Face and fingerprint recognition.
WHAT IT ACTUALLY CONFIRMS
That the device's enrolled owner is present.
WHAT IT DOES NOT DO
Authenticate to a server.
WHY THAT DISTINCTION MATTERS
It unlocks something held locally. It is not a credential you transmit.
WHAT THE CORRECT PATTERN IS
A token or key in secure storage, released only after successful local authentication.
WHAT THE SYSTEM NEVER PROVIDES
The biometric data itself.
WHY
It never leaves the secure hardware, deliberately.
WHAT TO ALWAYS PROVIDE
A fallback: the device passcode, or your own.
WHY
Biometrics fail, and some users cannot use them.
WHAT TO HANDLE
Hardware absent Nothing enrolled Repeated failure, which locks it out Enrolment changed on the device
WHY THAT LAST POINT MATTERS
Adding a new face or fingerprint should invalidate what was protected, and the platform supports detecting this.
WHAT TO NEVER DO
Treat local authentication alone as server authorisation.
WHAT TO USE FOR SENSITIVE ACTIONS
Confirmation at the moment of the action, not only at launch.