The server side of major services already perform some very sophisticated probablistic authentication mechanisms. Ever had Google or facebook ask you to sign in again when you got off a flight or accessed a sensitive setting? You've experienced it firsthand. Taking it down to the device level is just acknowledging the danger of loss or stolen second factors. Further, frameworks like tensorflow may allow the learning…
I've never been prompted to reauthenticate to Facebook or Google based on travel, actually, and if I was, I would be paranoid about a MITM attack. Has this happened to anyone?
Project Abacus: Google's plan to kill the password via biometric tracking
31–40 of 59 posts
Re: Project Abacus: Google's plan to kill the password via biometric tracking
#32Earlier quoted context omitted.
Medical researchers?
Insurance Agents? So, Mr. Owl, I'm afraid that your insurance premiums are going up. Why? Because of that slip on the ice two days ago; our monitoring indicates that you have injured your back. Yes, I know you haven't even seen a doctor yet, but there's a 62% probability that you will be making a large claim shortly, so up with your premiums!
Re: Project Abacus: Google's plan to kill the password via biometric tracking
#33Furthermore, how high a level of security is needed depends on the situation. Sometimes passwords guard fairly trivial risk exposure, like belonging to some newsgroup to make occasional comments. Hardly any personal info to leak in such cases and simple measures will do just fine.
OTOH my health records needs to be protected far more vigorously, but why would I trust that security to a third party entity like Google? I'd much rather have security for the EHR managed within the EHR system itself, and whatever is adopted, I doubt it would look a whole lot like what's proposed in the article.
Re: Project Abacus: Google's plan to kill the password via biometric tracking
#34Calling it a trust score instead of a confidence score was pretty stupid of them and lends to the whole creepy vibe mentioned in the title.
Re: Project Abacus: Google's plan to kill the password via biometric tracking
#35Maybe it's too obvious or maybe I'm completely missing something, but seems a "fatal flaw" in this scheme is the fact that not everyone owns a smartphone, or even uses web services enough to develop much of an identifiable "profile". Smartphones are fragile, easily lost, not always available or reliable, making their use for the purpose seem far less than optimum. Furthermore, how high a level of security is needed d…
Relax. We'll chip anyone without a smart device companion.
Re: Project Abacus: Google's plan to kill the password via biometric tracking
#36Earlier quoted context omitted.
>>> If you trust the authority, it's no big deal. And, I trust Google... today. Google yes/maybe. But when you talk to Google who else is involved? Which governments are granted access, with or without google's knowledge? How many 20-something analysts at three-lettered agencies have access? I would like to trust a large publicly-traded company, but the reality today is that they seem in little more control than the…
My trust in Google comes from me believing Google is capable of preventing undetected access, and limiting detected access to that which is legally obligated. I'm not going to try to convince you that this is the case, only state that it's what I believe.
Re: Project Abacus: Google's plan to kill the password via biometric tracking
#37Re: Project Abacus: Google's plan to kill the password via biometric tracking
#38(disclosure: I am a Googler, but I have nothing to do with this project) Passwords are problematic, easy to lose, easy to steal, but an issue with biometric identify verification is that you can no longer maintain multiple personas. Using a password with 2FA, you can quite easily maintain two sets of those credentials, assuming that the authority doesn't demand proof of real name or such nonsense. If you trust the au…
This is really hard problem for our society. A lot of people say 'nothing to hide', most people don't have a problem with gov. surveillance, only because we live in a semi-democratic countries and a lot of them were not hurt by communistic governments. People in Germany and Poland look differently at such things, they still remember Stasi (Ger) and SB with WRON(Pl). Clearly our governments want more power and information and it's not for our safety, this situation is reminding people that communism can be turned into democracy, and democracy into communism, very quickly.
Re: Project Abacus: Google's plan to kill the password via biometric tracking
#39Re: Project Abacus: Google's plan to kill the password via biometric tracking
#40Earlier quoted context omitted.
It's not clear to me what you're suggesting - your two statements are, at least superficially, at odds with one another.
The difference I'm guessing is deep integration would be like IE and Windows in the pre lawsuit days. Basically, OSes should come with a password manager app by default, but users can download their own to replace it which would replace the default one. Much like how you can set your default browser on desktop OSes.