Security Signing in safely: 2FA, passkeys and account recovery
Face and fingerprint unlock: safer than a PIN, with caveats
What happens when you unlock with your face, why the biometric never leaves the device, where it is weaker than a passcode, and the legal difference worth knowing.
The short answer
- Face and fingerprint unlock is safer than the short PIN most people would otherwise use, mainly because it makes a long passcode painless to live with.
- The sensor reading becomes a mathematical template held in secure hardware on that one device, so no image is uploaded and no app or website ever receives your biometric.
- Your passcode is still the real credential: it protects the encryption keys, and the device falls back to it after a restart, several failed scans, or a couple of days unused.
- The realistic attack is not a fake fingerprint, it is someone watching you type a four digit passcode and then stealing the phone.
- A passcode is the better choice when you might be compelled, because a face or a finger can be used on you without your cooperation.
- In the US, courts have often treated a passcode as protected speech and a biometric as not, while UK law can compel disclosure of a key either way.
Unlocking with your face or your finger is not a separate password. It is a fast local check that releases a secret the device is already holding. A sensor measures you, compares the measurement against a mathematical template stored in secure hardware on that specific device, and the chip answers yes or no. Nothing about your face travels to the website or app you are opening. For most people this is safer than what it replaces, because it makes a long passcode bearable, and the passcode underneath is still the credential that really protects the device.
What happens in the second you unlock
A capacitive fingerprint reader, the kind in a power button or a home button, senses tiny differences in electrical charge across the ridges and valleys of your skin. An ultrasonic reader under a screen bounces sound off the finger and reads a shallow three dimensional echo. An optical under display reader effectively photographs the finger through the glass, which is the weakest of the three.
Face unlock splits the same way. Some phones use only the front camera and a flat image. Others project a grid of infrared dots, build a depth map of the face, and read it in infrared so darkness and a change of hair color do not matter. A flat camera system can be fooled by a good photograph. A depth mapping system cannot.
Whichever sensor is used, the reading is converted into a template: a set of numbers describing relationships between features, not a picture. The comparison happens inside a separate secure processor, sometimes called a secure enclave or a trusted execution environment, which has its own storage the main operating system cannot read. The result handed back to the system is a yes or a no.
Why your face never leaves the phone
When you open a banking app and it shows a face scan prompt, the bank is not receiving your face. The app asks the operating system a question along the lines of has this user just been verified on this device. If the answer is yes, the system releases a key that was already stored for that app, and the app signs in with it. The bank never sees the biometric, cannot store it, and could not recognize you on a different device.
That structure has three consequences. The template is per device, so enrolling on a phone tells your laptop nothing. It is not in your cloud backup, which is why a restored phone asks you to enroll again. And it is not a photo library, so a leak would not hand anyone a usable image of your face.
It is also extremely small. If your phone is running out of room, the biometric data is not the reason, and what actually fills a phone covers where the space really goes. When you sell the device, a proper wipe destroys the keys that protect the template along with everything else, which is part of why wiping a device properly is worth doing rather than deleting files by hand.
The passcode underneath is the real credential
Your phone's storage is encrypted with keys ultimately tied to the passcode. Your face does not decrypt anything. It authorizes the release of a key the device kept in memory after the last passcode entry. That is why the passcode is demanded again in specific situations, which are worth recognizing rather than finding annoying: after a restart or a power off, after several failed biometric attempts, after a remote lock, after a couple of days without a successful unlock, and whenever you add or remove a biometric.
Now the uncomfortable part. An attacker attacks the easiest accepted route, and that route is the passcode, not your face. The common real world theft is not a mask or a fake fingerprint. It is someone watching you type four digits in a bar, a station or a queue, then taking the phone. Once they have both, they own the device, the messages, the codes arriving in those messages, and often the accounts behind them.
Both major platforms now offer a setting that adds friction when the phone is away from familiar locations: sensitive changes need a biometric rather than the passcode, and a delay is imposed before a thief can alter the account. That removes most of the value of a watched passcode, and almost nobody has it switched on.
