Live data from Hacker News

Fingerprints are Usernames, not Passwords

blog.dustinkirkland.com

11–20 of 261 posts

Re: Fingerprints are Usernames, not Passwords

#11
#66 on the Evil Overlord list:

My security keypad will actually be a fingerprint scanner. Anyone who watches someone press a sequence of buttons or dusts the pad for fingerprints then subsequently tries to enter by repeating that sequence will trigger the alarm system.

Why not have the sequence remain the password, but also scan fingerprints? If you have the wrong fingerprints (username), the right password still won't work.

http://www.eviloverlord.com/lists/overlord.html

Re: Fingerprints are Usernames, not Passwords

#13
post #3

A very good point. One of the most important things about strong authentication schemes is the revocation protocol. When things go bad, how easy and secure is the process of changing the auth mechanism? The trouble with fingerprints is that you're stuck with them for life, even if somebody else gets their hands on them .

Wouldn't the revocation process be very simple? If some one has acquired your prints, just stop using touch ID? I mean, there are still 2 other authentication options on the iPhone.

Re: Fingerprints are Usernames, not Passwords

#14
Makes sense. Just like in a PGP web of trust, where that key is your unique identity, so will these fingerprints be. But it's a lot riskier to use them as your passwords (either against the NSA or other dedicated hackers).

Re: Fingerprints are Usernames, not Passwords

#15
post #5

I'll be interested when someone breaks Touch ID in a real life theft. This is not a simple process, it's not clear that a determined thief is even likely to find a good enough print in a real life case, and you can't mess around because after 5 failed attempts it will prompt for a password. Touch ID will likely cover the vast majority of security use cases for iPhone owners.

I saw the CCC video and I think you are right, a suitable print being found on the phone is a bit slim, although not impossible.

However, I think the point of the article is that you can change a compromised password, you can't change a compromised fingerprint. As is mentioned, there are plenty of databases with fingerprint information. Also, for the crowd that is paranoid about government accessing their data, an authority might have an easier time getting into a device when they already have your fingerprint as opposed to figuring out your passwords.

Re: Fingerprints are Usernames, not Passwords

#16

I'm not so sure. How many people are motivated to dupe your fingerprints to get into your iPhone? How many of those people could conceivably get into your iPhone through other ways? Fingerprints are a nice way to keep almost everyone out of your device. And for the rest, well, I really doubt some other locking mechanism would've kept them out.

I'm sure 5s's are fetching at least $400 on the conservative side. If all I have to do is spend like $5 and follow a how-to on a website, I think a lot of people would be willing to make the investment.

If your objective is to sell a stolen iPhone then you still have to know the owners Apple ID and password due to activation lock. Being able to bypass Touch ID isn't going to help you.

Re: Fingerprints are Usernames, not Passwords

#17
This might be true for things that truly need to be secure (bank vaults, super secret government facilities, etc.). Clearly in those cases just relying on a fingerprint that could be compromised by motivated attackers is not enough. But personally (and I imagine this is true for many users) I'm not trying to secure my iPhone from highly motivated and skilled attackers. Those individuals will probably be able to access the data on my iPhone fingerprint or not. Given that, it just is a convenience feature, allowing me to secure my phone from the everyday person trying to pry into my phone and give me access much easier and quicker.

Re: Fingerprints are Usernames, not Passwords

#18

I'm not so sure. How many people are motivated to dupe your fingerprints to get into your iPhone? How many of those people could conceivably get into your iPhone through other ways? Fingerprints are a nice way to keep almost everyone out of your device. And for the rest, well, I really doubt some other locking mechanism would've kept them out.

What I think he is saying is that because it is now on iPhone, more devices/services/whatever may be likely to use finger prints for auth. This is dangerous because you can't change your fingerprint in the unlikely case someone dupes your print. If more and more things rely on finger prints, the value of duping goes up, right? What happens when your prints are duped once?

Re: Fingerprints are Usernames, not Passwords

#19

I'm not so sure. How many people are motivated to dupe your fingerprints to get into your iPhone? How many of those people could conceivably get into your iPhone through other ways? Fingerprints are a nice way to keep almost everyone out of your device. And for the rest, well, I really doubt some other locking mechanism would've kept them out.

What are people going to do when, in the all-too-near future, criminals begin sharing and selling databases of stolen high resolution finger prints?

One theft isn't practical? How about a million? Driven by a never-ending pursuit of monetary gain via crime; with criminals always happy to conquer the latest technology wave. There's absolutely no reason to think that criminals won't amass substantial finger print records just like they do any other intimate information they can get their hands on, from SS numbers to passwords. It's not a question of if, but when this starts becoming common.

All it requires is linking finger prints to something valuable at a mass market scale, and that will drive an unlimited criminal demand for finger prints.

It's not about the iPhone. It's about a consumer shift to finger prints as a primary security feature, and whether that is sane (with the iPhone potentially setting the trend given its cultural status).

Re: Fingerprints are Usernames, not Passwords

#20
post #4

then don't use it. For me, it far outweighs having to type my password in everytime.

I don't think anyone cares what level of security you are personally comfortable with. If you are fine with its weaknesses, go for it.

However, those of us that set security on company devices are very interested in the quality of different methods, and are glad to as many learned opinions on the matter as possible.

Post reply on HN