Live data from Hacker News

Project Abacus: Google's plan to kill the password via biometric tracking

engadget.com

41–50 of 59 posts

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#41
post #2

(disclosure: I am a Googler, but I have nothing to do with this project) Passwords are problematic, easy to lose, easy to steal, but an issue with biometric identify verification is that you can no longer maintain multiple personas. Using a password with 2FA, you can quite easily maintain two sets of those credentials, assuming that the authority doesn't demand proof of real name or such nonsense. If you trust the au…

It could be even creepier if the biometric data could be sold to third parties, or if Google were to offer an identification service for third parties.

Biometrics are an excellent technology for tracking convicts because they can't be changed.

Edit: Downvotes? Prisons and corrections would love this thing for checking convicts identities. They already use fingerprints and mugshots which are cruder biometrics. This is just taking it to the next level.

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#42
post #38
post #2

(disclosure: I am a Googler, but I have nothing to do with this project) Passwords are problematic, easy to lose, easy to steal, but an issue with biometric identify verification is that you can no longer maintain multiple personas. Using a password with 2FA, you can quite easily maintain two sets of those credentials, assuming that the authority doesn't demand proof of real name or such nonsense. If you trust the au…

>I trust Google... today. This is really hard problem for our society. A lot of people say 'nothing to hide', most people don't have a problem with gov. surveillance, only because we live in a semi-democratic countries and a lot of them were not hurt by communistic governments. People in Germany and Poland look differently at such things, they still remember Stasi (Ger) and SB with WRON(Pl). Clearly our governments w…

I think most people understand your last point as you meant it, but Democracy and communism are Apples and Oranges.

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#43
post #37

The real problem is that bio-metrics are basically unchangeable. As soon as a database gets hacked or stolen, or whatever device does the recording has a vulnerability, your security with such systems is compromised forever -- not just at the original place that was breached, but with everyone else who uses the same metrics.

Yes - my rule is that if the other side knows you're using biometrics, the system is too dangerous to use.

The weird part is how unnecessary the Mission Impossible stuff is: replacing passwords is a legacy hassle so if you're going to do that there's no reason not to do so with a flexible public key design which doesn't make assumptions about the client hardware and can be patched when it's compromised. (Biometrics might be a fine usability option for the client store)

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#44
> And then we have fingerprints, which are very secure and onerous to imitate

Fingerprints are SO EASY to imitate that I taught a group of 10-12 years old to do it successfully with something as simple as a drinking cup, superglue an smartphone and a SLA printer.

You can cheat the Iphone sensor with no problems.

Everything you touch has your fingerprint on it. Secure! Ha!

A fingerprint taken from you works today and works tomorrow and it will work forever.

I prefer passwords or tokens that I could change, that you very much.

What Google wants it to do surveillance on everyone all day long. Their interest are different from ours.

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#45
post #20

> And then we have fingerprints, which are very secure and onerous to imitate Aaaaand there goes the article's credibility. A pity, because there's a real need for a cogent debate about this panopticon-as-password program.

The best thing about fingerprint authentication is that you can (literally) hack up a way for up to ten people to share a device.

You also can (literally) cut access to service.

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#46
post #42
post #38

Earlier quoted context omitted.

>I trust Google... today. This is really hard problem for our society. A lot of people say 'nothing to hide', most people don't have a problem with gov. surveillance, only because we live in a semi-democratic countries and a lot of them were not hurt by communistic governments. People in Germany and Poland look differently at such things, they still remember Stasi (Ger) and SB with WRON(Pl). Clearly our governments w…

I think most people understand your last point as you meant it, but Democracy and communism are Apples and Oranges.

[deleted]

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#47
post #2

(disclosure: I am a Googler, but I have nothing to do with this project) Passwords are problematic, easy to lose, easy to steal, but an issue with biometric identify verification is that you can no longer maintain multiple personas. Using a password with 2FA, you can quite easily maintain two sets of those credentials, assuming that the authority doesn't demand proof of real name or such nonsense. If you trust the au…

Maybe the biometric verification could be done on a home server, if it makes sense. Make like a hash of the behavior, and share the hash instead. So you'd have privacy, and multiple personas, and the ease of use.

Also, I imagined "contracts of morality", where corporations are enforced into ethical behavior, if they choose to, so they can be 'trusted' on a longer scale, to be 'good' beyond the common law. I understand it's not easy to define.

For the password, I think it could end like Facebook, anonymity sacrificed. It just gives you an edge. It's a form of tragedy of commons. It gives you an edge until it doesn't. (but I trust it'll be worked out)

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#48
I am glad that Google is not focusing exclusively on using biometric factors to implement two or more factor authentication solutions these days, because there are quite a lot of valid arguments against widespread use of it. Biometric properties are limited in number (couple of irises, bunch of fingers), cannot be replaced (at least not with a replacement that can serve as a biometric source of identification), cannot be shared (voluntarily), and are considered by many as an unreasonably invasive manner of identifying yourself. Needless to say that the notion of a microphone analysing my every move and utterance sounds like something from a dystopian sci-fi novel.

Instead of using biometric properties as a second factor, I find user-friendly and reusable hardware tokens to be very much preferable. Fortunately Google is also a backer of FIDO U2F, which outlines a standard for hardware tokens the size of a thumb — but unlike your actual meaty appendages, it is replaceable and not quite as bloody to lend to someone in case he or she has a valid reason to access your accounts for you. These work with USB, NFC, and Bluetooth LTE, on any OS, with (soon) any modern browser (currently only Chrome supports it, but Mozilla is committed to implement this technique in Firefox as well), and can be used for an infinite number of services; without the token being identifiable across services.

Succeed in making having one of these tokens on your (physical!) key-chain as common as having the key your front door there, and use the economy of scale to make these tokens as cheap as a happy meal; that would be an acceptable way to beef up security for Joe Sixpack and privacy conscious netizens alike, but leave my body alone.

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#49
post #20

> And then we have fingerprints, which are very secure and onerous to imitate Aaaaand there goes the article's credibility. A pity, because there's a real need for a cogent debate about this panopticon-as-password program.

The best thing about fingerprint authentication is that you can (literally) hack up a way for up to ten people to share a device.

The tokens you pass out even expire automatically. How useful.
Post reply on HN