Using same idea, could’t AI generate FaceId from videos?
Fingerprints can be hacked
101–110 of 333 posts
Re: Fingerprints can be hacked
#102Earlier quoted context omitted.
'what if somebody ...' made SaaS service to upload pictures and overnight ship the fingertip.
It would probably cause a huge media storm. Then the politicians would "fix it" by replacing it with face recognition... (suddenly Face/Off is no longer science fiction)
Didn't a woman in France already have a face transplant?
Re: Fingerprints can be hacked
#103Earlier quoted context omitted.
No, but combined with torture it might be effective enough.
No, I think that adding torture to the mix will make the FMRI results even less readable
Re: Fingerprints can be hacked
#104Would that help make FP authentication more robust?
Re: Fingerprints can be hacked
#105Earlier quoted context omitted.
State driver license in USA is a honey pot of thumb/finger scans. Anyone on HN think the NSA doesn't have access? NSA info sharing with trusted foreign countries makes a reliable distributed backup for use by foreign spooks.
> State driver license in USA In which states? The only thing I have been fingerprinted for is in the US is The Global Entry program.
One state I lived in gave me the option of not having a RealID-compliant license if I wanted to. Another didn't, so fingerprints were compulsory.
Re: Fingerprints can be hacked
#106[edit for clarity] As someone who doesn’t specialize in security, one claim that has stood out to me for not using fingerprints is that you can't run bcrypt (or some other salting algorithm) on fingerprints [1]. I don’t see any discussion of that here thus far. Is that still the case? I feel like I would have heard about developments in this area if something had changed. But perhaps I've always misunderstood the cri…
Re: Fingerprints can be hacked
#107My favorite photograph of a fingerprint is when the Chaos Computer Club reproduced the German Foreign ministers fingerprint from a photo. So much for military grade security. https://www.dw.com/en/german-defense-minister-von-der-leyens... - The core problems with biometrics are that: 1) Not revokable (unlike compromised credentials) 2) Not a secret 3) Usually trivial to reproduce and spoof (even "liveliness" tests)
The strength of a security system based on biometrics is exactly how well that system can detect that it's reading from an living breathing human.
- Perfect: A human guard manually taking a fingerprint reading. Can't be beat because the guard can obviously see that it's not really your hand.
- Shit: A camera that compares pictures.
The entire industry is about making an autonomous system that gets as close as possible to perfect. It's fine to say that you don't think it's good enough right now but "oh no I lifted a fingerprint from a photo" isn't some security breach.
Re: Fingerprints can be hacked
#108Earlier quoted context omitted.
Maybe at some point in the future, but we definitely aren't at the stage of being able to parse out a specific password from an FMRI reading right now.
No, but combined with torture it might be effective enough.
Re: Fingerprints can be hacked
#109Using same idea, could’t AI generate FaceId from videos?
Sounds likely. When you train FaceID you are filmed. What's to stop someone from using film of you giving a speech? At best the biometric locks are like locks on your house. Stops most people but not someone really determined.
Re: Fingerprints can be hacked
#110My favorite photograph of a fingerprint is when the Chaos Computer Club reproduced the German Foreign ministers fingerprint from a photo. So much for military grade security. https://www.dw.com/en/german-defense-minister-von-der-leyens... - The core problems with biometrics are that: 1) Not revokable (unlike compromised credentials) 2) Not a secret 3) Usually trivial to reproduce and spoof (even "liveliness" tests)
This meme really really has to die. It's so annoying that it's spread so far. Biometric security (i.e something you are) does not need to be secret nor revoked. That's the entire point . It's a piece of information that even when it's known by everyone still can't be reproduced. The strength of a security system based on biometrics is exactly how well that system can detect that it's reading from an living breathing…
And yet, it can be reproduced. So it seems like the entire point is... invalid.