Live data from Hacker News

Project Abacus: Google's plan to kill the password via biometric tracking

engadget.com

31–40 of 59 posts

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#31
post #4

The server side of major services already perform some very sophisticated probablistic authentication mechanisms. Ever had Google or facebook ask you to sign in again when you got off a flight or accessed a sensitive setting? You've experienced it firsthand. Taking it down to the device level is just acknowledging the danger of loss or stolen second factors. Further, frameworks like tensorflow may allow the learning…

I've never been prompted to reauthenticate to Facebook or Google based on travel, actually, and if I was, I would be paranoid about a MITM attack. Has this happened to anyone?

Facebook in the past has required me to authenticate during travel by showing me pictures in which my friends are tagged, and asking me to name them. Of course this was made more difficult by my friends' tendencies to abuse the image tagging feature...

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#32
post #15

Earlier quoted context omitted.

Medical researchers?

Insurance Agents? So, Mr. Owl, I'm afraid that your insurance premiums are going up. Why? Because of that slip on the ice two days ago; our monitoring indicates that you have injured your back. Yes, I know you haven't even seen a doctor yet, but there's a 62% probability that you will be making a large claim shortly, so up with your premiums!

I've stated elsewhere in the thread that there would need to be privacy protections, e.g. require Google or anyone using biometrics to be HIPAA compliant, make it opt-in only, but if anyone is actually going to implement this, medical research should benefit.

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#33
Maybe it's too obvious or maybe I'm completely missing something, but seems a "fatal flaw" in this scheme is the fact that not everyone owns a smartphone, or even uses web services enough to develop much of an identifiable "profile". Smartphones are fragile, easily lost, not always available or reliable, making their use for the purpose seem far less than optimum.

Furthermore, how high a level of security is needed depends on the situation. Sometimes passwords guard fairly trivial risk exposure, like belonging to some newsgroup to make occasional comments. Hardly any personal info to leak in such cases and simple measures will do just fine.

OTOH my health records needs to be protected far more vigorously, but why would I trust that security to a third party entity like Google? I'd much rather have security for the EHR managed within the EHR system itself, and whatever is adopted, I doubt it would look a whole lot like what's proposed in the article.

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#35
post #33

Maybe it's too obvious or maybe I'm completely missing something, but seems a "fatal flaw" in this scheme is the fact that not everyone owns a smartphone, or even uses web services enough to develop much of an identifiable "profile". Smartphones are fragile, easily lost, not always available or reliable, making their use for the purpose seem far less than optimum. Furthermore, how high a level of security is needed d…

> ... not everyone owns a smartphone

Relax. We'll chip anyone without a smart device companion.

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#36
post #11

Earlier quoted context omitted.

>>> If you trust the authority, it's no big deal. And, I trust Google... today. Google yes/maybe. But when you talk to Google who else is involved? Which governments are granted access, with or without google's knowledge? How many 20-something analysts at three-lettered agencies have access? I would like to trust a large publicly-traded company, but the reality today is that they seem in little more control than the…

My trust in Google comes from me believing Google is capable of preventing undetected access, and limiting detected access to that which is legally obligated. I'm not going to try to convince you that this is the case, only state that it's what I believe.

[deleted]

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#37
The real problem is that bio-metrics are basically unchangeable. As soon as a database gets hacked or stolen, or whatever device does the recording has a vulnerability, your security with such systems is compromised forever -- not just at the original place that was breached, but with everyone else who uses the same metrics.

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#38
post #2

(disclosure: I am a Googler, but I have nothing to do with this project) Passwords are problematic, easy to lose, easy to steal, but an issue with biometric identify verification is that you can no longer maintain multiple personas. Using a password with 2FA, you can quite easily maintain two sets of those credentials, assuming that the authority doesn't demand proof of real name or such nonsense. If you trust the au…

>I trust Google... today.

This is really hard problem for our society. A lot of people say 'nothing to hide', most people don't have a problem with gov. surveillance, only because we live in a semi-democratic countries and a lot of them were not hurt by communistic governments. People in Germany and Poland look differently at such things, they still remember Stasi (Ger) and SB with WRON(Pl). Clearly our governments want more power and information and it's not for our safety, this situation is reminding people that communism can be turned into democracy, and democracy into communism, very quickly.

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#40
post #12

Earlier quoted context omitted.

It's not clear to me what you're suggesting - your two statements are, at least superficially, at odds with one another.

The difference I'm guessing is deep integration would be like IE and Windows in the pre lawsuit days. Basically, OSes should come with a password manager app by default, but users can download their own to replace it which would replace the default one. Much like how you can set your default browser on desktop OSes.

Yup that's what I was saying.
Post reply on HN