The broader argument here is less about fingerprints, and more about using anything immutable as authentication. You cannot change your fingerprints. You cannot change your social security number (at least not easily). These should therefore, NEVER be a primary method to authorize access to anything. Once stolen, the proverbial horse is out of the barn.
You can in fact change your fingerprints; glassblowing and metalwork, for example, offer numerous opportunities to do so.
Fingerprints can be hacked
211–220 of 333 posts
Re: Fingerprints can be hacked
#212As an IT professional you should know to never use fingerprints or facial recognition for logins.
Re: Fingerprints can be hacked
#213Earlier quoted context omitted.
> The huge advantage of biometrics ... is the ease with which a user can unlock their phone This does not prevent involuntary unlocking - it actually can allow for eased against-will unlocking. «Ease» and security may sometimes not be friends.
At least on iPhones though they have a way to activate a mode that prevents the use of TouchID and FaceID. If I press the power button on my phone 5 times in a row that turns that off. Yes I still run the risk of my device being unlocked against my will if I'm caught by surprise. But I'm able to disable this functionality in places where I think the risk of that may be higher, e.g. while traveling. I'll still take th…
Re: Fingerprints can be hacked
#214The biggest problem imho is that we only have two states on our phones - locked and unlocked. Ideally, I should be able to unlock the phone and take photos using just my fingerprint. In my case I would also like to be able to call, message, play games and similar. But to access the 2fa app, cryptoasset app or similar, I must further authenticate in a way that I only reveal parts of my secret ("Enter 3rd, 8th and 11th…
On Android (don't know about iOS) you can take photos without even unlocking - double press on the power button opens the camera. You can't access anything else (including existing photos in the camera roll).
Re: Fingerprints can be hacked
#215Earlier quoted context omitted.
I’m waiting on a court case with a fingerprint as key evidence for conviction, in which the defendant brings this up. Might not pass reasonable doubt muster, but what if somebody sold fingerprint forgery kits online that made it push-button simple? Just supply an image or two, run it through some ML to reconstruct the print, laser etch a latex glove or similar… I wonder if you could use CRISPR or “lab-grown meat” tec…
Most of the evidence that shows up at a court case is forgeable. Simply showing that a particular piece of evidence could be forged in no way proves that it is forged. You would need some sort of argument to prove your contention.
Re: Fingerprints can be hacked
#216Earlier quoted context omitted.
> lengthy [...] password policies Bizarrely, my organization limits passwords to a length of 12 characters or shorter. I agree with you, I don't want a password the size of a paragraph, but c'mon... 12 characters?
I think you misread me, or I didn't communicate clearly. By "lengthy" I was referring to the policy , not password length. Indeed max password length itself is another common bit of foolishness, for sanity reasons arguably it shouldn't be infinite but ~150 characters should be fine so that if people want to have a long diceware passphrase that's fine. To the extent passwords are used at all it should be exclusively a…
Re: Fingerprints can be hacked
#217Earlier quoted context omitted.
> The core problems with biometrics are that: … is that they're treated as passwords instead of usernames. The three problems you list all have the biometric=password assumption in them. See also using the American SSN usage: it's treated like a (secret) token, and so when it leaks it can be used to access sensitive information. Using it as 'just' a username would probably reduce a lot of problems as well.
> American SSN usage Nothing like a secret token that can be reliably guessed using only your birth month+year and place of birth!
Re: Fingerprints can be hacked
#218My favorite photograph of a fingerprint is when the Chaos Computer Club reproduced the German Foreign ministers fingerprint from a photo. So much for military grade security. https://www.dw.com/en/german-defense-minister-von-der-leyens... - The core problems with biometrics are that: 1) Not revokable (unlike compromised credentials) 2) Not a secret 3) Usually trivial to reproduce and spoof (even "liveliness" tests)
Can biometrics be spoofed? Absolutely. Is it likely to happen to the average person? Not at all. For a typical everyday user, a fingerprint or face scan is probably more secure than the common alternatives of "sticky note" passwords, easily guessed PINs, or no authentication at all.
Biometrics are a compromise between security and convenience. Before iPhones got Touch ID, it was not uncommon for people to just not put a lock on their phone out of convenience. Now it is impossible to find an iPhone out in the wild that is not fully encrypted. The average level of security on consumer devices that hold sensitive information has increased dramatically thanks to biometrics.
Re: Fingerprints can be hacked
#219The biggest problem imho is that we only have two states on our phones - locked and unlocked. Ideally, I should be able to unlock the phone and take photos using just my fingerprint. In my case I would also like to be able to call, message, play games and similar. But to access the 2fa app, cryptoasset app or similar, I must further authenticate in a way that I only reveal parts of my secret ("Enter 3rd, 8th and 11th…
Re: Fingerprints can be hacked
#220My favorite photograph of a fingerprint is when the Chaos Computer Club reproduced the German Foreign ministers fingerprint from a photo. So much for military grade security. https://www.dw.com/en/german-defense-minister-von-der-leyens... - The core problems with biometrics are that: 1) Not revokable (unlike compromised credentials) 2) Not a secret 3) Usually trivial to reproduce and spoof (even "liveliness" tests)
This meme really really has to die. It's so annoying that it's spread so far. Biometric security (i.e something you are) does not need to be secret nor revoked. That's the entire point . It's a piece of information that even when it's known by everyone still can't be reproduced. The strength of a security system based on biometrics is exactly how well that system can detect that it's reading from an living breathing…
"Perfect" is too strong a statement. This is only true if the guard very carefully checks every fingertip to ensure nothing is glued over your normal fingertips, and even then it's possible to distract the guard or rush them with a socially-engineered premise. Or just bribe or blackmail them.