„But biometric authentication does not fulfill the advertised security promises“
This is completely out of context. For the average smartphone user Iris-Recognition on a phone (just like touch-ID) VS pin-disabled on the phone is a huge step forward.
The patterns in your irises are unique to you and are
virtually impossible to replicate, meaning iris
authentication is one of the safest ways to keep your
phone locked and the contents private.
Also your pin disabled argument doesn't make a lot of sense. That's like saying 123456 is a good password because many people disable the password prompt at login.
Yes, but that doesn't say anything about the security of passwords in general. (The same way that bad iris recognition being better than no auth at all doesn't say anything about the security of iris recognition in general.)
I can obtain an image of you online, while I need to be on-site to spot you typing your pin. So if I have your phone, I can do research at home to break in.
Additionally, you cannot change your iris once it's compromised. This is an absolute no-no for secure systems! Changing your pin is easy.
This is definitely not a huge step forward. And, as already mentioned, the average user gets misguided by exaggerated marketing promises.
The trouble with statements like 'for the average xyz user' is:
1. 50% of your users won't have their needs met - that's a large proportion assuming a uniform distribution
2. We can't be sure a uniform distribution in the first place is appropriate
3. If we're going to assume an average user then why don't we assume an average phone too: If the average user gets by without something today then why bother building it as a new feature?
In the end a product should not be designed for an average user. It should be designed for a well defined audience who's needs will met well by the product. If you're going to bother with fancy biometric tech as a feature and selling point then you're clearly NOT aiming at the average user who couldn't care less...
These are general consumer devices and there are trade offs. The most sophisticated hacker the vast majority of users must defeat is a prying family member or friend.
This is completely out of context. For the average smartphone user Iris-Recognition on a phone (just like touch-ID) VS pin-disabled on the phone is a huge step forward.