Live data from Hacker News

Project Abacus: Google's plan to kill the password via biometric tracking

engadget.com

1–10 of 59 posts

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#2
(disclosure: I am a Googler, but I have nothing to do with this project)

Passwords are problematic, easy to lose, easy to steal, but an issue with biometric identify verification is that you can no longer maintain multiple personas. Using a password with 2FA, you can quite easily maintain two sets of those credentials, assuming that the authority doesn't demand proof of real name or such nonsense.

If you trust the authority, it's no big deal. And, I trust Google... today. But do I trust Google tomorrow? I don't yet know tomorrow's Google.

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#4
The server side of major services already perform some very sophisticated probablistic authentication mechanisms. Ever had Google or facebook ask you to sign in again when you got off a flight or accessed a sensitive setting? You've experienced it firsthand.

Taking it down to the device level is just acknowledging the danger of loss or stolen second factors. Further, frameworks like tensorflow may allow the learning model to run directly on your phone, alleviating a lot of the concerns enumerated in this article.

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#5
This sounds bad. We are already forced to use almost exact voice to give voice commands. Now we will be forced to walk the same, speak every so even if you are alone in the room and be sure we dont break our habits. For me this sounds bad. I will be waiting for Google to prove me I am mistaken.

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#6
There's still a lot that can be done to improve passwords without eliminating them. Perhaps the single biggest step is to encourage password managers that can auto-generate strong passwords. I seem to recall an article recently showing that the biggest difference between normal people and security professionals was the use of password managers.

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#7
post #2

(disclosure: I am a Googler, but I have nothing to do with this project) Passwords are problematic, easy to lose, easy to steal, but an issue with biometric identify verification is that you can no longer maintain multiple personas. Using a password with 2FA, you can quite easily maintain two sets of those credentials, assuming that the authority doesn't demand proof of real name or such nonsense. If you trust the au…

>>> If you trust the authority, it's no big deal. And, I trust Google... today.

Google yes/maybe. But when you talk to Google who else is involved? Which governments are granted access, with or without google's knowledge? How many 20-something analysts at three-lettered agencies have access? I would like to trust a large publicly-traded company, but the reality today is that they seem in little more control than the individual. We've seen their logos on too many leaked documents.

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#8
post #2

(disclosure: I am a Googler, but I have nothing to do with this project) Passwords are problematic, easy to lose, easy to steal, but an issue with biometric identify verification is that you can no longer maintain multiple personas. Using a password with 2FA, you can quite easily maintain two sets of those credentials, assuming that the authority doesn't demand proof of real name or such nonsense. If you trust the au…

It could be even creepier if the biometric data could be sold to third parties, or if Google were to offer an identification service for third parties.

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#10
post #6

There's still a lot that can be done to improve passwords without eliminating them. Perhaps the single biggest step is to encourage password managers that can auto-generate strong passwords. I seem to recall an article recently showing that the biggest difference between normal people and security professionals was the use of password managers.

Password managers could be included with the OS - like notepad. But deep integration with the OS would be bad.
Post reply on HN