Live data from Hacker News

Fingerprints Are Usernames, Not Passwords (2013)

blog.dustinkirkland.com

61–70 of 106 posts

Re: Fingerprints Are Usernames, Not Passwords (2013)

#61

Something I feel that's always missed in these discussions is context: Who is the adversary you're attempting to protect against? Your kids screwing around with your phone? TouchID does the job. Random people screwing around with your phone if they find it? Same thing. Government gets ahold of it? Yeah.. notsomuch. Considering that the primary adversaries of an average smartphone user are other mere mortals, not dedi…

In the biometrics field we use the threshold that separates an authentic and impostor match score to adjust our system sensitivity - for TouchID it's set such that the false acceptance rate (FAR) is high, while the gov may set it very low (usually the standard for papers is looking at the false reject rate at 0.1% FAR).

The alternative you suggest is related to biometric key binding (http://www.cs.cmu.edu/~vboddeti/key-binding.html).

Re: Fingerprints Are Usernames, Not Passwords (2013)

#63

Something I feel that's always missed in these discussions is context: Who is the adversary you're attempting to protect against? Your kids screwing around with your phone? TouchID does the job. Random people screwing around with your phone if they find it? Same thing. Government gets ahold of it? Yeah.. notsomuch. Considering that the primary adversaries of an average smartphone user are other mere mortals, not dedi…

This a thousand times!

When you think about security, you should have in mind who you are protecting against, and the same applies to passwords.

Security purists love to advocate that password reuse is evil, but who in the first place is going to be your attacker and for which purpose?

For example, in the context of money (online banking, paypal, ebay, etc.) I completely agree that password reuse is evil.

But when it comes to random websites, or simply to access my devices does it really matter? The first time I saw the Chromebook my first impression was "do I really have to write my entire Gmail password EVERY TIME I want to access this thing???" With my Galaxy S5 I was like "Don't tell me how should I create a password to unlock you!!! If I want to use 0000 it's my problem!!!"

I personally like the approach of FastMail: Different Login methods (like using Google Authenticator to generate random one time use passwords, or the ability to create different plaintext passwords). You decide which login methods allows you to access your account, and which ones allows you to manage it.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#64

Something I feel that's always missed in these discussions is context: Who is the adversary you're attempting to protect against? Your kids screwing around with your phone? TouchID does the job. Random people screwing around with your phone if they find it? Same thing. Government gets ahold of it? Yeah.. notsomuch. Considering that the primary adversaries of an average smartphone user are other mere mortals, not dedi…

Still, I'd rather not give hardened criminals a reason to cut off my fingers.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#65
post #53

Passwords are not passwords, they are usernames. It's a part from the combination to identify you, while unlike usernames, it's hidden by design. Fingerprints are like passwords, they can't be easily copied and be reused somewhere else, for now.

I came to say essentially the same thing, but not quite. Fingerprints are not like passwords. You can't reset them or change them.

Something you know: Username/password Something you have: security key/phone Something you are: fingerprint/facial recognition

Those are three factors of authentication. Can anyone think of others?

Re: Fingerprints Are Usernames, Not Passwords (2013)

#66
post #64

Something I feel that's always missed in these discussions is context: Who is the adversary you're attempting to protect against? Your kids screwing around with your phone? TouchID does the job. Random people screwing around with your phone if they find it? Same thing. Government gets ahold of it? Yeah.. notsomuch. Considering that the primary adversaries of an average smartphone user are other mere mortals, not dedi…

Still, I'd rather not give hardened criminals a reason to cut off my fingers.

I think that goes back to identifying adversaries. It's unlikely a criminal would attempt to cut off fingers for access to a random smartphone.

If you have secrets that are very valuable, you are outside the standard use case, and should probably use more advanced authentication.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#67
post #13

Why not both? First, a fingerprint is unique, also serves as _identification_. Secondly, a fingerprint is secure to a very high degree - cannot be easily stolen and duplicated, always is with you and so on. Thus, it serves as _authentication_ too. EDIT: to the downvoters and critics: what you describe is using an _excess_ of effort to get my fingerprint ( technically, using force, etc ) . If I see a password, I can u…

lol. This is not Hollywood. A phone thief isn't going to be using tape and superglue to find your fingerprint. Do you really want to encourage someone to remove your index finger when they mug you for your phone?

Re: Fingerprints Are Usernames, Not Passwords (2013)

#68
post #67
post #13

Why not both? First, a fingerprint is unique, also serves as _identification_. Secondly, a fingerprint is secure to a very high degree - cannot be easily stolen and duplicated, always is with you and so on. Thus, it serves as _authentication_ too. EDIT: to the downvoters and critics: what you describe is using an _excess_ of effort to get my fingerprint ( technically, using force, etc ) . If I see a password, I can u…

lol. This is not Hollywood. A phone thief isn't going to be using tape and superglue to find your fingerprint. Do you really want to encourage someone to remove your index finger when they mug you for your phone?

But is there a single piece of evidence for this ever happening outside of Hollywood?

Re: Fingerprints Are Usernames, Not Passwords (2013)

#69
post #64

Something I feel that's always missed in these discussions is context: Who is the adversary you're attempting to protect against? Your kids screwing around with your phone? TouchID does the job. Random people screwing around with your phone if they find it? Same thing. Government gets ahold of it? Yeah.. notsomuch. Considering that the primary adversaries of an average smartphone user are other mere mortals, not dedi…

Still, I'd rather not give hardened criminals a reason to cut off my fingers.

Touch ID only works for a minute or two after your finger is cut off. Touch ID reads the blood vessels, not the fingerprint, meaning it only works for a minute or two after the finger is cut off.

Re: Fingerprints Are Usernames, Not Passwords (2013)

#70
post #64

Earlier quoted context omitted.

Still, I'd rather not give hardened criminals a reason to cut off my fingers.

Touch ID only works for a minute or two after your finger is cut off. Touch ID reads the blood vessels, not the fingerprint, meaning it only works for a minute or two after the finger is cut off.

I'm not really interested in being the one on whom someone learns that, though.
Post reply on HN