Post
Topic
Board Speculation (Altcoins)
Re: [XMR] Monero Speculation
by
ArticMine
on 12/04/2016, 23:31:29 UTC
...

But that is because the user didn't wipe their fingerprint off the phone. That doesn't prove that TouchID has an insecure DRM.

Precisely what sort of access would you recommend for a mobile device? Uses will not memorize a secure password.

A separate key they carry on their keychain?

Be honest with the end user rather than try to mislead in order to market. Giving the end user a false sense of security is far worse than no security at all. The key here is that the end user makes an informed choice. The user then makes a trade off between security and convenience.

1) A secure password.
2) A separate key that can be inserted into the device.
3) No security. Rely only on physical possession. User does not keep sensitive data on the device.
4) Weak security / DRM. Useful only if one wants to delay rather than prevent access. This can be effective where time is of the essence to an attacker.

An example of (4) where delay could work. Let us say one stores the Monero keywords un encrypted on a 5.25in floppy disk, and then places the 5.25in floppy disk in a bank safety deposit box. If the safety deposit box is compromised then the owner can empty the Monero wallet while the attacker tries to figure out how to read the 5.25 in floppy disk. One the other hand let us say the owner dies. Then the executor of the Monero owner's estate has ample time to figure out how to read the 5.25 in floppy disk.