Live data from Hacker News

Windows Hello – Biometric authentication to Windows 10 devices

blogs.windows.com

31–40 of 95 posts

Re: Windows Hello – Biometric authentication to Windows 10 devices

#31
post #20

This was demoed to my employer when Microsoft came through a month ago. I was not impressed -- biometrics are a username, not a password. edit: the article does not cover using your voice. I'm 99% sure they demoed to us the ability to use a custom phrase to authenticate with your voice as well.

> biometrics are a username, not a password.

Can you clarify what you mean by that. People like to parrot it, but few if any will explain why they feel that way.

If you simply mean that you don't find it secure enough, wouldn't that really depend on the use-case? For example, what may not be secure enough to log into a DC, may be secure enough to let the secretary log into their computer which just has access to address books and calendars. It is all relative.

Some biometric systems are fairly secure, like fingerprints. The cost and skill required to extract and reproduce a fingerprint so it is scannable make it a non-trivial affair. While the security services and a dedicated adversary could, for 80%+ of normal computer users it is a non-threat.

Android's face unlock may have been trivially beaten but it reads like Microsoft are using multi-level photography (i.e. both IR for under-the-skin and visible light for on-the-skin) to extract a layered model of a person's face and head which could (maybe) prove harder to bypass with just a photograph.

Re: Windows Hello – Biometric authentication to Windows 10 devices

#33

I hope that PINs and such always remain alternatives to biometrics. My usual concern -- if the locally stored biometric data is compromised (malware, poor crypto, etc.), I need a way to "change my password", which isn't really possible for something like facial recognition. Likewise, I'm curious if there's a fallback authentication method for people who lose a finger, get their faces deformed, etc. That said, the who…

Biometrics have more in common with usernames than passwords.

Re: Windows Hello – Biometric authentication to Windows 10 devices

#34

I hope that PINs and such always remain alternatives to biometrics. My usual concern -- if the locally stored biometric data is compromised (malware, poor crypto, etc.), I need a way to "change my password", which isn't really possible for something like facial recognition. Likewise, I'm curious if there's a fallback authentication method for people who lose a finger, get their faces deformed, etc. That said, the who…

Biometrics are user names, not passwords.

Re: Windows Hello – Biometric authentication to Windows 10 devices

#35
post #8
post #5

Earlier quoted context omitted.

Ah, so reading between the lines I'm going to guess they're building Win 10 devices with a built in kinect-like device that does depth sensing in addition to photo recognition.

Time to start 3D-printing faces...

You could, but it is an IR camera, so you better have the IR characteristics of your 3D face match also. If you combine IR and visible light photography you actually get a layered face-scan which is VERY hard to fake (not impossible, hard).

e.g. http://produceconsumerobot.com/biosensing/content/Face%20fev...

Re: Windows Hello – Biometric authentication to Windows 10 devices

#36

I hope that PINs and such always remain alternatives to biometrics. My usual concern -- if the locally stored biometric data is compromised (malware, poor crypto, etc.), I need a way to "change my password", which isn't really possible for something like facial recognition. Likewise, I'm curious if there's a fallback authentication method for people who lose a finger, get their faces deformed, etc. That said, the who…

An old one but this is more of a worry:

http://news.bbc.co.uk/1/hi/world/asia-pacific/4396831.stm

Plus it's pretty difficult to reissue a biometric ID if it is compromised.

Re: Windows Hello – Biometric authentication to Windows 10 devices

#37

I hope that PINs and such always remain alternatives to biometrics. My usual concern -- if the locally stored biometric data is compromised (malware, poor crypto, etc.), I need a way to "change my password", which isn't really possible for something like facial recognition. Likewise, I'm curious if there's a fallback authentication method for people who lose a finger, get their faces deformed, etc. That said, the who…

You don't need to only worry about your device being compromised, your biometric credentials are being leaked by your mere existence . Before long, I can imagine someone being able to build facial models capable of fooling recognition systems using only a few source images. Your finger prints are everywhere . Iris would be a bit harder, for now, but potentially possible with an image of high enough resolution.

Fingerprint and iris scanners have been compromised with nothing more than a high resolution image https://www.youtube.com/watch?v=vVivA0eoNGM

Re: Windows Hello – Biometric authentication to Windows 10 devices

#39
post #20

This was demoed to my employer when Microsoft came through a month ago. I was not impressed -- biometrics are a username, not a password. edit: the article does not cover using your voice. I'm 99% sure they demoed to us the ability to use a custom phrase to authenticate with your voice as well.

> biometrics are a username, not a password. Can you clarify what you mean by that. People like to parrot it, but few if any will explain why they feel that way. If you simply mean that you don't find it secure enough, wouldn't that really depend on the use-case? For example, what may not be secure enough to log into a DC, may be secure enough to let the secretary log into their computer which just has access to addr…

Biometrics is identification, not authentication.

It identifies who you are talking to, which is not the same as confirming who you are talking to (verifying authenticity of identity.)

Post reply on HN