Live data from Hacker News

Windows Hello – Biometric authentication to Windows 10 devices

blogs.windows.com

81–90 of 95 posts

Re: Windows Hello – Biometric authentication to Windows 10 devices

#81

I hope that PINs and such always remain alternatives to biometrics. My usual concern -- if the locally stored biometric data is compromised (malware, poor crypto, etc.), I need a way to "change my password", which isn't really possible for something like facial recognition. Likewise, I'm curious if there's a fallback authentication method for people who lose a finger, get their faces deformed, etc. That said, the who…

You don't need to only worry about your device being compromised, your biometric credentials are being leaked by your mere existence . Before long, I can imagine someone being able to build facial models capable of fooling recognition systems using only a few source images. Your finger prints are everywhere . Iris would be a bit harder, for now, but potentially possible with an image of high enough resolution.

They have long range iris identification. It stands to reason that soon that will also be enough to gather a replica without the target knowing.

https://www.cylab.cmu.edu/research/projects/2012/long-range-...

In fact my research lab recently received a donation of high power telescopes after being used for testing extremely long range iris identification technology. I'm not sure if the project was scrapped or if they are planning on continuing development.

Re: Windows Hello – Biometric authentication to Windows 10 devices

#82
post #79
post #71

One thing I like about passwords is that they give me the choice to not unlock something, should I wish that, which isn't the case with biometrics. Say I'm a journalist who gets stopped at the border of a country and am asked to open up my computer. If I want to, I can refuse - and face the consequences but still, i can make that choice. With biometrics all they'd have to do is force my finger onto the scanner, or pu…

That's not a downside. Why should you be allowed to smuggle contraband into the country?

Nanna isn't suggesting smuggling contraband. As a journalist, they have a responsibility to maintain the privacy of their sources. They shouldn't be letting customs officials go through their emails and identifying people they have contact with, or photos or whatever.

No matter what is on the device, border security shouldn't be able to access it without probable cause for a search, and knowing what they are looking for.

Re: Windows Hello – Biometric authentication to Windows 10 devices

#83
post #74

Earlier quoted context omitted.

Just the usual post-Snowden concerns about MS... http://www.theguardian.com/world/2013/jul/11/microsoft-nsa-c...

Just an FYI, but that was the least useful bit of the Snowden leaks and is more speculation and insinuation than anything. It's literally based on the reading of a PowerPoint slide. AFAIK, there's been no actual evidence of "direct access", whatever that's supposed to mean. An automatic subpoena-serving could easily be written down as " direct access " on a ppt to management. It's probably a good idea to not store cr…

We'd be ignoring a lot of the Snowden revelations if we discounted the parts only 'based on the reading of a PowerPoint slide', wouldn't we?

As for why you trust Google less than Microsoft, how comes? (genuinely interested in your reasoning)

Re: Windows Hello – Biometric authentication to Windows 10 devices

#84

Earlier quoted context omitted.

> Yea I see the point, but there will always need to be an asterisk after the statement, "a biometric is a username, not a password", because it's only valid in the sense there are concerns about the security of the biometric template. Down the line maybe we'll figure out this spoofing/liveness test thing, but we won't find out while many instantly write off the merit of the system to begin with. Any sensor accurate…

>The only way to avoid this requires an active activity, at which case you've just duplicated the password [e.g. the act of typing is identical to the act of sufficient action to make it virtually impossible to duplicate] which has better known security characteristics. Only way is active activity? Or just the only way you can think of? >A single breach and you cannot rely on biometric data for life is the reason thi…

>You're assuming all recognition algorithms of the same biometric produce the same raw template. That if I get one I can gain access on another.

Well, is that an unreasonable assumption? With passwords knowing what one person's password used to be or even knowing one hash of their current password tells you nothing about a different hash of their current password. With biometric data points presumably if they get accurate and detailed enough (which you already admit they would have to do to be a valid authentication mechanism) you can extrapolate. Faces are known quantities. Knowing how 999 points of your face are arranged does give you data about how other points on your face are likely to be arranged. We already have modelling software capable of this, so it doesn't seem unreasonable that such methods may be improved if facial recognition gains traction. At the very least it brings down the solution space to a much smaller size the more data points are used, which is the opposite of what happens when more data points (characters) are used in alpha-numeric passwords.

>It's often frustrating to discuss things with those who clearly know little about the topic and yet declare their opinion as fact.