How realistic is spoofing
Vendors publish false match figures for a random stranger, commonly around one in a million for depth mapped face recognition and roughly one in fifty thousand for a fingerprint. Read those carefully. They describe a stranger trying once, not a determined person with your prints, your photographs or your genes, and vendors say openly that close relatives and identical twins fall outside the estimate.
| Attack | How hard in practice | Who should actually care |
|---|---|---|
| Photo or video held up to a flat camera face unlock | Easy on budget phones with no depth sensing | Anyone whose phone unlocks with the ordinary front camera |
| Lifted fingerprint made into a mold | Hours of work, needs a clean print and equipment | People facing a targeted adversary, not opportunistic thieves |
| Custom mask against depth mapped face unlock | Demonstrated in research, expensive and needs your facial geometry | A very small number of high value targets |
| Sibling or identical twin | Sometimes works with no effort at all | Anyone sharing a household with a lookalike |
| Your finger or face used while you sleep | Trivial for someone in the room with you | Anyone worried about a partner, flatmate or family member |
| Passcode watched, then the phone taken | Requires patience and no equipment | Everyone, and it is the most common case by far |
The ranking is the point. Spoofing the sensor is the least likely thing that will ever happen to your phone. Someone close to you using it while you doze, and someone stealing a device whose passcode they already watched you type, are the two that happen constantly.
When a passcode beats your face
Biometrics fail in one particular way: they can be used on you without your cooperation. A phone can be pointed at your face while someone else holds it. A finger can be pressed to a sensor. A passcode cannot be taken from your head by force in the same way, which makes it the better choice in a handful of situations.
Consider disabling biometrics temporarily when you are crossing a border, attending a protest, facing any search of your device, travelling where robbery is a realistic worry, or spending time around someone you do not fully trust.
You do not need to dig through settings in the moment. Both platforms can force the next unlock to demand the passcode: on an iPhone, hold the side button and a volume button until the power off screen appears, and on Android, use lockdown in the power menu, which may need enabling first. Learn the gesture now.
The legal difference worth knowing
This is general information, not advice about your own situation, and it is the least settled area here.
In the United States, the argument turns on whether producing a credential is testimonial, meaning it reveals the contents of your mind. Several courts have held that compelling a passcode is testimonial and protected, while compelling a fingerprint or a face is closer to producing a physical characteristic and is not. Other courts have disagreed, and there is no Supreme Court ruling settling it, so the answer genuinely depends on where you are.
In the United Kingdom, the framing is different. A notice can require you to hand over a key or a password to decrypt material, and refusing is itself a criminal offense, so the distinction between something you know and something you are gives you much less separation than it does in the US. Border powers are stricter again. In the European Union the position varies by member state, with the right against self incrimination pointing broadly in the American direction but applied inconsistently.
The setup worth doing today
Use biometrics. The alternative most people would actually choose is a four digit code typed twenty times a day in public, and that is worse. Then spend ten minutes on the layer beneath.
Set a six digit passcode at minimum, and treat it the way you would treat a strong password: never reused, never typed where a camera or a shoulder can see it. Turn on the stolen device protection setting. Enroll a second finger so a cut does not push you to the passcode in public. Check that attention detection, which requires your eyes to be open and on the screen, is enabled for face unlock, because it blocks the sleeping user problem.
Finally, remember what the unlock is gating. It releases the vault your password manager keeps on the device, your authenticator codes, and increasingly the passkeys that sign you in to other accounts, so a weak passcode quietly weakens every account behind it. If a code arriving by text is still your second factor anywhere, how second factors actually work explains why moving that to an app or a passkey matters more than any sensor choice.
Common questions
Is Face ID or fingerprint safer than a PIN?
For everyday use, yes, but not for the reason people assume. The sensor is harder to fool than a PIN is to guess, and more importantly it lets you set a long passcode you would otherwise find too annoying. The catch is that a biometric can be used on you while you are asleep or under pressure, which a passcode cannot.
Can someone unlock my phone with a photo of me?
Only on phones that use the plain front camera for face unlock, which is common on cheaper models. Systems that project infrared dots and build a depth map of your face are not fooled by a flat image, whether printed or on a screen. If you are unsure which yours uses, check whether face unlock still works in complete darkness.
Does my fingerprint get uploaded or shared with apps?
No. The scan is converted into a template that stays in secure hardware on that specific device, is not included in cloud backups, and is not readable by apps. An app asking for a fingerprint only receives confirmation that the device verified someone, and then gets access to a key it had already stored there.
Can police make me unlock my phone with my face?
It depends on the country and, in the United States, on the court. Several US rulings treat a compelled passcode as protected testimony while treating a face or finger as a physical characteristic that can be compelled, but courts disagree and the question is unsettled. In the UK, a legal notice can require you to hand over a password, with refusal a criminal offense. This is general information, not legal advice.
What happens to my face data when I sell the phone?
A proper factory reset destroys the encryption keys protecting the secure storage, which makes the stored template unrecoverable along with the rest of your data. Deleting files or signing out is not enough. Sign out of your device account first so activation locks are released, then run the built in erase all content option.