Does it worth repeating that "fingerprints are usernames, not passwords"? It is straightforward to copy someone's fingerprint. If technology does not include some additional biometric property (blood vessel arrangement, unique capacitance?!, unique heat signature that will not change over time?! ...) that is hard to obtain, it is pretty much useless, especially if someone is really keen to hack you ...
Getting a biometric security key right
41–50 of 81 posts
Re: Getting a biometric security key right
#42Earlier quoted context omitted.
If you have two, say, Microsoft accounts, can you use the same FIDO2-capable authenticator for both, and can Microsoft correlate the accounts by authenticator? I know keys are unique per-site, but are they per-account? edit: The spec[1] is vague on this, but it looked like a Relying Party can't correlate accounts directly via some kind of identifier for the authenticator. It looks like individual key pairs are genera…
You have to distinguish between resident keys and non-resident keys (that I'll just call "normal keys"). Resident keys are stored on the device, so today you can only have a limited number of RKs. This said it's a temp limitation. As usage will increase, devices will allow for more RKs. For example, if I'm not wrong, yubikeys support 25 RKs, solokeys 50. (But the only sites where you can use RKs are basically Microso…
> For each account on a given site, you'll have an independent RK.
Is this only for usernameless sites? Sites with usernames can just use normal keys, right?
> (But the only sites where you can use RKs are basically Microsoft or demos.)
How do sites request to use RK’s? Why would Microsoft request RK’s when they can use the associated email address as a unique username?
Also, I can’t find anything about hardware security keys on my Microsoft account page, much less usernameless authentication.
If there’s multiple usernameless accounts per site how does the user select which RK to use? This seems impossible. If it is in fact impossible, then only one RK per authenticator would be necessary and only one usernameless account per site per authenticator could be used.
Re: Getting a biometric security key right
#43There are plenty of fingerprint readers on the market, doesn't really excite me because it just makes it 2-in-1. What does excite me? Smart rings like https://store.nfcring.com/products/omni
Funny enough their own demo (from the parent article) is on a MacBook Air with built-in Touch ID.
Re: Getting a biometric security key right
#44Does it worth repeating that "fingerprints are usernames, not passwords"? It is straightforward to copy someone's fingerprint. If technology does not include some additional biometric property (blood vessel arrangement, unique capacitance?!, unique heat signature that will not change over time?! ...) that is hard to obtain, it is pretty much useless, especially if someone is really keen to hack you ...
One of them is beige and from the 1990s. It has a keyboard and screen into which you type in your regular username and password. It is the computer that you actually use to get things done.
That computer is behind another fancier one though. The fancy one has a fingerprint reader and a robot arm. It reads your fingerprint (possibly incorrectly) and turns it into a password (also, potentially with inaccuracies.) The password might literally be “thumb with two loops that are 2034 pixels apart”.
The robot arm on the fancy computer then types the generated password into the 1990s computer. If anyone sees the password being typed, you’re out of luck. You can’t change your fingerprint to something different. There are no other inputs to the fancy machine. You’ll just have to use another finger.
You certainly wouldn’t be able to generate a meaningful username with the fancy computer. (Which is a finer point than simply fingerprints = usernames.)
What’s different with the Yubikey is that it’s trusted portable and tamper proof. It’s considerably harder for an attacker to intercept my fingerprint on the fancy computer with the fingerprint and robot arm if it’s either stuck in a USB port or in my pocket on my key chain.
Re: Getting a biometric security key right
#45Earlier quoted context omitted.
U2F is a second factor, not a primary one.
While this is true, the spirit of the GP is correct. To login you will need both a username/password and the second factor. So losing the key is still relevant. In practice that means people really need to buy (at least) two yubikeys to register with services that allow it. Have one on something that’s always with you (such as keys) and the extra(s) as a backup somewhere secure. Unfortunately this works with most acc…
Re: Getting a biometric security key right
#46Does it worth repeating that "fingerprints are usernames, not passwords"? It is straightforward to copy someone's fingerprint. If technology does not include some additional biometric property (blood vessel arrangement, unique capacitance?!, unique heat signature that will not change over time?! ...) that is hard to obtain, it is pretty much useless, especially if someone is really keen to hack you ...
Just getting the fingerprint of someone else does not allow you to log in as them. The fingerprint is only used as a presence check by the security key, which digitally signs a challenge using its own internal non-exportable key material. So you would have to both steal someone else's security key (note you cannot "clone" it, at least not trivially), and also get their fingerprint, if you wanted to "hack" them.
I had a chat with a spokesman from a bank they had similar technology for a credit card, basically what he said is that key factor is time. That is, if someone steal your card in bar and takes fingerprint from a glass you were drinking, only things that will protect you is time you will notice that your card is missing and reporting it to the bank. As person hacking will need a bit of time to replicate fingerprint. Which is about between 15 - 30 min with proper tools...
Re: Getting a biometric security key right
#47Earlier quoted context omitted.
Just getting the fingerprint of someone else does not allow you to log in as them. The fingerprint is only used as a presence check by the security key, which digitally signs a challenge using its own internal non-exportable key material. So you would have to both steal someone else's security key (note you cannot "clone" it, at least not trivially), and also get their fingerprint, if you wanted to "hack" them.
So, device is password generator, and fingerprint is the username. What happens when you lose or brake your security key, is your PC locked forever, or it will stay that way until they send you replacement? But if they can send you replacement, that means that "the company" (read government services) have sort off master key for your PC (they have fingerprint database) and they can get access to inside hardware depen…
Not sure about macOS, but on Windows it would most likely use Windows Hello, even though they didn't mention it once in that blogpost. It doesn't allow you to have biometrics as the only method of logging in. You would have to setup a PIN too and the usual password will always be available. On Linux anything goes, depends on how you set it up.
All that FIDO2 stuff is for browsers mainly, unless MS would meet them in the middle and allow FIDO2 without AD for system logins in upcoming updates.
EDIT: This old preview shows Windows Hello https://www.youtube.com/watch?v=L2y3g_094TI
Re: Getting a biometric security key right
#48Could someone ELI5 the security benefits of Yubikey over Apple's finger print sensor?
Re: Getting a biometric security key right
#49With Yubico I always get a feeling that if they could breakaway from all this legacy smartcard stuff and lock everyone in, they would. But they can't yet, so they distanced themselves from it and were keeping it on the down-low ever since. I would really like if they made a wearable without any ports like a NFC ring, but that would mean either keeping it tied to phones only with an app or selling their own NFC/contac…
I really like Yubico and fingerpring scanner is an awesome idea, would be really happy to bring my fingerprint instead of relying on laptops. On the other hand, a wearable would be a whole new level, like thinking 2 steps ahead
Re: Getting a biometric security key right
#50There are plenty of fingerprint readers on the market, doesn't really excite me because it just makes it 2-in-1. What does excite me? Smart rings like https://store.nfcring.com/products/omni
Thanks for the link - this is an ideal solution to the problem of forgetting to carry, or mislaying, tokens. I was about to press the Buy button for the McLear payment-enabled ring priced at £89.99 https://mclear.com/product/payment-ring/# but paused for thought after reading the terms and conditions (it's a PrePay Visa account) and finding this gem: "Your McLEAR Product(s) will be valid for 24 months from date of re…