Live data from Hacker News

Windows Hello – Biometric authentication to Windows 10 devices

blogs.windows.com

91–95 of 95 posts

Re: Windows Hello – Biometric authentication to Windows 10 devices

#91
post #60

Earlier quoted context omitted.

"A biometric is both a 'username' and a 'password' " This is true, but usually people don't go around showing their passwords to any camera they walk by or surface they touch. That is why people say that it is more appropriate for biometrics to identify someone than it is to provide their authentication. "our password is just as at risk as your fingerprint." Also true, but what do you do when these breaches happen if…

The perfect use case for biometrics is identifying people who don't want to be identified specifically because they can't change their "password". For example, prisoners, fugitives, enemy combatants, people trying to use software they are not licensed to use or listen to music they have not properly licensed. In the future the bottom 64 bits of your ipv6 address will be a unique biometric identifier that all licensed…

A government grade application does just this - look at the NIST competitions, they focus on verification scenarios (one to one matching) which span over large datasets.

Appending a biometric id to your ipv6 address seems a bit redundant and unnecessary - you don't need to authenticate to the internet...why not encode more hardware or location information?

Re: Windows Hello – Biometric authentication to Windows 10 devices

#92

I hope that PINs and such always remain alternatives to biometrics. My usual concern -- if the locally stored biometric data is compromised (malware, poor crypto, etc.), I need a way to "change my password", which isn't really possible for something like facial recognition. Likewise, I'm curious if there's a fallback authentication method for people who lose a finger, get their faces deformed, etc. That said, the who…

On the same note, while I think the technology is cool, I think there should (and will) always be an alternative for the traditional PIN/password. One prime reason why you'd want a password-only entry is because LEOs (law enforcement officers) can force you to swipe your thumb, look into an iris scanner, look at a camera for face unlock, etc. but they cannot force you to type in your password.

Re: Windows Hello – Biometric authentication to Windows 10 devices

#93
post #83

Earlier quoted context omitted.

Just an FYI, but that was the least useful bit of the Snowden leaks and is more speculation and insinuation than anything. It's literally based on the reading of a PowerPoint slide. AFAIK, there's been no actual evidence of "direct access", whatever that's supposed to mean. An automatic subpoena-serving could easily be written down as " direct access " on a ppt to management. It's probably a good idea to not store cr…

We'd be ignoring a lot of the Snowden revelations if we discounted the parts only 'based on the reading of a PowerPoint slide', wouldn't we? As for why you trust Google less than Microsoft, how comes? (genuinely interested in your reasoning)

Eh, some parts are clearer than others. A ppt that says "direct access" and everyone coming up with their own interpretation of what "direct" means is silly. Especially when high level engineers have directly contradicted those statements.

I trust Google less than MS because MS seems less likely to go use my data or even get their act together. They seem more legally scared and bureaucratic due to their past legal problems. Google seems intent on making us give up privacy (didn't Schmidt say something to that effect)? My interaction with Google services includes them constantly and repeatedly asking me to turn on history or other tracking systems. Even when I constantly decline, they keep returning. Google's main goal is to datamine to sell advertising, so that's sort of fundamentally in conflict with my personal values. Android permissions is another shining example (and now, at version 5, what exactly is the excuse?).

If Bing ever took off and replaced MS's real revenue, then I suppose I might feel the same way about MS. But that whole division, the MSN/Live/Bing/whatever, seems mired with idiotic managers that can't get anything straight (hence them losing to Skype, not turning MSN messenger into a real social network, repeatedly rebranding and offering random services then discontinuing them, etc.). They did have some great engineering though. But even if they were intent on malice, I'm not sure they'd be capable of pulling it off due to the legal/management part getting in the way for good or bad.

Overall, I give MS money, so I'm their customer, for the most part. Not true for Google, at all.

Re: Windows Hello – Biometric authentication to Windows 10 devices

#94
post #79

Earlier quoted context omitted.

That's not a downside. Why should you be allowed to smuggle contraband into the country?

Nanna isn't suggesting smuggling contraband. As a journalist, they have a responsibility to maintain the privacy of their sources. They shouldn't be letting customs officials go through their emails and identifying people they have contact with, or photos or whatever. No matter what is on the device, border security shouldn't be able to access it without probable cause for a search, and knowing what they are looking…

If the legitimate border guards of a country are unable to inspect something to their satisfaction, they are well within their rights to force you to leave it outside their country, or to keep you yourself out.

Sometimes they will make decisions that are bad either for the people of the country or the greater global community, but smuggling is not the right way to protest.

Re: Windows Hello – Biometric authentication to Windows 10 devices

#95
post #85
post #79

Earlier quoted context omitted.

That's not a downside. Why should you be allowed to smuggle contraband into the country?

I had the linked image in mind when I wrote that, of a journalist whose laptop was shot by Israeli border police whilst she was being interrogated. http://lilyasussman.com/2009/11/30/im-sorry-but-we-blew-up-y... Actually the reference doesn't totally work in hindsight because she was never asked for her password, but it seems as though it was encrypted and hence they just destroyed her laptop instead of asking her fo…

If you are unwilling to allow border guards to inspect something you are attempting to bring into their country, then you should be prepared for them to tell you to leave it outside at best or punish you for attempted smuggling at worst. I am skeptical of the story you linked as it's entirely from the perspective of the smuggler, but I don't see any reason to believe anything wrong happened there.
Post reply on HN