org/doc/html/rfc3092
97•ipnon•5h ago•18 comments

Running Your Own As: BGP on FreeBSD with FRR, GRE Tunnels, and Policy Routing

https://blog.hofstede.it/running-your-own-as-bgp-on-freebsd-with-frr-gre-tunnels-and-policy-routing/
95•todsacerdoti•6h ago•38 comments

Exploiting signed bootloaders to circumvent UEFI Secure Boot

https://habr.com/en/articles/446238/
58•todsacerdoti•5h ago•26 comments

Omega-3 is inversely related to risk of early-onset dementia

https://pubmed.ncbi.nlm.nih.gov/41506004/
149•brandonb•3h ago•80 comments

Formally Verifying PBS Kids with Lean4

https://www.shadaj.me/writing/cyberchase-lean
42•shadaj•6d ago•1 comments

Bun v1.3.9

https://bun.com/blog/bun-v1.3.9
67•tosh•2h ago•19 comments

Dave Farber has died

https://lists.nanog.org/archives/list/nanog@lists.nanog.org/thread/TSNPJVFH4DKLINIKSMRIIVNHDG5XKJCM/
163•vitplister•8h ago•22 comments

Experts Have World Models. LLMs Have Word Models

https://www.latent.space/p/adversarial-reasoning
11•aaronng91•1h ago•7 comments

Billing can be bypassed using a combo of subagents with an agent definition

https://github.com/microsoft/vscode/issues/292452
134•napolux•3h ago•71 comments

Curating a Show on My Ineffable Mother, Ursula K. Le Guin

https://hyperallergic.com/curating-a-show-on-my-ineffable-mother-ursula-k-le-guin/
117•bryanrasmussen•9h ago•41 comments

Let's compile Quake like it's 1997

https://fabiensanglard.net/compile_like_1997/index.html
76•birdculture•2h ago•21 comments

Show HN: It took 4 years to sell my startup. I wrote a book about it

https://derekyan.com/ma-book/
144•zhyan7109•4d ago•39 comments

The First Sodium-Ion Battery EV Is a Winter Range Monster

https://insideevs.com/news/786509/catl-changan-worlds-first-sodium-ion-battery-ev/
81•andrewjneumann•2h ago•68 comments

Kolakoski Sequence

https://en.wikipedia.org/wiki/Kolakoski_sequence
49•surprisetalk•6d ago•11 comments

OpenClaw is changing my life

https://reorx.com/blog/openclaw-is-changing-my-life/
145•novoreorx•13h ago•242 comments

Reverse Engineering Raiders of the Lost Ark for the Atari 2600

https://github.com/joshuanwalker/Raiders2600
76•pacod•10h ago•2 comments

Why E cores make Apple silicon fast

https://eclecticlight.co/2026/02/08/last-week-on-my-mac-why-e-cores-make-apple-silicon-fast/
187•ingve•8h ago•194 comments

A Community-Curated Nancy Drew Collection

https://blog.openlibrary.org/2026/01/30/a-community-curated-nancy-drew-collection/
3•sohkamyung•5d ago•1 comments

Matchlock – Secures AI agent workloads with a Linux-based sandbox

https://github.com/jingkaihe/matchlock
122•jingkai_he•12h ago•48 comments

Slop Terrifies Me

https://ezhik.jp/ai-slop-terrifies-me/
276•Ezhik•9h ago•248 comments

Show HN: LocalGPT – A local-first AI assistant in Rust with persistent memory

https://github.com/localgpt-app/localgpt
303•yi_wang•18h ago•142 comments

Beyond agentic coding

https://haskellforall.com/2026/02/beyond-agentic-coding
225•RebelPotato•18h ago•83 comments

We mourn our craft

https://nolanlawson.com/2026/02/07/we-mourn-our-craft/
627•ColinWright•1d ago•730 comments

DoNotNotify is now Open Source

https://donotnotify.com/opensource.html
353•awaaz•12h ago•47 comments