i'm seeing two (obvious) bigger picture trends here that this story reinforces. 1. Digital authentication for purchasing is moving towards non-transferable biometrics ( i cant divulge my thumbprint like i can my pin ) 2. Goods of all kinds are being delivered faster The scary thing for me is that thieves love goods delivered quickly, so they can turn them quickly, and cut down on their ability to get intercepted. So…
The scary part of that trend is that biometrics should not be replacing passwords. User ID, fine, but finger prints are something you have, not something you know.
Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys
71–80 of 141 posts
Re: Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys
#72It seems like they could add a few less-predictable factors to improve the security of thumbprints without completely ruining their convenience. For instance: — Maybe you must use two or more particular fingerprints in sequence, selected by you in advance. This would require a “sleep attack” to at least try different combinations of your fingers (without knowing which to use first or how many fingers are required). —…
Re: Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys
#73There's not a way to combine both Touch ID and PIN for iOS access, but some apps do provide a PIN or passcode setting. For me, with the banking apps on my phone for example, I use my fingerprint to get into my phone and then manually type in the password. Seems like the best combo to me for mobile security. (Not that I'm worried about it, I'm just security minded.)
Re: Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys
#74People seem to numb out when they hear this in person. I don't understand why...
Re: Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys
#75There's not a way to combine both Touch ID and PIN for iOS access, but some apps do provide a PIN or passcode setting. For me, with the banking apps on my phone for example, I use my fingerprint to get into my phone and then manually type in the password. Seems like the best combo to me for mobile security. (Not that I'm worried about it, I'm just security minded.)
It'd seem fairly trivial for, e.g. Amazon (as in this case) to ask for your Amazon password if you go over a certain dollar-spend - or even weigh the risk of various product categories (e.g., you commonly overnight items from household goods, so we'll trust your thumbprint; but you've never ordered 5 TVs before, you're gonna need your password for that one).
Re: Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys
#76i'm seeing two (obvious) bigger picture trends here that this story reinforces. 1. Digital authentication for purchasing is moving towards non-transferable biometrics ( i cant divulge my thumbprint like i can my pin ) 2. Goods of all kinds are being delivered faster The scary thing for me is that thieves love goods delivered quickly, so they can turn them quickly, and cut down on their ability to get intercepted. So…
I had to disable touch ID on my iPhone out of frustration. It works for me maybe 1 out of 10 times no matter which finger I try to use (my wife has no problem with hers). But I've always had trouble with fingerprint readers. At the DMV, govt ID card office (back when I was in the Army), etc. "Place your finger on the scanner. Nope, try again.. press harder. No, harder." I have no idea what's wrong with my fingers :|
Re: Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys
#77Earlier quoted context omitted.
The most fascinating part for me is that 6 year old managed to find a way to circumvent biometric security without hacking off someone's finger: authenticate while the user is asleep. Necessity is truly the mother of innovation.
And I thought me using a keylogger as a teen to access my mom's AOL account was impressive. Clever 6 year old.
Re: Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys
#78i'm seeing two (obvious) bigger picture trends here that this story reinforces. 1. Digital authentication for purchasing is moving towards non-transferable biometrics ( i cant divulge my thumbprint like i can my pin ) 2. Goods of all kinds are being delivered faster The scary thing for me is that thieves love goods delivered quickly, so they can turn them quickly, and cut down on their ability to get intercepted. So…
I had to disable touch ID on my iPhone out of frustration. It works for me maybe 1 out of 10 times no matter which finger I try to use (my wife has no problem with hers). But I've always had trouble with fingerprint readers. At the DMV, govt ID card office (back when I was in the Army), etc. "Place your finger on the scanner. Nope, try again.. press harder. No, harder." I have no idea what's wrong with my fingers :|
Most notable: brick masons. The fingerprints are damaged and smoothed out over the years by acids in the cement and the roughness of the bricks.
Re: Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys
#79It seems like they could add a few less-predictable factors to improve the security of thumbprints without completely ruining their convenience. For instance: — Maybe you must use two or more particular fingerprints in sequence, selected by you in advance. This would require a “sleep attack” to at least try different combinations of your fingers (without knowing which to use first or how many fingers are required). —…
Re: Child uses sleeping mom's thumbprint to buy $250 worth of Pokémon toys
#80Earlier quoted context omitted.
Identity Authentication Authority I deal with this in my industry (telecommunications). Just because you've provided proof of identity (eg your phone number, account number), there are still things you're not allowed to do until you've authenticated your identity--and the system determines your authority, to perform an action. This is accomplished through a password, a PIN, etc. On a phone, it's an interesting shift…
You're demonstrating the difference between authentication and authorization, not the difference between identity and authentication. Notice you use the word authority, which has the same root word as authorization. Authentication is merely the confirmation of identity...it is not the same thing as authorization.
You seem to be suggesting we add extra layers here so that merely authenticating as the device's owner is insufficient authorization to conduct some actions, and re-authenticating as the owner by using something they know (secret token like PIN/password) instead of something they possess (finger) will re-grant authorization, but users find this constant re-auth very annoying.
Most would probably prefer device makers to allow them to trust the people whom they sleep around rather than input another authentication method all the time. Personal responsibility has to enter into the equation somewhere.
My advice to this parent would be to keep their phone and/or body inaccessible while unconscious.