Live data from Hacker News

Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

techcrunch.com

41–46 of 46 posts

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#41
post #36

Earlier quoted context omitted.

This is completely counterintuitive to me. How are you going to remotely copy my fingerprint or iris? Isn't the fact that scanned fingerprints are still used by immigration control and criminal investigators evidence against this?

Lets say someone took your fingerprints off a glass or a light-switch or your car, is there any reasonable way to prevent this? Lets also say that you somehow become aware of them having a copy of your fingerprints and you remember that your phone requires your fingerprints to unlock; what do you do? It's the fact that you can't permanently change your fingerprints nor restrict access to them which make them bad for…

Isn't that assuming that the system will accept a copy of a fingerprint? Are you telling me that I could easily spoof the fingerprint readers in immigration control simply by applying some kind of copies of another person's fingerprints over my own?

Anyway, if copying fingerprints is possible, then they are useless for forensics, contrary to your final point.

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#42
post #39

Earlier quoted context omitted.

How does one forge biometrics? (Notice that I'm not asking how to spoof biometric readers with insecure designs, e.g., the one mythbusters busted). Anyway, this is already the case – fingerprints are used as evidence of criminal liability. If someone forges my fingerprints, they could get me into a huge amount of trouble, in theory.

> How does one forge biometrics? At the end of the day a finger or an iris is a physical object you can make. Since it's impossible to keep the "key" secret, you can always copy it and make one - how hard you have to work to make it depends on how good the design is, but fundamentally there is no secret and without a secret it's useless for authentication. > If someone forges my fingerprints, they could get me into a…

But let's admit that there's no such thing as a secret, really, and it's more about how difficult a thing is to reproduce or reverse engineer. I mean, everything about security is just a big game of "hide the ball" and the question is how many hoops one must jump through to find the ball.

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#43
post #39

Earlier quoted context omitted.

> How does one forge biometrics? At the end of the day a finger or an iris is a physical object you can make. Since it's impossible to keep the "key" secret, you can always copy it and make one - how hard you have to work to make it depends on how good the design is, but fundamentally there is no secret and without a secret it's useless for authentication. > If someone forges my fingerprints, they could get me into a…

But let's admit that there's no such thing as a secret, really, and it's more about how difficult a thing is to reproduce or reverse engineer. I mean, everything about security is just a big game of "hide the ball" and the question is how many hoops one must jump through to find the ball.

Of course there are secrets. What you are trying to say is that system will let you do many attempts till you guess the secret.

But with biometrics there are no guesses - you know exactly what it should look like. There is difficulty in implementation certainly, but a basic principle of security is that each increment of difficulty in the securer (like a longer password) should increase the difficulty of the attacker by an order of magnitude.

Biometrics does not have this properly.

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#44
post #38

Earlier quoted context omitted.

> Isn't the fact that scanned fingerprints are still used by immigration control and criminal investigators evidence against this? Not at all - they use it for identification not authentication. It's a completely different application.

Forgive me if this seems ignorant, but how is verifying a person's identity at immigration control different from verifying their identity when logging into their phone?

The main difference is automated vs human checked.

The next difference is that for authentication it's important to be able to change the password (as it were), and with biometrics that's impossible. Once copied an attacker has access forever.

But I do see your point, and there are a lot of things in common. But going back to your earlier post, just because immigration control does it that way doesn't mean it's best - it just means they don't have a better way.

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#45
post #36

Earlier quoted context omitted.

Lets say someone took your fingerprints off a glass or a light-switch or your car, is there any reasonable way to prevent this? Lets also say that you somehow become aware of them having a copy of your fingerprints and you remember that your phone requires your fingerprints to unlock; what do you do? It's the fact that you can't permanently change your fingerprints nor restrict access to them which make them bad for…

Isn't that assuming that the system will accept a copy of a fingerprint? Are you telling me that I could easily spoof the fingerprint readers in immigration control simply by applying some kind of copies of another person's fingerprints over my own? Anyway, if copying fingerprints is possible, then they are useless for forensics, contrary to your final point.

> Are you telling me that I could easily spoof the fingerprint readers in immigration control simply by applying some kind of copies of another person's fingerprints over my own?

Yes, it's pretty easy. However the immigration officer might notice.

> Anyway, if copying fingerprints is possible, then they are useless for forensics, contrary to your final point.

Well, it is possible to copy them, and they are not useless, therefor your conclusion has an error. And that error is that forensics does not require certainty, they require evidence. Evidence is probabilistic, and accumulating various forms of it can eventually be convincing, but each piece on its own is insufficient.

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#46
post #43

Earlier quoted context omitted.

But let's admit that there's no such thing as a secret, really, and it's more about how difficult a thing is to reproduce or reverse engineer. I mean, everything about security is just a big game of "hide the ball" and the question is how many hoops one must jump through to find the ball.

Of course there are secrets. What you are trying to say is that system will let you do many attempts till you guess the secret. But with biometrics there are no guesses - you know exactly what it should look like. There is difficulty in implementation certainly, but a basic principle of security is that each increment of difficulty in the securer (like a longer password) should increase the difficulty of the attacker…

Thanks for taking the time to respond here and elsewhere. You make some really interesting points, and I understand this topic much better now.
Post reply on HN