I would agree. Especially opinions like how others "clearly know little about the topic".

But is it as frustrating as someone explaining their reasoning for their statement and then you ignoring that reasoning to discuss their closing statement as the entire argument?

Re: Windows Hello – Biometric authentication to Windows 10 devices

#85
post #79
post #71

One thing I like about passwords is that they give me the choice to not unlock something, should I wish that, which isn't the case with biometrics. Say I'm a journalist who gets stopped at the border of a country and am asked to open up my computer. If I want to, I can refuse - and face the consequences but still, i can make that choice. With biometrics all they'd have to do is force my finger onto the scanner, or pu…

That's not a downside. Why should you be allowed to smuggle contraband into the country?

I had the linked image in mind when I wrote that, of a journalist whose laptop was shot by Israeli border police whilst she was being interrogated.

http://lilyasussman.com/2009/11/30/im-sorry-but-we-blew-up-y...

Actually the reference doesn't totally work in hindsight because she was never asked for her password, but it seems as though it was encrypted and hence they just destroyed her laptop instead of asking her for the pw. If it had biometrics they might have just forced her to open it. So actually, the example might work after all.

Re: Windows Hello – Biometric authentication to Windows 10 devices

#86
post #84

Earlier quoted context omitted.

>The only way to avoid this requires an active activity, at which case you've just duplicated the password [e.g. the act of typing is identical to the act of sufficient action to make it virtually impossible to duplicate] which has better known security characteristics. Only way is active activity? Or just the only way you can think of? >A single breach and you cannot rely on biometric data for life is the reason thi…

>You're assuming all recognition algorithms of the same biometric produce the same raw template. That if I get one I can gain access on another. Well, is that an unreasonable assumption? With passwords knowing what one person's password used to be or even knowing one hash of their current password tells you nothing about a different hash of their current password. With biometric data points presumably if they get acc…

> Well, is that an unreasonable assumption? With passwords knowing what one person's password used to be or even knowing one hash of their current password tells you nothing about a different hash of their current password.

Yea it is, this is very different from a password, even though it's being used in a similar way. Lets take fingerprints as an example - algorithm A uses minutiae points, and algorithm B does a simple normalized cross correlation between the two images. While this is a toy example, you can see there is a clear difference in what is being stored or even hashed.

> At the very least it brings down the solution space to a much smaller size the more data points are used, which is the opposite of what happens when more data points (characters) are used in alpha-numeric passwords.

No, it doesn't. You'd have better luck using a facebook profile picture printed on an old inkjet than you would trying to use a specific template as the 'solution space' of what other templates may be.

> But is it as frustrating as someone explaining their reasoning for their statement and then you ignoring that reasoning to discuss their closing statement as the entire argument?

I admit that it wasn't the classiest way to respond, and i apologize for it (i'm not going to delete it though, i wrote it and i won't run from it), but the same arguments keep coming up over and over again, and it's very clear that the users making these statements not reading any previous replies so i wasn't going to waste my time going over all the points again and again.

Re: Windows Hello – Biometric authentication to Windows 10 devices

#87
post #60

As someone who actively researches biometric authentication, when I hear/read someone saying that biometrics are "usernames" and not "passwords", I automatically think they fundamentally misunderstand what a biometric is. A biometric is both a 'username' and a 'password' - for instance, when you access your computer/device/whatnot you type in your username and your password to identify to the system that you are requ…

"A biometric is both a 'username' and a 'password' " This is true, but usually people don't go around showing their passwords to any camera they walk by or surface they touch. That is why people say that it is more appropriate for biometrics to identify someone than it is to provide their authentication. "our password is just as at risk as your fingerprint." Also true, but what do you do when these breaches happen if…

The perfect use case for biometrics is identifying people who don't want to be identified specifically because they can't change their "password". For example, prisoners, fugitives, enemy combatants, people trying to use software they are not licensed to use or listen to music they have not properly licensed.

In the future the bottom 64 bits of your ipv6 address will be a unique biometric identifier that all licensed internet devices must collect and send with each and every packet.

Re: Windows Hello – Biometric authentication to Windows 10 devices

#88

Earlier quoted context omitted.

