Live data from Hacker News

Windows Hello – Biometric authentication to Windows 10 devices

blogs.windows.com

71–80 of 95 posts

Re: Windows Hello – Biometric authentication to Windows 10 devices

#71
One thing I like about passwords is that they give me the choice to not unlock something, should I wish that, which isn't the case with biometrics. Say I'm a journalist who gets stopped at the border of a country and am asked to open up my computer. If I want to, I can refuse - and face the consequences but still, i can make that choice. With biometrics all they'd have to do is force my finger onto the scanner, or put the computer in front of me and scan my iris or face. That's a big downside.

Also, after everything we know about Microsoft and and the security services, there's absolutely no way I'd give them my biometric data.

Re: Windows Hello – Biometric authentication to Windows 10 devices

#72
post #71

One thing I like about passwords is that they give me the choice to not unlock something, should I wish that, which isn't the case with biometrics. Say I'm a journalist who gets stopped at the border of a country and am asked to open up my computer. If I want to, I can refuse - and face the consequences but still, i can make that choice. With biometrics all they'd have to do is force my finger onto the scanner, or pu…

Followed you and agreed up until the last paragraph. Can you elaborate?

Re: Windows Hello – Biometric authentication to Windows 10 devices

#73
post #60

Earlier quoted context omitted.

"A biometric is both a 'username' and a 'password' " This is true, but usually people don't go around showing their passwords to any camera they walk by or surface they touch. That is why people say that it is more appropriate for biometrics to identify someone than it is to provide their authentication. "our password is just as at risk as your fingerprint." Also true, but what do you do when these breaches happen if…

> usually people don't go around showing their passwords to any camera they walk by or surface they touch. That is why people say that it is more appropriate for biometrics to identify someone than it is to provide their authentication. Yea i see the point, but there will always need to be an asterisk after the statement, "a biometric is a username, not a password", because it's only valid in the sense there are conc…

> Yea I see the point, but there will always need to be an asterisk after the statement, "a biometric is a username, not a password", because it's only valid in the sense there are concerns about the security of the biometric template. Down the line maybe we'll figure out this spoofing/liveness test thing, but we won't find out while many instantly write off the merit of the system to begin with.

Any sensor accurate enough to perform biometrics is simultaneously accurate enough to create a spoof capable of fooling the authentication sensor. The only way to avoid this requires an active activity, at which case you've just duplicated the password [e.g. the act of typing is identical to the act of sufficient action to make it virtually impossible to duplicate] which has better known security characteristics.

> I did mention this somewhat in the original post. Saving a raw biometric template (minutiae points or whatnot) is synonymous to keeping a database of plain text passwords. It's just wrong. The data breaches (Uber, Target, etc.) are proof that in 2015, we still have this problem. I would never trust a start-up or large corporation with consumer grade biometric authentication. However, on my laptop a different story...i've been using the Thinkpad fingerprint reader for years and love it.

A single breach and you cannot rely on biometric data for life is the reason this is only safe to use as a "username" and not a password. You won't be able to significantly change your biometrics w/o breaking other identification issues.

Biometrics are only valid as a username or secondary authentication factor.

Re: Windows Hello – Biometric authentication to Windows 10 devices

#74
post #71

One thing I like about passwords is that they give me the choice to not unlock something, should I wish that, which isn't the case with biometrics. Say I'm a journalist who gets stopped at the border of a country and am asked to open up my computer. If I want to, I can refuse - and face the consequences but still, i can make that choice. With biometrics all they'd have to do is force my finger onto the scanner, or pu…

Followed you and agreed up until the last paragraph. Can you elaborate?

Just the usual post-Snowden concerns about MS... http://www.theguardian.com/world/2013/jul/11/microsoft-nsa-c...

Re: Windows Hello – Biometric authentication to Windows 10 devices

#75
post #74

Earlier quoted context omitted.

Followed you and agreed up until the last paragraph. Can you elaborate?

