Live data from Hacker News

Fingerprints are Usernames, not Passwords

blog.dustinkirkland.com

1–10 of 261 posts

Re: Fingerprints are Usernames, not Passwords

#2
Above is by a "maintainer of eCryptfs" noting that we would otherwise leave our passwords on everything we touch and without option when that password is compromised.

I wonder though, is there a biometric facet that can surmount the bar of unreplicable uniqueness? Contact lenses can fool iris scanners. Perhaps we should make a dental impression sensor?

Re: Fingerprints are Usernames, not Passwords

#3
A very good point. One of the most important things about strong authentication schemes is the revocation protocol. When things go bad, how easy and secure is the process of changing the auth mechanism? The trouble with fingerprints is that you're stuck with them for life, even if somebody else gets their hands on them .

Re: Fingerprints are Usernames, not Passwords

#5
I'll be interested when someone breaks Touch ID in a real life theft. This is not a simple process, it's not clear that a determined thief is even likely to find a good enough print in a real life case, and you can't mess around because after 5 failed attempts it will prompt for a password.

Touch ID will likely cover the vast majority of security use cases for iPhone owners.

Re: Fingerprints are Usernames, not Passwords

#6
I'm not so sure. How many people are motivated to dupe your fingerprints to get into your iPhone? How many of those people could conceivably get into your iPhone through other ways?

Fingerprints are a nice way to keep almost everyone out of your device. And for the rest, well, I really doubt some other locking mechanism would've kept them out.

Re: Fingerprints are Usernames, not Passwords

#7
post #2

Above is by a "maintainer of eCryptfs" noting that we would otherwise leave our passwords on everything we touch and without option when that password is compromised. I wonder though, is there a biometric facet that can surmount the bar of unreplicable uniqueness? Contact lenses can fool iris scanners. Perhaps we should make a dental impression sensor?

"without option when that password is compromised."

I don't understand why people keep repeating this. As long as fingerprints are an optional authentication mechanism, you absolutely have an option if your fingerprint is compromised: switch to a passcode.

Re: Fingerprints are Usernames, not Passwords

#8
post #2

Above is by a "maintainer of eCryptfs" noting that we would otherwise leave our passwords on everything we touch and without option when that password is compromised. I wonder though, is there a biometric facet that can surmount the bar of unreplicable uniqueness? Contact lenses can fool iris scanners. Perhaps we should make a dental impression sensor?

Unique? Maybe. Unreplicable? I can't imagine so, we're all just a bunch of molecules.

At some point in the perhaps-not-too-distant future, we will likely have very sophisticated brain-scanning technologies, and combined with advances against biometric methods, basically any form of authentication will be useless.

I have absolutely no idea how to get around this, and can only hope that our society has advanced enough by that point that we don't need to keep any secrets at all. Not much chance of that really, IMHO...

Re: Fingerprints are Usernames, not Passwords

#10

I'm not so sure. How many people are motivated to dupe your fingerprints to get into your iPhone? How many of those people could conceivably get into your iPhone through other ways? Fingerprints are a nice way to keep almost everyone out of your device. And for the rest, well, I really doubt some other locking mechanism would've kept them out.

I'm sure 5s's are fetching at least $400 on the conservative side. If all I have to do is spend like $5 and follow a how-to on a website, I think a lot of people would be willing to make the investment.
Post reply on HN