Fingerprint and face login: how safe is biometrics?
Fingerprint and face unlock are convenient and, used on your own device, quite safe. Learn how they work, where they fall short and how to set them up sensibly.
Login securityPublished
Fingerprint and face login are safe and convenient for unlocking your own device and for approving passkeys, because the biometric data stays on the device and never goes to the website. Their limit is that you cannot change a fingerprint, and a PIN or password always stands behind them. Used sensibly, they are a good fit for most people.
How biometric login works
When you enrol a finger or face, your phone or laptop converts it into a mathematical template and stores it in protected hardware, such as a secure enclave or a TPM chip. Later, it compares a fresh scan with that template locally. If it matches, the device releases a stored key or opens the lock screen.
The important point: the biometric is a way to unlock something on your device. It is not sent to the service. This is why it fits so well with passkeys, where your finger or face approves a signing operation that happens locally.
How accurate is it?
Manufacturers publish false-match figures for their systems. Apple, for example, states in its platform security documentation that the chance of a random person unlocking a phone is about 1 in 50,000 for Touch ID and 1 in 1,000,000 for Face ID, with caveats for identical twins, close relatives and young children. Other vendors use different technologies and thresholds, so treat such numbers as vendor claims rather than a universal rule. The practical question is rarely random matching. It is what happens when someone gets hold of your unlocked device or forces the issue.
Strengths and limits
| Strength | Limit |
|---|---|
| Fast, so you actually use a lock | You cannot change a fingerprint or face if a copy is ever obtained |
| Cannot be shoulder-surfed like a PIN | Others may be able to compel you to use it |
| Stays on the device, not sent to websites | Fails with wet hands, gloves, injuries or strong light |
| Works with passkeys for phishing-resistant sign-in | The fallback PIN or password is the weak link |
The fallback matters most
Biometrics make unlocking easy, but a thief who knows your PIN, often by watching you type it in public, can unlock the phone and reach your accounts. Using face or fingerprint in public spaces actually reduces that risk, because there is nothing to peek at. Beyond that:
- Use a long PIN or alphanumeric passcode, not 4 digits.
- Do not reuse the phone PIN as a bank PIN or other code.
- Turn on the settings that require the passcode after restarts or after several failed attempts.
Step by step: set up biometric login sensibly
- Choose a strong passcode first. The biometric sits on top of it.
- Enrol your fingerprint or face in the device security settings. Add a second finger as a spare.
- Switch on passkeys. Our guide to setting up passkeys walks through it for the main platforms.
- Enable a screen lock timeout so the device locks quickly.
- Learn the quick-disable gesture for your phone, which switches off biometrics and demands the passcode, useful when travelling, crossing borders or in a tense situation.
- Keep a recovery path in case a sensor breaks or you change devices. See two-factor authentication and our guide to account recovery for fallbacks.
Biometrics and 2FA
A biometric on your own device counts as an unlock factor for something you have, such as a passkey. It is not the same as sending your fingerprint to a website. In standards terms, this separation of local verification from online authentication is what makes passkeys phishing-resistant, a topic covered in phishing-resistant MFA. For the underlying distinction between proving who you are and proving that you control a login, read identity versus authentication.
What to avoid
- Services that collect your biometric data on their own servers when a local alternative exists.
- Sharing your phone’s unlock with others, since added fingerprints or faces also unlock your accounts.
- Treating a biometric as a replacement for any backup or recovery plan.
Biometrics beyond the phone
Laptops, tablets and some password managers also offer fingerprint or face unlock. The same principle applies: the biometric unlocks a key stored on that device, and it is the device that is trusted. A few practical points:
- Laptops. Windows and macOS laptops can unlock with a fingerprint reader or camera, and use it to approve passkeys. Keep a strong sign-in password as the fallback.
- Password managers. Biometric unlock is a convenience on top of your master password. After a restart or several failed attempts, the app normally asks for the master password again, so remember it.
- Shared devices. Do not enrol biometrics on a device that several people use, since every enrolled person unlocks it.
Are twins, masks or fake fingers a real danger?
Researchers have shown that high-quality copies can fool some sensors, and that some systems work less reliably for certain groups of people. For most everyday risks, such as a lost phone or a curious stranger, modern sensors are strong enough. If your situation is unusual, for example you handle highly sensitive information, a hardware security key or a longer passcode adds a layer that does not depend on your body.
Children and biometrics
Parents often wonder about enrolling a child. Consider the platform’s family settings, and prefer a passcode for young children while their fingerprints and faces are still changing. Check the age rules of each service.
Bottom line
Use biometrics for what they do well: quick, private unlocking of your own devices and passkeys. Keep a long passcode behind them, know how to disable them quickly, and keep recovery options ready.
Frequently asked questions
Is Face ID or fingerprint safer than a PIN?
For everyday use, often yes, because nobody can watch you type it and it is quick enough that you will not turn it off. A PIN remains the fallback, so the strength of the whole system depends on a long, private PIN or passcode.
Do websites receive my fingerprint when I use a passkey?
No. The biometric check happens on your device and unlocks a private key stored there. The website only receives a cryptographic proof, not your fingerprint or face.
Can someone force me to unlock my phone with my face or finger?
In some situations, authorities or other people may be able to compel a biometric more easily than a passcode. Most phones let you temporarily disable biometrics and require the passcode, for example through a quick button combination. Check your device's instructions.
Are biometrics personal data under the GDPR?
Biometric data used to uniquely identify a person is a special category of data under the GDPR. When it stays on your own device, as with phone unlock and passkeys, the service you sign in to does not receive it.
More in Login security
Account recovery: how to plan it before you need it
Locked out of Google, Apple or your email? Set up recovery options, backup codes and a trusted contact now, and test them, so a lost phone is an annoyance.
Account security for the whole family: a practical guide
Keep a household safe online: a shared password manager, 2FA for everyone, child accounts, help for parents and a simple plan if someone loses access.
Backup codes: what they are and where to keep them
Backup codes get you into an account when your phone or authenticator is gone. Learn how to generate them, where to store them safely and when to replace them.
Data breach: what to do now, step by step
Your email was in a breach? Check Have I Been Pwned or the HPI Identity Leak Checker, change the right passwords, switch on 2FA and watch for follow-up scams.
Hardware security keys explained: how they work
A hardware security key is a small device that proves it is you. Learn how FIDO2 keys work, what to look for, how to set one up and why you need a spare.
How authenticator codes (TOTP) work and how to use them
TOTP codes are the six-digit numbers in authenticator apps. See how they are generated, why they work offline, their limits and how to back them up safely.