Live data from Hacker News

Project Abacus: Google's plan to kill the password via biometric tracking

engadget.com

11–20 of 59 posts

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#11
post #2

(disclosure: I am a Googler, but I have nothing to do with this project) Passwords are problematic, easy to lose, easy to steal, but an issue with biometric identify verification is that you can no longer maintain multiple personas. Using a password with 2FA, you can quite easily maintain two sets of those credentials, assuming that the authority doesn't demand proof of real name or such nonsense. If you trust the au…

>>> If you trust the authority, it's no big deal. And, I trust Google... today. Google yes/maybe. But when you talk to Google who else is involved? Which governments are granted access, with or without google's knowledge? How many 20-something analysts at three-lettered agencies have access? I would like to trust a large publicly-traded company, but the reality today is that they seem in little more control than the…

My trust in Google comes from me believing Google is capable of preventing undetected access, and limiting detected access to that which is legally obligated. I'm not going to try to convince you that this is the case, only state that it's what I believe.

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#12
post #10
post #6

There's still a lot that can be done to improve passwords without eliminating them. Perhaps the single biggest step is to encourage password managers that can auto-generate strong passwords. I seem to recall an article recently showing that the biggest difference between normal people and security professionals was the use of password managers.

Password managers could be included with the OS - like notepad. But deep integration with the OS would be bad.

It's not clear to me what you're suggesting - your two statements are, at least superficially, at odds with one another.

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#13
post #5

This sounds bad. We are already forced to use almost exact voice to give voice commands. Now we will be forced to walk the same, speak every so even if you are alone in the room and be sure we dont break our habits. For me this sounds bad. I will be waiting for Google to prove me I am mistaken.

If you combined this with multifactor authentication (e.g. fallback to a password for a 100% trust score), it could potentially match your change in biometrics against a diagnostics knowledge base and use any new data following to further train the diagnostics knowledge base. Of course, that would have to be opt-in with patient confidentiality as strongly defended as possible (there needs to be laws and regulations defending privacy with this model), but it would be an interesting source of data collection.

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#14
post #11

Earlier quoted context omitted.

>>> If you trust the authority, it's no big deal. And, I trust Google... today. Google yes/maybe. But when you talk to Google who else is involved? Which governments are granted access, with or without google's knowledge? How many 20-something analysts at three-lettered agencies have access? I would like to trust a large publicly-traded company, but the reality today is that they seem in little more control than the…

My trust in Google comes from me believing Google is capable of preventing undetected access, and limiting detected access to that which is legally obligated. I'm not going to try to convince you that this is the case, only state that it's what I believe.

Capable? Have you heard about prism? Google claims to have been in the dark, that data was siphoning off as it flowed between data centers. That is an admission that Google is not capable of protecting against such things. They claim to have not even contemplated the attack.

To quote the boss:

"Until this week’s reports, we had never heard of the broad type of order that Verizon received—an order that appears to have required them to hand over millions of users’ call records. We were very surprised to learn that such broad orders exist."

https://googleblog.blogspot.ca/2013/06/what.html

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#15
post #2

(disclosure: I am a Googler, but I have nothing to do with this project) Passwords are problematic, easy to lose, easy to steal, but an issue with biometric identify verification is that you can no longer maintain multiple personas. Using a password with 2FA, you can quite easily maintain two sets of those credentials, assuming that the authority doesn't demand proof of real name or such nonsense. If you trust the au…

It could be even creepier if the biometric data could be sold to third parties, or if Google were to offer an identification service for third parties.

Medical researchers?

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#16
post #12
post #10

Earlier quoted context omitted.

Password managers could be included with the OS - like notepad. But deep integration with the OS would be bad.

It's not clear to me what you're suggesting - your two statements are, at least superficially, at odds with one another.

The difference I'm guessing is deep integration would be like IE and Windows in the pre lawsuit days.

Basically, OSes should come with a password manager app by default, but users can download their own to replace it which would replace the default one. Much like how you can set your default browser on desktop OSes.

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#17
post #11

Earlier quoted context omitted.

My trust in Google comes from me believing Google is capable of preventing undetected access, and limiting detected access to that which is legally obligated. I'm not going to try to convince you that this is the case, only state that it's what I believe.

Capable? Have you heard about prism? Google claims to have been in the dark, that data was siphoning off as it flowed between data centers. That is an admission that Google is not capable of protecting against such things. They claim to have not even contemplated the attack. To quote the boss: "Until this week’s reports, we had never heard of the broad type of order that Verizon received—an order that appears to have…

Yes, and as a result traffic is now encrypted between data centers.

And I'm not sure what your quote adds to the point.

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#18
Has anyone published precise technical details about what this actually does? The writeup here makes it sound like it's being pitched as a replacement for network logins or two-factor authentication, which would be an unmitigated disaster – can't rekey, client compromises are irrecoverable, etc.

There's certainly a tradition of academics without security experience pitching that concept but it'd be surprising for it to get very far at Google given how many qualified security people work there and the actual YouTube video makes it sound like this is just being pitched as an alternative phone unlock mechanism.

I don't see anything in there suggesting that it's being pitched as a replacement for either network passwords or two-factor authentication. Has anyone seen another source for anything that leaves the device or is this just a reporter jumping to conclusions?

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#19
post #12

Earlier quoted context omitted.

It's not clear to me what you're suggesting - your two statements are, at least superficially, at odds with one another.

The difference I'm guessing is deep integration would be like IE and Windows in the pre lawsuit days. Basically, OSes should come with a password manager app by default, but users can download their own to replace it which would replace the default one. Much like how you can set your default browser on desktop OSes.

Or the Win10 case where it sends private WiFi passwords to MS servers and shares it with your outlook.com-friends.
Post reply on HN