As with many things, it depends heavily on what you're using it for . Not as pithy for a title though, I suppose. No amount of information entered into a computer fully proves it's you and not someone else. A fingerprint provides some information, as does a password. This sounds like a fairly useless distinction, but hopefully this will make sense: If all we're doing is trying to prove we're us and not someone else,…
Fingerprints Are Usernames, Not Passwords (2013)
11–20 of 106 posts
Re: Fingerprints Are Usernames, Not Passwords (2013)
#12As with many things, it depends heavily on what you're using it for . Not as pithy for a title though, I suppose. No amount of information entered into a computer fully proves it's you and not someone else. A fingerprint provides some information, as does a password. This sounds like a fairly useless distinction, but hopefully this will make sense: If all we're doing is trying to prove we're us and not someone else,…
I think that's all irrelevant. Passwords can be compromised and must be changeable - that alone makes fingerprints a bad choice.
Re: Fingerprints Are Usernames, Not Passwords (2013)
#13First, a fingerprint is unique, also serves as _identification_.
Secondly, a fingerprint is secure to a very high degree - cannot be easily stolen and duplicated, always is with you and so on. Thus, it serves as _authentication_ too.
EDIT: to the downvoters and critics: what you describe is using an _excess_ of effort to get my fingerprint ( technically, using force, etc ) . If I see a password, I can use it immediatelly, if you see my finger, there is a long way ( in terms of steps) until you can use the fingerprint attached to it. And btw, I am not defending Apple here.
Re: Fingerprints Are Usernames, Not Passwords (2013)
#14Re: Fingerprints Are Usernames, Not Passwords (2013)
#15Earlier quoted context omitted.
I think that's all irrelevant. Passwords can be compromised and must be changeable - that alone makes fingerprints a bad choice.
A bad choice for what? Your fingerprint can only be used to access a particular device in the case of Touch ID. It is worthless if you don't also have physical access to the device. And it's a lot easier to tell if your device has been compromised because it means that you no longer possess it, in which case you can simply remote wipe it. To reiterate: Possession of your fingerprint alone does not allow someone to ac…
Or any previous device you might have had with Touch ID. Unless you change your fingerprints when you get a new phone.
And it's a lot easier to tell if your device has been compromised because it means that you no longer possess it, in which case you can simply remote wipe it.
Which can easily be subverted by simply disallowing the phone from connecting to the Internet. A "faraday bag" costs a few bucks. Assuming TouchID doesn't prevent you from logging in without Internet access, of course.
Re: Fingerprints Are Usernames, Not Passwords (2013)
#16Why not both? First, a fingerprint is unique, also serves as _identification_. Secondly, a fingerprint is secure to a very high degree - cannot be easily stolen and duplicated, always is with you and so on. Thus, it serves as _authentication_ too. EDIT: to the downvoters and critics: what you describe is using an _excess_ of effort to get my fingerprint ( technically, using force, etc ) . If I see a password, I can u…
Once of the major issues with biometrics is revocation. If compromised it can be difficult to change!
Re: Fingerprints Are Usernames, Not Passwords (2013)
#17Why not both? First, a fingerprint is unique, also serves as _identification_. Secondly, a fingerprint is secure to a very high degree - cannot be easily stolen and duplicated, always is with you and so on. Thus, it serves as _authentication_ too. EDIT: to the downvoters and critics: what you describe is using an _excess_ of effort to get my fingerprint ( technically, using force, etc ) . If I see a password, I can u…
Re: Fingerprints Are Usernames, Not Passwords (2013)
#18Why not both? First, a fingerprint is unique, also serves as _identification_. Secondly, a fingerprint is secure to a very high degree - cannot be easily stolen and duplicated, always is with you and so on. Thus, it serves as _authentication_ too. EDIT: to the downvoters and critics: what you describe is using an _excess_ of effort to get my fingerprint ( technically, using force, etc ) . If I see a password, I can u…
you might want to review some of the literature around bypassing fingerprint readers before making that kind of statement... A large number of readers are easily fooled by copied prints. Also there's the False acceptance/false rejection rate tradeoff to consider. Once of the major issues with biometrics is revocation. If compromised it can be difficult to change!
Re: Fingerprints Are Usernames, Not Passwords (2013)
#19Why not both? First, a fingerprint is unique, also serves as _identification_. Secondly, a fingerprint is secure to a very high degree - cannot be easily stolen and duplicated, always is with you and so on. Thus, it serves as _authentication_ too. EDIT: to the downvoters and critics: what you describe is using an _excess_ of effort to get my fingerprint ( technically, using force, etc ) . If I see a password, I can u…
Re: Fingerprints Are Usernames, Not Passwords (2013)
#20Also, I think he misconstrues the purpose of Touch ID. It's not meant to completely replace passwords.
There are three categories of authentication methods:
1. Something you know (password, combination, challenge responses).
2. Something you have (crypto token, phone, key).
3. Something you are (fingerprint, face, DNA, etc).
Methods can be combined for added security. All three have advantages and disadvantages. Passwords are typically chosen by users, making them weak. Good crypto tokens are hard to copy, but loss or theft can mean getting locked-out. Biometrics are convenient, but can't be revoked. Also, some activities can make them hard to read.[1]
Apple uses all three authentication methods in the iPhone. Touch ID is for basic access. The passcode is for admin-level functionality like erasing or restoring the device. Lastly, physical access to the phone is required to decrypt important data such as Apple Pay's Device Access Numbers. This gives typical, non-technical users a sane combination of security and convenience. If thieves and scammers start copying fingerprints, Apple will change their auth mechanisms.
1. I love Touch ID, but it takes a while to work again after I rock climb or lift weights.