> Yea I see the point, but there will always need to be an asterisk after the statement, "a biometric is a username, not a password", because it's only valid in the sense there are concerns about the security of the biometric template. Down the line maybe we'll figure out this spoofing/liveness test thing, but we won't find out while many instantly write off the merit of the system to begin with. Any sensor accurate…

>The only way to avoid this requires an active activity, at which case you've just duplicated the password [e.g. the act of typing is identical to the act of sufficient action to make it virtually impossible to duplicate] which has better known security characteristics. Only way is active activity? Or just the only way you can think of? >A single breach and you cannot rely on biometric data for life is the reason thi…

> Only way is active activity? Or just the only way you can think of?

https://www.defcon.org/images/defcon-13/dc13-presentations/D...

http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.10....

> For eliminating type 2 attacks, where a previously intercepted biometric is replayed, Ratha et al. [9] proposed a challenge/response based system. A pseudo-random challenge is presented to the sensor by a secure transaction server. At that time, the sensor acquires the current biometric signal and computes the response corresponding to the challenge (for example, pixel values at locations indicated in the challenge). The acquired signal and the corresponding response are sent to the transaction server where the response is checked against the received signal for consistency. An inconsistency reveals the possibility of the resubmission attack.

Please provide evidence you have a better defense against replay attacks. Then we can go through all the other avenues of attack on biometrics...

> You're assuming all recognition algorithms of the same biometric produce the same raw template. That if I get one I can gain access on another.

The fact replay attacks are taken seriously in regards to biometrics and you arguing you cannot engage in such makes me seriously question your claims of authority on the subject matter.

> It's often frustrating to discuss things with those who clearly know little about the topic and yet declare their opinion as fact.

How many papers basically agreeing some kind of challenge is needed in addition to the biometric will you need before you change your mind?

Re: Windows Hello – Biometric authentication to Windows 10 devices

#89

Earlier quoted context omitted.

>The only way to avoid this requires an active activity, at which case you've just duplicated the password [e.g. the act of typing is identical to the act of sufficient action to make it virtually impossible to duplicate] which has better known security characteristics. Only way is active activity? Or just the only way you can think of? >A single breach and you cannot rely on biometric data for life is the reason thi…

> Only way is active activity? Or just the only way you can think of? https://www.defcon.org/images/defcon-13/dc13-presentations/D... http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.10.... > For eliminating type 2 attacks, where a previously intercepted biometric is replayed, Ratha et al. [9] proposed a challenge/response based system. A pseudo-random challenge is presented to the sensor by a secure transact…

> https://www.defcon.org/images/defcon-13/dc13-presentations/D....

Slide 44 has a long list of things other than active movement on the user end. Video liveness tests are effective, but there are more methods available than just activity, contrast to your previous statement.

> http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.10..... > Please provide evidence you have a better defense against replay attacks. Then we can go through all the other avenues of attack on biometrics...

When did i discredit replay attacks? It seems like you're setting up a straw man. You said the "only way to avoid this requires an active activity, at which case you've just duplicated the password". I refuted saying there's more than one, and you actually found a source that confirms that.

> The fact replay attacks are taken seriously in regards to biometrics and you arguing you cannot engage in such makes me seriously question your claims of authority on the subject matter.

I didn't claim you can't. The paper you linked (http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.10....) applies a relay attack to a known system.

  "we propose a system that can attack a minutia-based fingerprint matcher"
In this case, the attack algorithm is building an optimization to determine a viable template - using some prior information of what type of template is acceptable (how it's stored, the features being used to build it, etc.) In real life, this type of information is not readily available, and at best, an attacker is going to be just guessing.

> makes me seriously question your claims of authority on the subject matter.

I honestly don't care what you think, but questioning my credentials is your right.

> How many papers basically agreeing some kind of challenge is needed in addition to the biometric will you need before you change your mind?

When did i ever state that an additional challenge wasn't needed? You're setting up another straw man instead of actually backing up your claims.

Many of my posts mention biometric key-binding as a good alternative to a pure biometric system. In a large scale operation i would never suggest or imply that a pure biometric is good enough - you should really read the rest of the thread. However, what MS implemented here is probably good for the average user.

Re: Windows Hello – Biometric authentication to Windows 10 devices

#90
post #33

I hope that PINs and such always remain alternatives to biometrics. My usual concern -- if the locally stored biometric data is compromised (malware, poor crypto, etc.), I need a way to "change my password", which isn't really possible for something like facial recognition. Likewise, I'm curious if there's a fallback authentication method for people who lose a finger, get their faces deformed, etc. That said, the who…

Biometrics have more in common with usernames than passwords.

You can change usernames at will.

A lot harder with biometrics.

Post reply on HN