is there a way to encrypt file with fingerprint (android 13) ?

Discussion in 'privacy general' started by mantra, Jan 4, 2025.

  1. mantra

    mantra Registered Member

    Joined:
    Jan 25, 2005
    Posts:
    6,281
    Hi


    is there a way to encrypt file with fingerprint ?
    for example password files or password database with my fingerprint ?

    I was tring to do it with a cheap phone xioami redmi note 13 pro , there are many tutorials on youtube ,but never understood how to do it

    thanks
     
  2. Palancar

    Palancar Registered Member

    Joined:
    Oct 26, 2011
    Posts:
    2,462
    That is what Android already does with Knox Security on their devices. Maybe reading through the process they use will shed some light.

    My thoughts because I always lean to security is that while your fingerprint is unique you could easily be forced to provide it to an adversary. It CAN be copied and used directly from any object you touch as well. Watch movies it happens ---- > LOL!!
     
  3. longshots

    longshots Registered Member

    Joined:
    Oct 20, 2017
    Posts:
    649
    Location:
    Australia
    You forgot the fun bit - it can also be chopped off...perfect spot for the emoji...
     
  4. zapjb

    zapjb Registered Member

    Joined:
    Nov 15, 2005
    Posts:
    5,642
    Location:
    USA still the best. But barely.
    Isn't Knox just for Samsungs? I've had Motos for Years & I never saw Knox on them.
     
  5. Robin A.

    Robin A. Registered Member

    Joined:
    Feb 25, 2006
    Posts:
    2,586
    it´s Secure Folder - only for a Samsung phone with Knox.
     
  6. mantra

    mantra Registered Member

    Joined:
    Jan 25, 2005
    Posts:
    6,281
    hi
    i will look for a tutorial , i know only about Second Space
    I would like to use only my fingerprint/s and not password pin or pattern
    thanks
     
  7. reasonablePrivacy

    reasonablePrivacy Registered Member

    Joined:
    Oct 7, 2017
    Posts:
    2,170
    Location:
    Member state of European Union
    I have it in Xiaomi. No Knox here of course. It may be a feature inside Google Files app.
    Samsung however may have extended it to use fingerprint, but only as convenience - it seems that primary credential is still PIN or password or pattern
    https://m.youtube.com/watch?v=JIxnCbq_Y98

    Yes, but it could at least prevent digital adversaries in most circumstances. This could be prevented as an example

    https://www.wilderssecurity.com/thr...-with-just-one-bad-click.455743/#post-3219199
     
  8. Robin A.

    Robin A. Registered Member

    Joined:
    Feb 25, 2006
    Posts:
    2,586
    Yes, primary is PIN, pattern or password.
     
  9. mantra

    mantra Registered Member

    Joined:
    Jan 25, 2005
    Posts:
    6,281
    hi
    i have seen only in the samsung phones
    but the fingerprints should be more secure than Pin , and they are faster
    Pin are only 4 numbers , aren't ?
     
  10. reasonablePrivacy

    reasonablePrivacy Registered Member

    Joined:
    Oct 7, 2017
    Posts:
    2,170
    Location:
    Member state of European Union
    The weakest is probably a pattern. Yes, PIN for secure folder is 4 numers, at least in 5 yo Xiaomi.
    As main screen lock it is 8 numbers.
     
  11. Robin A.

    Robin A. Registered Member

    Joined:
    Feb 25, 2006
    Posts:
    2,586
    PIN can be more than 4 digits. Samsung recommends 6 minimum, it can be 10 or more. Samsung rates PIN security as "medium to high".
     
    Last edited: Jan 5, 2025
  12. Palancar

    Palancar Registered Member

    Joined:
    Oct 26, 2011
    Posts:
    2,462
    Nope. My PASSWORD to unlock my Android 23 Ultra is 21 characters long. Yep, not a mis-type! I rely on my fingerprint but have the quick biometric "killer" available with the touch of a button. If I touch that button it takes the correct 21 characters to unlock the phone because Android KNOX disables ALL biometrics. I don't usually need to use my unlock password but I keep the quick biometric disable at the ready!

    ps - ditch the PIN and go with password. With PIN there are only 10 options with each digit you use. With password each character is close to 80, and you can use ASIC 2 digits which will never be attempted in a brute force scenario.
     
    Last edited: Jan 5, 2025
  13. mantra

    mantra Registered Member

    Joined:
    Jan 25, 2005
    Posts:
    6,281
    hi
    what can happen to an andoird after 10 or more attempts with wrong pin or password ?
    seems there is a delay and after x seconds , the phone will let again to try another pin
    on other side ,I guess apple locks the phone

    thanks
     
    Last edited: Jan 6, 2025
  14. Robin A.

    Robin A. Registered Member

    Joined:
    Feb 25, 2006
    Posts:
    2,586
    The phone is already locked.

    After a "certain" number of failed attempts, the phone may ask for a Google account login, and after a successful login it enters an automatic factory reset.

    Not sure, I haven´t tried...
     
    Last edited: Jan 6, 2025
  15. TairikuOkami

    TairikuOkami Registered Member

    Joined:
    Oct 10, 2005
    Posts:
    3,564
    Location:
    Flat Earth Matrix
    You have to wait for 5 min and you can try again.
    Well you can lock it and reset it remotely.
     
  16. mantra

    mantra Registered Member

    Joined:
    Jan 25, 2005
    Posts:
    6,281
    hi
    could be unlocked remotely?
    thanks
     
  17. Palancar

    Palancar Registered Member

    Joined:
    Oct 26, 2011
    Posts:
    2,462
    I do not allow my phone to be remotely unlocked - on purpose. And with 21 characters I could care less if someone wants to bang away at it all day long. Four of my characters are ASIC II so party on if they want to, LOL! 21 to the 80th exponent of possibilities.
     
  18. XIII

    XIII Registered Member

    Joined:
    Jan 12, 2009
    Posts:
    1,416
    What’s “ASIC II”?
     
  19. TairikuOkami

    TairikuOkami Registered Member

    Joined:
    Oct 10, 2005
    Posts:
    3,564
    Location:
    Flat Earth Matrix
    I do not think so, but you can just re-login to google account on it.
     

    Attached Files:

  20. Palancar

    Palancar Registered Member

    Joined:
    Oct 26, 2011
    Posts:
    2,462
    These are actually ASIC II extended --- > recognized but seldom used by "street users" (non-scientist types). I haven't seen hashing tables and other mechanisms in the wild that patrol for these during brute force. It does add MANY more options per character to the mathematical paradigm. Just a math and probabilities thing for password characters.

    https://theasciicode.com.ar/
     
  21. XIII

    XIII Registered Member

    Joined:
    Jan 12, 2009
    Posts:
    1,416
    I only see ASCII codes there; not ASIC.

    Did you make a consistent typo? Or is ASIC how ASCII is called in your country?

    (or am I still reading it wrong / misunderstanding?)
     
  22. Palancar

    Palancar Registered Member

    Joined:
    Oct 26, 2011
    Posts:
    2,462
    Consistent typo! Mostly demonstrating how many additional characters are available with the extended set of stuff that is rarely used by folks, but the software is fine with it on passwords.
     
  23. mantra

    mantra Registered Member

    Joined:
    Jan 25, 2005
    Posts:
    6,281
    hi
    with xioami should i open google page or xioami web page to enable
    i think google with internet could block it or erase remotely
    thanks
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.