Hacker News new | past | comments | ask | show | jobs | submit login

It can be a reasonable tradeoff to leave it enabled, even knowing that the state can compel you to present your finger or face. If you disable it, you'll need to enter your passphrase regularly, which means it needs to be short and easy to enter, which usually means 4 to 6 digit numeric, which means you're more vulnerable to offline bruteforce attacks if you lose physical custody of your device. If you leave it enabled, and deauthenticate any time you're about to interact with a police officer, then you can use a longer and more complex passphrase, and be more secure if it's seized from you.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
