Live data from Hacker News

Project Abacus: Google's plan to kill the password via biometric tracking

engadget.com

51–59 of 59 posts

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#51
post #33

Maybe it's too obvious or maybe I'm completely missing something, but seems a "fatal flaw" in this scheme is the fact that not everyone owns a smartphone, or even uses web services enough to develop much of an identifiable "profile". Smartphones are fragile, easily lost, not always available or reliable, making their use for the purpose seem far less than optimum. Furthermore, how high a level of security is needed d…

> I'd much rather have security for the EHR managed within the EHR system itself

I would trust Google's security team over most EHRs. I base this on finding a few sql injection flaws and single DES usage in one I worked on but I don't have broad experience in many EHRs.

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#52
post #38
post #2

(disclosure: I am a Googler, but I have nothing to do with this project) Passwords are problematic, easy to lose, easy to steal, but an issue with biometric identify verification is that you can no longer maintain multiple personas. Using a password with 2FA, you can quite easily maintain two sets of those credentials, assuming that the authority doesn't demand proof of real name or such nonsense. If you trust the au…

>I trust Google... today. This is really hard problem for our society. A lot of people say 'nothing to hide', most people don't have a problem with gov. surveillance, only because we live in a semi-democratic countries and a lot of them were not hurt by communistic governments. People in Germany and Poland look differently at such things, they still remember Stasi (Ger) and SB with WRON(Pl). Clearly our governments w…

It is just freaky Western people today are so ignorant about McCarthyism or COINTELPRO (https://en.wikipedia.org/wiki/COINTELPRO).

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#53

> Cisco engineer Shawn Cooley countered him saying, "very cool until I break my leg or hand & can't auth to any services to get healthcare info since my behavior is diff." Messina said, "you presume that your health records aren't being managed by Verily. You would be wrong." So Verily would be automatically sharing information with Abacus to modulate its user identification, and they feel can just start doing that b…

> Is this the attitude toward privacy and data isolation at Alphabet/Google?

It is a Twitter remark by an ex-Googler who had nothing to do with Abacus and never worked at Verily. That is, some combination of snark and wild-ass speculation.

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#54
This is disconcerting. I don't like the idea of biometric and other characteristic data being used to identify me, but at least with fingerprint sensors, retina scanners and other such devices I am aware what is happening and give consent each time. This system proposes to silently identify me by the way I type, click or use a device, constantly learning and improving. No doubt the processed data, like a signature, will reside in the cloud and eventually be used identify users on any device they happen to be using. Convenience above all else, yet again.

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#55
post #33

Maybe it's too obvious or maybe I'm completely missing something, but seems a "fatal flaw" in this scheme is the fact that not everyone owns a smartphone, or even uses web services enough to develop much of an identifiable "profile". Smartphones are fragile, easily lost, not always available or reliable, making their use for the purpose seem far less than optimum. Furthermore, how high a level of security is needed d…

> I'd much rather have security for the EHR managed within the EHR system itself I would trust Google's security team over most EHRs. I base this on finding a few sql injection flaws and single DES usage in one I worked on but I don't have broad experience in many EHRs.

Yeah, I know some EHRs have been attacked re: inadequate security, though AFAIK major vendors in my local area seem to have been doing OK recently. However, it only takes small errors here or there to open up significant holes, a fact I've brought up many times when discussing "interoperability" among EHRs, a favorite subject of governmental planners.

I think the problem trusting Google might not lie with their "security team" (they probably have a number of such teams), but rather with privacy policies and guarantees. IOW Google is no doubt capable of providing security, questions arise about enforcing constraints necessary to assure the high level of privacy required by EHR systems.

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#56
post #17

Earlier quoted context omitted.

Capable? Have you heard about prism? Google claims to have been in the dark, that data was siphoning off as it flowed between data centers. That is an admission that Google is not capable of protecting against such things. They claim to have not even contemplated the attack. To quote the boss: "Until this week’s reports, we had never heard of the broad type of order that Verizon received—an order that appears to have…

Yes, and as a result traffic is now encrypted between data centers. And I'm not sure what your quote adds to the point.

This response is too terse given the calmness and energy other people have put into their discussion. If people were saying blatantly stupid responses, that's understandable -- but that's not apparent here whatsoever.

Google has been penetrated before, and Google has had to comply with government agencies, and legislation has passed legally shielding Google from complying with orders later found to be unlawful.

Now you're saying that Google can't be penetrated again, and can be trusted with user privacy. Nobody is saying that getting Google to lawfully turn over user privacy, or that penetrating Google is easy. But Google is a massive organization, and it's not surprising that the USA or China can penetrate it -- lawfully and unlawfully.

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#57
post #53

> Cisco engineer Shawn Cooley countered him saying, "very cool until I break my leg or hand & can't auth to any services to get healthcare info since my behavior is diff." Messina said, "you presume that your health records aren't being managed by Verily. You would be wrong." So Verily would be automatically sharing information with Abacus to modulate its user identification, and they feel can just start doing that b…

> Is this the attitude toward privacy and data isolation at Alphabet/Google? It is a Twitter remark by an ex-Googler who had nothing to do with Abacus and never worked at Verily. That is, some combination of snark and wild-ass speculation.

[deleted]

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#58
post #17

Earlier quoted context omitted.

Yes, and as a result traffic is now encrypted between data centers. And I'm not sure what your quote adds to the point.

This response is too terse given the calmness and energy other people have put into their discussion. If people were saying blatantly stupid responses, that's understandable -- but that's not apparent here whatsoever. Google has been penetrated before, and Google has had to comply with government agencies, and legislation has passed legally shielding Google from complying with orders later found to be unlawful. Now y…

As I mentioned in another post, I'm not trying to convince anyone. I'm just saying I have confidence.

Even so, security is a road, not a destination. If people want to argue that you should put your data anywhere, I'll buy it. But of the places your data can go, right now I think good is the best steward. And that certainly includes just keeping it yourself.

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#59
post #20

> And then we have fingerprints, which are very secure and onerous to imitate Aaaaand there goes the article's credibility. A pity, because there's a real need for a cogent debate about this panopticon-as-password program.

The best thing about fingerprint authentication is that you can (literally) hack up a way for up to ten people to share a device.

I'm assuming you mean to hack of the fingers? But each finger doesn't have the same print.
Post reply on HN