Live data from Hacker News

Fingerprints Are Usernames, Not Passwords (2013)

blog.dustinkirkland.com

21–30 of 106 posts

Re: Fingerprints Are Usernames, Not Passwords (2013)

#21

Earlier quoted context omitted.

A bad choice for what? Your fingerprint can only be used to access a particular device in the case of Touch ID. It is worthless if you don't also have physical access to the device. And it's a lot easier to tell if your device has been compromised because it means that you no longer possess it, in which case you can simply remote wipe it. To reiterate: Possession of your fingerprint alone does not allow someone to ac…

Your fingerprint can only be used to access a particular device in the case of Touch ID. It is worthless if you don't also have physical access to the device. Or any previous device you might have had with Touch ID. Unless you change your fingerprints when you get a new phone. And it's a lot easier to tell if your device has been compromised because it means that you no longer possess it, in which case you can simply…

Or any previous device you might have had with Touch ID. Unless you change your fingerprints when you get a new phone.

Or... You could wipe your old phone when you get a new one.

Which can easily be subverted by simply disallowing the phone from connecting to the Internet.

Perhaps, but you know what they say: If a (determined) attacker gains physical access to your device, all bets are off. But at least you would know if you lost your device. A password OTOH could be compromised without you knowing.

Also, I am only saying that Touch ID is at least as secure as a username/password authentication scheme. If you want more security (perhaps because your adversary is someone who would go to the lengths of manifacturing a fake finger to fool a Touch ID sensor and also get a Faraday Bag to prevent you from wiping your device), the you should perhaps consider using 2-factor authentication.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#22
post #13

Why not both? First, a fingerprint is unique, also serves as _identification_. Secondly, a fingerprint is secure to a very high degree - cannot be easily stolen and duplicated, always is with you and so on. Thus, it serves as _authentication_ too. EDIT: to the downvoters and critics: what you describe is using an _excess_ of effort to get my fingerprint ( technically, using force, etc ) . If I see a password, I can u…

[deleted]

Re: Fingerprints Are Usernames, Not Passwords (2013)

#23
post #13

Why not both? First, a fingerprint is unique, also serves as _identification_. Secondly, a fingerprint is secure to a very high degree - cannot be easily stolen and duplicated, always is with you and so on. Thus, it serves as _authentication_ too. EDIT: to the downvoters and critics: what you describe is using an _excess_ of effort to get my fingerprint ( technically, using force, etc ) . If I see a password, I can u…

Acquiring someone's fingerprints is trivial.

- that glass you touched at the bar ? screwed

- you touched the door handle of your apartment / car ? screwed

- you shook someone's hand ? screwed

- someone lent you his pen ? screwed

Passwords are a better choice because they can be changed (10 fingers max.) and the amount of security you want is dependent on the user. If you want a stronger password, it's your choice.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#24

I don't think many (outside of perhaps Apple PR?) have argued that fingerprint security is great, absolutely speaking. Relatively speaking, however, it is great, as many phone owners would otherwise not have any sort of locking security on their devices at all. Yes a fingerprint unlock is hackable, but it's a lot less hackable than your phone being open from the get go.

I think Apple are pretty aware of the limitations - they don't accept TouchID on first login after a restart, for the first purchase after a restart, if it's been 48 hours since an unlock or for resets/major config changes. For that you either need the PIN or, if you've opted for more security, the password.

Overall it feels that Apple's take is for day to day login it's better than a four digit PIN and it's better than no PIN.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#25
post #20

His argument proves too much. If he thinks fingerprints are too insecure to be allowed, then he must think the same of low-entropy passwords. Yet I don't see him advocating that Ubuntu force users to choose high-entropy passwords and rotate them regularly. If he's fine letting users choose a low level of security by picking simple passwords, why not also let them choose to auth with fingerprints? Also, I think he mis…

Not disagreeing with you, just going on a tangent and extrapolating the point from the article, the third method group, "something you are" might jump into the "something you have" if it can be extracted or copied from you which might be the case of fingerprints. You are the original source of fingerprint, but you leave copies of it everywhere, so then there are several sources to mimick from and they work just as well on these technologies.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#26
post #20

His argument proves too much. If he thinks fingerprints are too insecure to be allowed, then he must think the same of low-entropy passwords. Yet I don't see him advocating that Ubuntu force users to choose high-entropy passwords and rotate them regularly. If he's fine letting users choose a low level of security by picking simple passwords, why not also let them choose to auth with fingerprints? Also, I think he mis…

> Yet I don't see him advocating that Ubuntu force users...

He doesn't have to for his point to be valid.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#27

I don't think many (outside of perhaps Apple PR?) have argued that fingerprint security is great, absolutely speaking. Relatively speaking, however, it is great, as many phone owners would otherwise not have any sort of locking security on their devices at all. Yes a fingerprint unlock is hackable, but it's a lot less hackable than your phone being open from the get go.

I think Apple are pretty aware of the limitations - they don't accept TouchID on first login after a restart, for the first purchase after a restart, if it's been 48 hours since an unlock or for resets/major config changes. For that you either need the PIN or, if you've opted for more security, the password. Overall it feels that Apple's take is for day to day login it's better than a four digit PIN and it's better t…

>they don't accept TouchID on first login after a restart

That's because the hash of the print is stored on an encrypted volume of some kind, which requires your regular password to decrypt after a cold boot. Once the hash is in memory, the fingerprint can be used instead.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#28
post #20

His argument proves too much. If he thinks fingerprints are too insecure to be allowed, then he must think the same of low-entropy passwords. Yet I don't see him advocating that Ubuntu force users to choose high-entropy passwords and rotate them regularly. If he's fine letting users choose a low level of security by picking simple passwords, why not also let them choose to auth with fingerprints? Also, I think he mis…

> Yet I don't see him advocating that Ubuntu force users... He doesn't have to for his point to be valid.

He won't allow fingerprint reader support in eCryptfs, yet he has put no effort into adding password complexity rules to eCryptfs.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#29
post #19
post #13

Why not both? First, a fingerprint is unique, also serves as _identification_. Secondly, a fingerprint is secure to a very high degree - cannot be easily stolen and duplicated, always is with you and so on. Thus, it serves as _authentication_ too. EDIT: to the downvoters and critics: what you describe is using an _excess_ of effort to get my fingerprint ( technically, using force, etc ) . If I see a password, I can u…

Fingerprints can easily be acquired, if that weren't the case they wouldn't be extensively used in crime scene investigation. When fingerprints were supposed to be used as authentication, together with an ID card, in Germany, the German Chaos Computer Club acquired the fingerprint of the minister of the interior from a used glass and spoofed a reader with it by transfering the print to some adhesive tape.

I think what op means is that if you find someone's password, you can type it into their device and you are in. Total breaking in time 1h.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#30
post #17
post #13

Why not both? First, a fingerprint is unique, also serves as _identification_. Secondly, a fingerprint is secure to a very high degree - cannot be easily stolen and duplicated, always is with you and so on. Thus, it serves as _authentication_ too. EDIT: to the downvoters and critics: what you describe is using an _excess_ of effort to get my fingerprint ( technically, using force, etc ) . If I see a password, I can u…

A fingerprint is trivially stolen and duplicated, and once they have physical access to you it's trivial to coerce you to use it too.

People have been saying this kind of thing since the 5s debuted - is there any evidence that it's actually happened outside of the fevered imaginations of Whatif Warriors?
Post reply on HN