Live data from Hacker News

Windows Hello – Biometric authentication to Windows 10 devices

blogs.windows.com

21–30 of 95 posts

Re: Windows Hello – Biometric authentication to Windows 10 devices

#21
post #17

Convenient, for sure. However, I always have the choice of not giving up my passwords, under (even painful) threat. Also, someone cannot get my passwords if I am dead. Ever. Unfortunately, with biometrics, it is quite easy to force me to put my face/finger/iris in front of the machine and unlock it. Even if I am (freshly) dead. Not that cool, really.

Wow - I guess any apps I build have to satisfy the "If I'm tortured" use case.

Something you have. Something you are. Something you know.

You actually really need the three of them. The last one prevents the scenario.

Re: Windows Hello – Biometric authentication to Windows 10 devices

#22
post #8
post #5

Earlier quoted context omitted.

Ah, so reading between the lines I'm going to guess they're building Win 10 devices with a built in kinect-like device that does depth sensing in addition to photo recognition.

Time to start 3D-printing faces...

I'm sure it could be done with paper folding.

Re: Windows Hello – Biometric authentication to Windows 10 devices

#24
post #17

Convenient, for sure. However, I always have the choice of not giving up my passwords, under (even painful) threat. Also, someone cannot get my passwords if I am dead. Ever. Unfortunately, with biometrics, it is quite easy to force me to put my face/finger/iris in front of the machine and unlock it. Even if I am (freshly) dead. Not that cool, really.

Real talk: I feel like the demographic of people who read and comment on HN is primarily people for whom "painful threat" is purely theoretical. Downstream folks are talking about preventing information leak if the adversary is literally willing to kill you via torture.

In the real world, torture is a fairly effective way to make somebody divulge information, especially in the case where it can be readily checked (by trying the password they divulge). It's a fairly well proven fact that living beings will do pretty much anything to make the pain stop. For recent reference, this HN article, where he repeatedly complied with demands, even including lying about being tortured, in the hope that it would make the torture stop:

https://news.ycombinator.com/item?id=9213753

Re: Windows Hello – Biometric authentication to Windows 10 devices

#25
post #8

Earlier quoted context omitted.

Time to start 3D-printing faces...

I'm sure it could be done with paper folding.

Come to think of it... print a cylindrical projection of the photo and then wrap around a cylinder...

Re: Windows Hello – Biometric authentication to Windows 10 devices

#26
post #21

Earlier quoted context omitted.

Wow - I guess any apps I build have to satisfy the "If I'm tortured" use case.

Something you have. Something you are. Something you know. You actually really need the three of them. The last one prevents the scenario.

The last one really just prevents the (immediate) death scenario. The something you know could presumably be why they're torturing you in the first place, caveats about the effectiveness of torture notwithstanding.

Re: Windows Hello – Biometric authentication to Windows 10 devices

#27

I hope that PINs and such always remain alternatives to biometrics. My usual concern -- if the locally stored biometric data is compromised (malware, poor crypto, etc.), I need a way to "change my password", which isn't really possible for something like facial recognition. Likewise, I'm curious if there's a fallback authentication method for people who lose a finger, get their faces deformed, etc. That said, the who…

Or if your device manufacturer decides it's time to store that data on their cloud and forces you to use their proprietary security tools. Good times.

Re: Windows Hello – Biometric authentication to Windows 10 devices

#28

I hope that PINs and such always remain alternatives to biometrics. My usual concern -- if the locally stored biometric data is compromised (malware, poor crypto, etc.), I need a way to "change my password", which isn't really possible for something like facial recognition. Likewise, I'm curious if there's a fallback authentication method for people who lose a finger, get their faces deformed, etc. That said, the who…

You don't need to only worry about your device being compromised, your biometric credentials are being leaked by your mere existence.

Before long, I can imagine someone being able to build facial models capable of fooling recognition systems using only a few source images. Your finger prints are everywhere. Iris would be a bit harder, for now, but potentially possible with an image of high enough resolution.

Re: Windows Hello – Biometric authentication to Windows 10 devices

#29
post #24
post #17

Convenient, for sure. However, I always have the choice of not giving up my passwords, under (even painful) threat. Also, someone cannot get my passwords if I am dead. Ever. Unfortunately, with biometrics, it is quite easy to force me to put my face/finger/iris in front of the machine and unlock it. Even if I am (freshly) dead. Not that cool, really.

Real talk: I feel like the demographic of people who read and comment on HN is primarily people for whom "painful threat" is purely theoretical. Downstream folks are talking about preventing information leak if the adversary is literally willing to kill you via torture. In the real world, torture is a fairly effective way to make somebody divulge information, especially in the case where it can be readily checked (by…

Not gonna lie, under threat of severe physical damage or death, I'd give away everything I know. Granted, I don't have access to nuclear weapons or anything, but I wouldn't care who gets effed up as long as I'm intact...
Post reply on HN