Live data from Hacker News

Fingerprints Are Usernames, Not Passwords (2013)

blog.dustinkirkland.com

11–20 of 106 posts

Re: Fingerprints Are Usernames, Not Passwords (2013)

#11
post #8

As with many things, it depends heavily on what you're using it for . Not as pithy for a title though, I suppose. No amount of information entered into a computer fully proves it's you and not someone else. A fingerprint provides some information, as does a password. This sounds like a fairly useless distinction, but hopefully this will make sense: If all we're doing is trying to prove we're us and not someone else,…

I think that's all irrelevant. Passwords can be compromised and must be changeable - that alone makes fingerprints a bad choice.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#12
post #8

As with many things, it depends heavily on what you're using it for . Not as pithy for a title though, I suppose. No amount of information entered into a computer fully proves it's you and not someone else. A fingerprint provides some information, as does a password. This sounds like a fairly useless distinction, but hopefully this will make sense: If all we're doing is trying to prove we're us and not someone else,…

I think that's all irrelevant. Passwords can be compromised and must be changeable - that alone makes fingerprints a bad choice.

A bad choice for what? Your fingerprint can only be used to access a particular device in the case of Touch ID. It is worthless if you don't also have physical access to the device. And it's a lot easier to tell if your device has been compromised because it means that you no longer possess it, in which case you can simply remote wipe it. To reiterate: Possession of your fingerprint alone does not allow someone to access your bank account or log into your webmail.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#13
Why not both?

First, a fingerprint is unique, also serves as _identification_.

Secondly, a fingerprint is secure to a very high degree - cannot be easily stolen and duplicated, always is with you and so on. Thus, it serves as _authentication_ too.

EDIT: to the downvoters and critics: what you describe is using an _excess_ of effort to get my fingerprint ( technically, using force, etc ) . If I see a password, I can use it immediatelly, if you see my finger, there is a long way ( in terms of steps) until you can use the fingerprint attached to it. And btw, I am not defending Apple here.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#15

Earlier quoted context omitted.

I think that's all irrelevant. Passwords can be compromised and must be changeable - that alone makes fingerprints a bad choice.

A bad choice for what? Your fingerprint can only be used to access a particular device in the case of Touch ID. It is worthless if you don't also have physical access to the device. And it's a lot easier to tell if your device has been compromised because it means that you no longer possess it, in which case you can simply remote wipe it. To reiterate: Possession of your fingerprint alone does not allow someone to ac…

Your fingerprint can only be used to access a particular device in the case of Touch ID. It is worthless if you don't also have physical access to the device.

Or any previous device you might have had with Touch ID. Unless you change your fingerprints when you get a new phone.

And it's a lot easier to tell if your device has been compromised because it means that you no longer possess it, in which case you can simply remote wipe it.

Which can easily be subverted by simply disallowing the phone from connecting to the Internet. A "faraday bag" costs a few bucks. Assuming TouchID doesn't prevent you from logging in without Internet access, of course.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#16
post #13

Why not both? First, a fingerprint is unique, also serves as _identification_. Secondly, a fingerprint is secure to a very high degree - cannot be easily stolen and duplicated, always is with you and so on. Thus, it serves as _authentication_ too. EDIT: to the downvoters and critics: what you describe is using an _excess_ of effort to get my fingerprint ( technically, using force, etc ) . If I see a password, I can u…

you might want to review some of the literature around bypassing fingerprint readers before making that kind of statement... A large number of readers are easily fooled by copied prints. Also there's the False acceptance/false rejection rate tradeoff to consider.

Once of the major issues with biometrics is revocation. If compromised it can be difficult to change!

Re: Fingerprints Are Usernames, Not Passwords (2013)

#17
post #13

Why not both? First, a fingerprint is unique, also serves as _identification_. Secondly, a fingerprint is secure to a very high degree - cannot be easily stolen and duplicated, always is with you and so on. Thus, it serves as _authentication_ too. EDIT: to the downvoters and critics: what you describe is using an _excess_ of effort to get my fingerprint ( technically, using force, etc ) . If I see a password, I can u…

A fingerprint is trivially stolen and duplicated, and once they have physical access to you it's trivial to coerce you to use it too.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#18
post #13

Why not both? First, a fingerprint is unique, also serves as _identification_. Secondly, a fingerprint is secure to a very high degree - cannot be easily stolen and duplicated, always is with you and so on. Thus, it serves as _authentication_ too. EDIT: to the downvoters and critics: what you describe is using an _excess_ of effort to get my fingerprint ( technically, using force, etc ) . If I see a password, I can u…

you might want to review some of the literature around bypassing fingerprint readers before making that kind of statement... A large number of readers are easily fooled by copied prints. Also there's the False acceptance/false rejection rate tradeoff to consider. Once of the major issues with biometrics is revocation. If compromised it can be difficult to change!

There's also the glossy fingerprint attracting screen of the iphone. Creating an artificial fingerprint from what you've left on the screen would be non trivial but far from impossible.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#19
post #13

Why not both? First, a fingerprint is unique, also serves as _identification_. Secondly, a fingerprint is secure to a very high degree - cannot be easily stolen and duplicated, always is with you and so on. Thus, it serves as _authentication_ too. EDIT: to the downvoters and critics: what you describe is using an _excess_ of effort to get my fingerprint ( technically, using force, etc ) . If I see a password, I can u…

Fingerprints can easily be acquired, if that weren't the case they wouldn't be extensively used in crime scene investigation. When fingerprints were supposed to be used as authentication, together with an ID card, in Germany, the German Chaos Computer Club acquired the fingerprint of the minister of the interior from a used glass and spoofed a reader with it by transfering the print to some adhesive tape.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#20
His argument proves too much. If he thinks fingerprints are too insecure to be allowed, then he must think the same of low-entropy passwords. Yet I don't see him advocating that Ubuntu force users to choose high-entropy passwords and rotate them regularly. If he's fine letting users choose a low level of security by picking simple passwords, why not also let them choose to auth with fingerprints?

Also, I think he misconstrues the purpose of Touch ID. It's not meant to completely replace passwords.

There are three categories of authentication methods:

1. Something you know (password, combination, challenge responses).

2. Something you have (crypto token, phone, key).

3. Something you are (fingerprint, face, DNA, etc).

Methods can be combined for added security. All three have advantages and disadvantages. Passwords are typically chosen by users, making them weak. Good crypto tokens are hard to copy, but loss or theft can mean getting locked-out. Biometrics are convenient, but can't be revoked. Also, some activities can make them hard to read.[1]

Apple uses all three authentication methods in the iPhone. Touch ID is for basic access. The passcode is for admin-level functionality like erasing or restoring the device. Lastly, physical access to the phone is required to decrypt important data such as Apple Pay's Device Access Numbers. This gives typical, non-technical users a sane combination of security and convenience. If thieves and scammers start copying fingerprints, Apple will change their auth mechanisms.

1. I love Touch ID, but it takes a while to work again after I rock climb or lift weights.

Post reply on HN