Android has three levels of biometric security. The strength of each tier depends on several factors, including its spoof acceptance rate (SAR), how often users should use their fallback authentication method, and how easily data can be read outside of the runtime environment. The requirements are as follows:
-
Class 1 (formerly Convenience): For users who want a quick way to unlock their device. Requires primary authentication every 24 hours, after four hours of inactivity, or after three unsuccessful biometric unlock attempts. SAR less than 30%. Can only be used to unlock devices, not for in-app authentication.
-
Class 2 (formerly Low): This happy medium between convenience and safety has the same requirements as Class 1, but with a SAR less than 20%. Encrypts biometric data and performs matching in an isolated environment. Can be used to authenticate into the application.
-
Class 3 (formerly Strong): the most secure. For users who want to lock their device. Same requirements as class 2, but with a SAR lower than 7%. Cryptographic keys are not visible to the operating system. Primary authentication required every 72 hours.
Currently, the only Android devices that get a Class 3 rating for facial scans are the Google Pixel 8 and later. Unlike their competitors, these use machine learning algorithms to prevent attackers from defeating facial recognition systems using Live Photos or videos. This is a huge advantage and one of the many reasons to consider a Pixel over other Android phones.
How to Make Sure Your Android Phone is Properly Secure
Scanning your fingerprint to unlock a device may not be as convenient as scanning your face, but it can actually be a benefit. Let’s say someone discreetly picks up your phone and points it at you; Some devices make sure you’re actually looking at the screen, but most don’t. The camera may also see someone who vaguely resembles you and decide that that’s enough, rendering it functionally useless. To be clear, fingerprint scanners can also be beaten; it just takes more effort.
You may also want to rethink model-based verification. Although a 3×3 grid offers more combinations than a four-digit PIN, studies show that users consistently start at the top left, significantly reducing the effectiveness of this method. In fact, almost a third of all patterns could be deciphered in 20 attempts, and that’s without researchers being able to see any useful spots or traces on the phone’s screen.
Finally, use Android’s built-in security features like Lockdown Mode, which disables biometrics, prevents USB connections, and temporarily blocks notifications. You may also want to disable features that reduce security by keeping your device unlocked, such as unlock extension, trusted places, and on-body detection. While no device can be 100% protected against unauthorized access, this is a step in the right direction.
