Earlier quoted context omitted.
I'm sure it could be done with paper folding.
Come to think of it... print a cylindrical projection of the photo and then wrap around a cylinder...
Windows Hello – Biometric authentication to Windows 10 devices
41–50 of 95 posts
Re: Windows Hello – Biometric authentication to Windows 10 devices
#42Convenient, for sure. However, I always have the choice of not giving up my passwords, under (even painful) threat. Also, someone cannot get my passwords if I am dead. Ever. Unfortunately, with biometrics, it is quite easy to force me to put my face/finger/iris in front of the machine and unlock it. Even if I am (freshly) dead. Not that cool, really.
Real talk: I feel like the demographic of people who read and comment on HN is primarily people for whom "painful threat" is purely theoretical. Downstream folks are talking about preventing information leak if the adversary is literally willing to kill you via torture. In the real world, torture is a fairly effective way to make somebody divulge information, especially in the case where it can be readily checked (by…
Re: Windows Hello – Biometric authentication to Windows 10 devices
#43Earlier quoted context omitted.
> biometrics are a username, not a password. Can you clarify what you mean by that. People like to parrot it, but few if any will explain why they feel that way. If you simply mean that you don't find it secure enough, wouldn't that really depend on the use-case? For example, what may not be secure enough to log into a DC, may be secure enough to let the secretary log into their computer which just has access to addr…
Biometrics is identification, not authentication. It identifies who you are talking to, which is not the same as confirming who you are talking to (verifying authenticity of identity.)
That's a whole of a lot better than a password, which can be shared by multiple people.
Re: Windows Hello – Biometric authentication to Windows 10 devices
#44They claim physical access for "hacking" is required, but that is not true. As long as you have a root access on a device you can do anything from anywhere. I don't see how this replaces or improves passwords from this perspective. Yes it is easier for the user, since they don't have to remember the password, but everything else stays the same.
> As long as you have a root access on a device you can do anything from anywhere. As Raymond Chen likes to say, "it rather involved being on the other side of this airtight hatchway." Once you have root, yes, you have compromised the machine.
Re: Windows Hello – Biometric authentication to Windows 10 devices
#45This was demoed to my employer when Microsoft came through a month ago. I was not impressed -- biometrics are a username, not a password. edit: the article does not cover using your voice. I'm 99% sure they demoed to us the ability to use a custom phrase to authenticate with your voice as well.
> biometrics are a username, not a password. Can you clarify what you mean by that. People like to parrot it, but few if any will explain why they feel that way. If you simply mean that you don't find it secure enough, wouldn't that really depend on the use-case? For example, what may not be secure enough to log into a DC, may be secure enough to let the secretary log into their computer which just has access to addr…
Biometric data are not secret (face, fingerprints, voice) nor can be changed.
That means they are easy to forge and hard to revoke when compromised, and at most they can be useful as identification, like your email, and not as password.
I wonder why none thought of biometric identification with an hardware token which plays a one time tone outside audible spectrum. That would be incredibly convenient for users and still quite resilient. Just throw in side channel auth like phone message for unknown position or devices and of you go.
Re: Windows Hello – Biometric authentication to Windows 10 devices
#46I hope that PINs and such always remain alternatives to biometrics. My usual concern -- if the locally stored biometric data is compromised (malware, poor crypto, etc.), I need a way to "change my password", which isn't really possible for something like facial recognition. Likewise, I'm curious if there's a fallback authentication method for people who lose a finger, get their faces deformed, etc. That said, the who…
Biometrics have more in common with usernames than passwords.
Re: Windows Hello – Biometric authentication to Windows 10 devices
#47I'd love to understand more about how the face recognition works. Does it have any way to combat someone just printing out a picture of your face and holding it up? I've done some simple face recognition stuff with OpenCV and it's super easy to fool with photos.
Windows Hello uses a combination of special hardware and software to accurately verify it is you – not a picture of you or someone trying to impersonate you. The cameras use infrared technology to identify your face or iris and can recognize you in a variety of lighting conditions. and later in the webpage: all OEM systems incorporating the Intel® RealSense™ 3D Camera (F200) will support the facial and iris unlock fe…
However, if I were to pick, I'd go for fingerprint recognition instead. Images of people's faces are everywhere online. It's much less likely to have a good photo of your fingerprints.
Re: Windows Hello – Biometric authentication to Windows 10 devices
#48Re: Windows Hello – Biometric authentication to Windows 10 devices
#49Earlier quoted context omitted.
Time to start 3D-printing faces...
You could, but it is an IR camera, so you better have the IR characteristics of your 3D face match also. If you combine IR and visible light photography you actually get a layered face-scan which is VERY hard to fake (not impossible, hard). e.g. http://produceconsumerobot.com/biosensing/content/Face%20fev...
Re: Windows Hello – Biometric authentication to Windows 10 devices
#50Earlier quoted context omitted.
The video actually shows a person attempting this, and it did not unlock the computer.
It did..? I think.