Just the usual post-Snowden concerns about MS... http://www.theguardian.com/world/2013/jul/11/microsoft-nsa-c...

Yeah it looks like it'd be vulnerable to an NSL or Prism req. Thanks for the link.

Re: Windows Hello – Biometric authentication to Windows 10 devices

#76
post #74

Earlier quoted context omitted.

Followed you and agreed up until the last paragraph. Can you elaborate?

Just the usual post-Snowden concerns about MS... http://www.theguardian.com/world/2013/jul/11/microsoft-nsa-c...

Just an FYI, but that was the least useful bit of the Snowden leaks and is more speculation and insinuation than anything. It's literally based on the reading of a PowerPoint slide. AFAIK, there's been no actual evidence of "direct access", whatever that's supposed to mean. An automatic subpoena-serving could easily be written down as " direct access " on a ppt to management.

It's probably a good idea to not store critical data with any third parties, but I'd be far more worried about Google than MS.

Re: Windows Hello – Biometric authentication to Windows 10 devices

#77

Earlier quoted context omitted.

You could, but it is an IR camera, so you better have the IR characteristics of your 3D face match also. If you combine IR and visible light photography you actually get a layered face-scan which is VERY hard to fake (not impossible, hard). e.g. http://produceconsumerobot.com/biosensing/content/Face%20fev...

What if you just hack the webcam firmware - like celebrity hackers and FBI have done for years already?

If you can modify firmware, you've probably already won. Unless the auth is done remotely and requires remote attestation, perhaps.

Re: Windows Hello – Biometric authentication to Windows 10 devices

#78

Earlier quoted context omitted.

> usually people don't go around showing their passwords to any camera they walk by or surface they touch. That is why people say that it is more appropriate for biometrics to identify someone than it is to provide their authentication. Yea i see the point, but there will always need to be an asterisk after the statement, "a biometric is a username, not a password", because it's only valid in the sense there are conc…

> Yea I see the point, but there will always need to be an asterisk after the statement, "a biometric is a username, not a password", because it's only valid in the sense there are concerns about the security of the biometric template. Down the line maybe we'll figure out this spoofing/liveness test thing, but we won't find out while many instantly write off the merit of the system to begin with. Any sensor accurate…

>The only way to avoid this requires an active activity, at which case you've just duplicated the password [e.g. the act of typing is identical to the act of sufficient action to make it virtually impossible to duplicate] which has better known security characteristics.

Only way is active activity? Or just the only way you can think of?

>A single breach and you cannot rely on biometric data for life is the reason this is only safe to use as a "username" and not a password. You won't be able to significantly change your biometrics w/o breaking other identification issues.

You're assuming all recognition algorithms of the same biometric produce the same raw template. That if I get one I can gain access on another.

>Biometrics are only valid as a username or secondary authentication factor

It's often frustrating to discuss things with those who clearly know little about the topic and yet declare their opinion as fact.

Re: Windows Hello – Biometric authentication to Windows 10 devices

#79
post #71

One thing I like about passwords is that they give me the choice to not unlock something, should I wish that, which isn't the case with biometrics. Say I'm a journalist who gets stopped at the border of a country and am asked to open up my computer. If I want to, I can refuse - and face the consequences but still, i can make that choice. With biometrics all they'd have to do is force my finger onto the scanner, or pu…

That's not a downside. Why should you be allowed to smuggle contraband into the country?

Re: Windows Hello – Biometric authentication to Windows 10 devices

#80
post #17

Convenient, for sure. However, I always have the choice of not giving up my passwords, under (even painful) threat. Also, someone cannot get my passwords if I am dead. Ever. Unfortunately, with biometrics, it is quite easy to force me to put my face/finger/iris in front of the machine and unlock it. Even if I am (freshly) dead. Not that cool, really.

>Also, someone cannot get my passwords if I am dead. Ever

99.9999% of the time this comes up in real life, it's an inconvenience.

Post reply on HN