Think this is still overestimating the threat. It's kinda like saying you can hack someone's password by watching video of them typing. True, but also non-trivial. If you're already being personally targeted by an organization professional enough to follow you around, take a photo of your fingerprint on something you touched, then painstakingly reproduce said fingerprint through highly technical means and then gain p…
Fingerprints can be hacked
301–310 of 333 posts
Re: Fingerprints can be hacked
#302Earlier quoted context omitted.
I would argue that the devices you carry with you are exactly the ones you shouldn’t use biometrics for. Law enforcement can force you to use biometrics to unlock a phone. They have used dead bodies to unlock phones.[0] What they can’t do is make you remember a code/password which you have “forgotten.” [0] https://www.forbes.com/sites/thomasbrewster/2018/03/22/yes-c...
The vast majority people will never encounter a circumstance where that will be an issue. To withhold a (n optional) feature from the masses based on the hypothetical actions of an agency who can abuse your fingerprints but will stop short of torture doesn't really make sense.
2. Nobody claimed to then want to withhold the feature "from the masses"... so this is a strawman.
3. "hypothetical actions of an agency"... I think it's pretty clear that these types of methods are not hypothetical, and are being used already
4. "will stop short of torture"... I also think it's clear that many LEO's, especially the closer to federal ones, have been found to torture already.
I agree with gp, biometrics on phones are a bad idea all around, for a lot more reasons that have been said. I don't know why you are protesting this idea as you do.
Re: Fingerprints can be hacked
#303Earlier quoted context omitted.
well, TFA used one photo...
How convenient for them that they: 1) did not write what are needed parameters of the photo or quality of left fingerprint 2) it does not look like they used photo from an angle of the screen as in article but some other closeup 3) somehow unlock stuff with thumb where most people use index finger 4) then they use index finger to operate "thumb" print 5) who touches screen like that with thumb, who touches back of th…
Re: Fingerprints can be hacked
#304My favorite photograph of a fingerprint is when the Chaos Computer Club reproduced the German Foreign ministers fingerprint from a photo. So much for military grade security. https://www.dw.com/en/german-defense-minister-von-der-leyens... - The core problems with biometrics are that: 1) Not revokable (unlike compromised credentials) 2) Not a secret 3) Usually trivial to reproduce and spoof (even "liveliness" tests)
> The core problems with biometrics are that: … is that they're treated as passwords instead of usernames. The three problems you list all have the biometric=password assumption in them. See also using the American SSN usage: it's treated like a (secret) token, and so when it leaks it can be used to access sensitive information. Using it as 'just' a username would probably reduce a lot of problems as well.
Re: Fingerprints can be hacked
#305Earlier quoted context omitted.
> The core problems with biometrics are that: … is that they're treated as passwords instead of usernames. The three problems you list all have the biometric=password assumption in them. See also using the American SSN usage: it's treated like a (secret) token, and so when it leaks it can be used to access sensitive information. Using it as 'just' a username would probably reduce a lot of problems as well.
So why not just use a username instead?
Re: Fingerprints can be hacked
#306My favorite photograph of a fingerprint is when the Chaos Computer Club reproduced the German Foreign ministers fingerprint from a photo. So much for military grade security. https://www.dw.com/en/german-defense-minister-von-der-leyens... - The core problems with biometrics are that: 1) Not revokable (unlike compromised credentials) 2) Not a secret 3) Usually trivial to reproduce and spoof (even "liveliness" tests)
> The core problems with biometrics are that: … is that they're treated as passwords instead of usernames. The three problems you list all have the biometric=password assumption in them. See also using the American SSN usage: it's treated like a (secret) token, and so when it leaks it can be used to access sensitive information. Using it as 'just' a username would probably reduce a lot of problems as well.
I think the current crusade against passwords is primarily motivated by different providers to advertise their ID schemes. Even needing a cert for something like Github is too much for me. I have no high profile repos and it might be reasonable in those cases, but I hope MS doesn't repeat the mistakes they made with their API access. The logistics of authentication is far too complex.
Aside from that I have seen people handling their keys that make you wish they would just use a password and cert logistics isn't trivial at all. No, you should not copy your key to our corporate file server... This is just the nerd way of gluing your password under your keyboard.
Re: Fingerprints can be hacked
#307My favorite photograph of a fingerprint is when the Chaos Computer Club reproduced the German Foreign ministers fingerprint from a photo. So much for military grade security. https://www.dw.com/en/german-defense-minister-von-der-leyens... - The core problems with biometrics are that: 1) Not revokable (unlike compromised credentials) 2) Not a secret 3) Usually trivial to reproduce and spoof (even "liveliness" tests)
My problem with this reasoning is that it leads people to think that biometrics therefore shouldn't be used. Can biometrics be spoofed? Absolutely. Is it likely to happen to the average person? Not at all. For a typical everyday user, a fingerprint or face scan is probably more secure than the common alternatives of "sticky note" passwords, easily guessed PINs, or no authentication at all. Biometrics are a compromise…
I believe biometrics aren't necessary to establish security and in the worst case reveal unnecessary information.
Re: Fingerprints can be hacked
#308My favorite photograph of a fingerprint is when the Chaos Computer Club reproduced the German Foreign ministers fingerprint from a photo. So much for military grade security. https://www.dw.com/en/german-defense-minister-von-der-leyens... - The core problems with biometrics are that: 1) Not revokable (unlike compromised credentials) 2) Not a secret 3) Usually trivial to reproduce and spoof (even "liveliness" tests)
The title almost sounds like that they have a meaningful fingerprint ready to open her iPhone... Was that the case? Or do they have a somewhat accurate partial fingerprint? I failed to find recoding of the presentation.
Re: Fingerprints can be hacked
#309Earlier quoted context omitted.
> Biometric security (i.e something you are) does not need to be secret nor revoked. That's the entire point. It's a piece of information that even when it's known by everyone still can't be reproduced. If that's the point, the effort is doomed. All biometrics will be able to be reproduced sooner or later. There's no way around that. So, like all other identifiers, revocation is an important trait. Even if successful…
> If that's the point, the effort is doomed. All biometrics will be able to be reproduced sooner or later. There's no way around that. All encryption will eventually be broken therefore what’s the point is a pretty bad security posture. But like no it won’t. Even if you can fake every other metric (good luck with eyes) a fresh blood sample taken by a guard with hypothetical futuristic instant DNA sequencing will neve…
Re: Fingerprints can be hacked
#310Earlier quoted context omitted.
This meme really really has to die. It's so annoying that it's spread so far. Biometric security (i.e something you are) does not need to be secret nor revoked. That's the entire point . It's a piece of information that even when it's known by everyone still can't be reproduced. The strength of a security system based on biometrics is exactly how well that system can detect that it's reading from an living breathing…
My thought is that biometrics should be the root of identity, not the endpoint. You shouldn't need to scan your retina, fingerprint, or face at every point you want to verify your identity. Instead you use other things like public key cryptography to verify your identity remotely, id cards (perhaps with strong cryptography) for in-person interactions, etc. Lost/stolen cryptographic keys or ID cards could be revoked a…
> biometric verification facility
sounds expensive.