You only get one set of fingerprints. If you use this as a master key, and someone else gets a hold of your fingerprints, you're vulnerable for the rest of your life. Not very secure.
Fake fingerprints can imitate real ones in biometric systems
11–20 of 44 posts
Re: Fake fingerprints can imitate real ones in biometric systems
#12You only get one set of fingerprints. If you use this as a master key, and someone else gets a hold of your fingerprints, you're vulnerable for the rest of your life. Not very secure.
Yes. We should think about our fingerprints as a userid, not as a password.
For root's sake, are you really actually thinking it through when you say stuff like this? In one breath your argument is "well biometrics aren't changeable so not like passwords" then you suggest it is equivalent to user IDs which by definition are all changeable, since they are essentially aesthetic symbolic pointers towards primary keys and bundles of identity. How easily or not any given entity makes it to change pointers in their own sphere varies based on subjective goals and tradeoffs, but there is nothing fundamental about it.
Re: Fake fingerprints can imitate real ones in biometric systems
#13I used to have stacks of these yellow sticky notes with my password printed on it. I ensured, that whereever I went, I would stick one of them to anything I touched, so I'd have it ready just in case. Thanks to fingerprint biometrics I can do this now just as well without even having to buy sticky notes.
Indeed, sticky notes with a password printed on them stuck around where they'd be needed is exactly what my very intelligent grandmother, doctor, and likely tens if not hundreds of millions of other people do worldwide. Often to comply with "good password policies" passed down from on high by thoughtless "security" technical people with zero appreciation or empathy for the actual humans they exist to serve and thus with minimal understanding of what "good security" actually means. Said sticky notes are quite trivial for any random passerby who possesses mildly functioning Mark 1 Eyeball(s) (only a single one is required!) to note. Turns out it's even easier then pulling a fingerprint or face/retina scan and turning it into something workable that can beat a good PAD and then stealing the device it's used with. Who'd have thought?
Oh wait, maybe you were trying to be sarcastic there and make some point? I think you might in fact have made a point, but perhaps not quite the one you intended.
Re: Fake fingerprints can imitate real ones in biometric systems
#14Earlier quoted context omitted.
Yes. We should think about our fingerprints as a userid, not as a password.
No, we shouldn't because that is entirely wrong. "corpMaverick" is a user ID. Your real name could be a form of user ID. "Something you are" is not a user ID. For root's sake, are you really actually thinking it through when you say stuff like this? In one breath your argument is "well biometrics aren't changeable so not like passwords" then you suggest it is equivalent to user IDs which by definition are all changea…
Re: Fake fingerprints can imitate real ones in biometric systems
#15Earlier quoted context omitted.
Yes. We should think about our fingerprints as a userid, not as a password.
No, we shouldn't because that is entirely wrong. "corpMaverick" is a user ID. Your real name could be a form of user ID. "Something you are" is not a user ID. For root's sake, are you really actually thinking it through when you say stuff like this? In one breath your argument is "well biometrics aren't changeable so not like passwords" then you suggest it is equivalent to user IDs which by definition are all changea…
Citation needed? A fingerprint can absolutely be used to generate a hash that functions as a pointer to primary keys.
Re: Fake fingerprints can imitate real ones in biometric systems
#16Earlier quoted context omitted.
No, we shouldn't because that is entirely wrong. "corpMaverick" is a user ID. Your real name could be a form of user ID. "Something you are" is not a user ID. For root's sake, are you really actually thinking it through when you say stuff like this? In one breath your argument is "well biometrics aren't changeable so not like passwords" then you suggest it is equivalent to user IDs which by definition are all changea…
> user IDs which by definition are all changeable, since they are essentially aesthetic symbolic pointers towards primary keys and bundles of identity Citation needed? A fingerprint can absolutely be used to generate a hash that functions as a pointer to primary keys.
Because all of those apply to user IDs.
Re: Fake fingerprints can imitate real ones in biometric systems
#17Earlier quoted context omitted.
No, we shouldn't because that is entirely wrong. "corpMaverick" is a user ID. Your real name could be a form of user ID. "Something you are" is not a user ID. For root's sake, are you really actually thinking it through when you say stuff like this? In one breath your argument is "well biometrics aren't changeable so not like passwords" then you suggest it is equivalent to user IDs which by definition are all changea…
wow dude i duno if the comments have been edited, but that's wrong. biometrics are much more like usernames than passwords. its a common sentiment among those educated in security
Re: Fake fingerprints can imitate real ones in biometric systems
#18Earlier quoted context omitted.
wow dude i duno if the comments have been edited, but that's wrong. biometrics are much more like usernames than passwords. its a common sentiment among those educated in security
It's a common sentiment amongst those who think they're educated about security. Just like "rotate passwords at rapid intervals and you must satisfy this baroque complex set of requirements for them too" is common sentiment. Unfortunately.
so if you're merely saying (as i think you are) that biometrics make poor usernames, much as they make poor passwords, your argument is quite trivial/tangential to this thread and really doesn't address the point op is making and doesn't contribute to the thread in any meaningful way (unless you wanted to expound specifically on why its so important for usernames to be, mutable?)
and if, instead, you're saying, as you implied to me, that biometrics make better passwords than usernames, i'll reiterate: that's wrong.
Re: Fake fingerprints can imitate real ones in biometric systems
#19Earlier quoted context omitted.
I would say biometrics is “usually” used in phones where it’s used completely on its own to unlock them. You might still need a PIN to install an OS update, but that won’t keep someone from going through all of your photos and emails.
> I would say biometrics is “usually” used in phones where it’s used completely on its own to unlock them. So you'd say that "there is an actual master password and the biometric authentication is being combined with a physical token as a shortcut/proxy" then? Because that's what it is. > but that won’t keep someone from going through all of your photos and emails. Neither will a PIN in a targeted physical attack. Th…
It's like keeping a safe unlocked while keeping the safes bios protected. It's the content that matters not the OS.
Re: Fake fingerprints can imitate real ones in biometric systems
#20Earlier quoted context omitted.
It's a common sentiment amongst those who think they're educated about security. Just like "rotate passwords at rapid intervals and you must satisfy this baroque complex set of requirements for them too" is common sentiment. Unfortunately.
i think we agree more than it might seem, but i can't tell. sure those types of requirements are often absurd and result of ignorance. but back to the point, i don't understand what your argument is about user IDs. remember the context of the comment you criticized is that there are vulnerabilities in biometric security. those vulnerabilities apply when the biometric data is used as a password; it does not apply when…
and then about usernames: maybe you're just saying, hey i can't just swipe my finger at gmail.com because which gmail account am i logging into? do i need 1 finger for each account (business, personal, etc)? lol that's kind of valid point too but nobody is proposing that the biometric identifier is the only part of the username anymore than your browser fingerprint is (which google does indeed utilize; sign in from somewhere else and you'll get 2FA vs on your own device, etc etc). think of your biometric data more like your phone number in 2fa. its yours and can help to verify your identify but its not secret and your authenticator should be secret