Live data from Hacker News

Amazon One – Palm recognition for Amazon Go

blog.aboutamazon.com

51–60 of 151 posts

Re: Amazon One – Palm recognition for Amazon Go

#51

Earlier quoted context omitted.

> I could age verify myself only once at an Amazon One kiosk and then have my legal age linked to my verified palm Why not do the same thing, but instead of verifying your palm you verify a device that's responsible for authenticating you? This could be a special phone app (like Singapore's SingPass[1]) or even a small card with a built-in fingerprint reader. Once you authenticate yourself to the device, it can attes…

> Why not do the same thing, but instead of verifying your palm you verify a device? Because my (imaginary) 12 year old son can grab my phone and then pretend to be an adult when doing booze shopping. This is the reason why most Western countries don't allow this kind of technology for age verification. For example in the UK you have to file an application if your new technology can be authorised to be used for age v…

If your son is stealing your stuff to go buy booze there's a bigger issue and the answer is not invasive biometrics, nor is it government restriction of alcohol sales. Kids will drink if they want to; only a willingness not to do so will stop them.

Re: Amazon One – Palm recognition for Amazon Go

#52

Earlier quoted context omitted.

> I could age verify myself only once at an Amazon One kiosk and then have my legal age linked to my verified palm Why not do the same thing, but instead of verifying your palm you verify a device that's responsible for authenticating you? This could be a special phone app (like Singapore's SingPass[1]) or even a small card with a built-in fingerprint reader. Once you authenticate yourself to the device, it can attes…

> Why not do the same thing, but instead of verifying your palm you verify a device? Because my (imaginary) 12 year old son can grab my phone and then pretend to be an adult when doing booze shopping. This is the reason why most Western countries don't allow this kind of technology for age verification. For example in the UK you have to file an application if your new technology can be authorised to be used for age v…

Germany uses for e.g. cigarette dispensers (those shitty ones you see in shitty districts) two possible options: (a) ID (b) bank card + PIN, where the bank verifies you’re > 18yo.

Works just fine.

Re: Amazon One – Palm recognition for Amazon Go

#53
post #43
post #12

Earlier quoted context omitted.

From the FAQ, it seems like this is not as invasive as fingerprints: "We selected palm recognition for a few important reasons. One reason was that palm recognition is considered more private than some biometric alternatives because you can’t determine a person’s identity by looking at an image of their palm."

That seems disengenuous? You can't determine a person's identity by looking at a fingerprint either. You have to match it against a database of them.

Same as face recognition in that regard. It's just that humans are evolved to do wetware-accelerated face recognition very well. And not hand palm recognition. But for computers its all the same

Re: Amazon One – Palm recognition for Amazon Go

#54
post #6

At this point I feel like products are named One when the product manager and marketing people are having a bad day and want to just be done with the naming discussions already.

I had initially read your comment as "marketing people are having a bad day and want to just be one with the naming discussion"

Re: Amazon One – Palm recognition for Amazon Go

#55
post #30

'One reason was that palm recognition is considered more private than some biometric alternatives because you can’t determine a person’s identity by looking at an image of their palm.' Umm, if this is true, how are you identifying the person then?

I think it means that they are using some 3d representation of a palm that a (single) 2d image won't capture (unlike a fingerprint). Maybe they use video (gesture was mentioned) or maybe something like lidar.

Re: Amazon One – Palm recognition for Amazon Go

#56

Terrible naming aside, the onslaught of biometrics everywhere is very concerning.

I recently attended a scientific conference on biometrics (I'm not from the field) and it was shocking to learn about all that stuff, both what's going on in the research community as well as on the law makers' side of things.

Re: Amazon One – Palm recognition for Amazon Go

#57
post #30

'One reason was that palm recognition is considered more private than some biometric alternatives because you can’t determine a person’s identity by looking at an image of their palm.' Umm, if this is true, how are you identifying the person then?

We should read the opposite of what they're saying to be true: they already have our fingerprints, and they want the rest of our hands.

Re: Amazon One – Palm recognition for Amazon Go

#59

Similar to FinGo ( https://fingo.to ) and Hitachi VeinID Five ( https://digitalsecurity.hitachi.eu/products/veinid-five/ ). All these new biometrics share one common theme: Better privacy for a user. FaceID has the problem that I can't hide it. As soon as I walk somewhere cameras can capture and match my face against their own records, however if I never registered my face ID with Amazon then they will know that I am…

Or we could (radical idea here) not use biometrics . I don't mean to be dismissive, but what advantage does this provide over opening a web site and hitting "pay" or maybe some sort of NFC tap? This looks like biometrics for the sake of being cool and flashy, which is not a trade-off I'm willing to make.

The justification of biometrics is usually to make it harder for fraudsters to pretend they're someone else.

However, one advantage of something external to your body is that if it ever does get compromised it is a lot easier to deprecate that thing and replace it with a new one.

Re: Amazon One – Palm recognition for Amazon Go

#60

Coupling un-alienable, (purposefully) unchangeable biological marks to any account is always horrible idea. And not just the privacy part, for one, it can (only) be unwillingly altered (eg. by an accident), the same way as fingerprints, so a secondary backup code is needed anyway, making the whole setup a bad sort of convenience feature. The proper solution would be a safe hardware key mechanism.

Also, Amazon (and any involved subcontractors) now have access to your palm, with the possibility of accessing any other system authorized by it.

We tell users not to re-use their passwords, but the same goes for fingerprints too.

Post reply on HN