Live data from Hacker News

I recommend against using biometric identification

medium.freecodecamp.org

101–110 of 239 posts

Re: I recommend against using biometric identification

#101
post #95
post #50

Earlier quoted context omitted.

The "door lock" analogy ignores the biggest flaw with fingerprints: they're forever. If your door lock is compromised, you can change the key. If someone steals your password, you can change the password. If someone steals your fingerprint, you can never change your fingerprint (same with your face). The other stuff is dead-on: its a "good enough" security measure for phones. But as a security practitioner, the bigge…

> If someone steals your fingerprint, you can never change your fingerprint (same with your face). Because you expect repeated attacks from the person who stole your fingerprints? Who are you, James Bond?

It doesn't have to be a repeated attack from the same attacker.

Imagine your fingerprint data is leaked to hundreds of hackers.

Re: I recommend against using biometric identification

#102
post #95

Earlier quoted context omitted.

> If someone steals your fingerprint, you can never change your fingerprint (same with your face). Because you expect repeated attacks from the person who stole your fingerprints? Who are you, James Bond?

It doesn't have to be a repeated attack from the same attacker. Imagine your fingerprint data is leaked to hundreds of hackers.

And many of those hackers (or even one of them) care enough to (a) steal your phone, (b) fake your fingerprints with a cast or whatever?

Yeah, I'll risk it...

Re: I recommend against using biometric identification

#103
post #84

Never? If Jason Bourne is after you that's probably true. If you're worried about border security, that's maybe true. But for most people, the lock on their phone isn't protecting them from the government, it's protecting them from nosy relatives, a pick pocket, or the guy that finds the phone you left at the bar, or their 4 year old. None of these 'attackers' will ever be sophisticated enough to defeat the biometric…

"sophisticated" here could be as simple as buying a mass-produced 3d filter sized for the dual lens on the iPhone, installing a companion computer program, running it, uploading a video, and then pointing the phone at the screen. If I were your nosy relative, that certainly wouldn't stop me. As with any security break, the first research prototypes may sound sophisticated, but they might not be that far off from prac…

I mean, cool, but I'm more worried about someone shoulder surfing with a camera or in person when I type my passcode in

Re: I recommend against using biometric identification

#104
post #84

Never? If Jason Bourne is after you that's probably true. If you're worried about border security, that's maybe true. But for most people, the lock on their phone isn't protecting them from the government, it's protecting them from nosy relatives, a pick pocket, or the guy that finds the phone you left at the bar, or their 4 year old. None of these 'attackers' will ever be sophisticated enough to defeat the biometric…

I agree that convenience is the real test of each of these technologies (along with "good enough" security) that lets the majority of people to have a good experience.

The biggest concerns for the iPhone (or others) then are things like viewing angle, sunlight, etc...

Also, if I were an identical twin (only 0.3% of the population) I would be a bit unhappy that my brother/sister could post anything they wanted on my IG/FB/SN.

Re: I recommend against using biometric identification

#106

The author doesn't seem to understand the difference between an iris and a retina, but he expects us to heed his advice on the topic of biometric identification.

Indeed.

For further clarity: The retina is the thin layer of cells at the back of your eye that pick up light. The iris is the colorful ring on the front of your eye.

A retina scan is thing most people wouldn't experience outside of an eye doctor's office. It requires really close proximity with the scanner, and it's very clear that's it's happening.

Phones, including the Galaxy 8 that the author of the article mentions, use iris scanning.

Re: I recommend against using biometric identification

#107

> And to be clear, a court in the US cannot force you to give up your passcode. That passcode exists in your head, and yours alone. It is your property, and won’t be used to incriminate you or strong-arm access to your data unless you voluntarily give it up. While technically true this is false in practice. While they can't force you to provide your passcode they can force you to unlock your phone. Francis Rawls has…

That man may still be in prison, but that drive is still encrypted.

If you are unwilling to give something you know to someone, no amount of force can take it from you. Had that drive been encrypted using facial biometrics, they could have just knocked him out, glued his eyes open, and taken what they wanted.

What works, and what has been deemed legal, as you probably already know, are not mutually exclusive.

Re: I recommend against using biometric identification

#108

Earlier quoted context omitted.

It doesn't have to be a repeated attack from the same attacker. Imagine your fingerprint data is leaked to hundreds of hackers.

And many of those hackers (or even one of them) care enough to (a) steal your phone, (b) fake your fingerprints with a cast or whatever? Yeah, I'll risk it...

The OPM hack resulted in millions of people's fingerprints and names being hacked, and now are floating out on the internet for anyone to look up.

Individuals who had their fingerprints stolen in that hack can now never use fingerprint readers with any reasonable confidence, since now all a hacker has to do is search that person's name and pull their fingerprint from one of aforementioned databases.

> fake your fingerprints with a cast

Fingerprint scanners like those on phones have been shown to be able to be fooled by using $10 worth of office supplies and some play-dough. It's not like we're talking mastermind levels of intelligence to do this stuff.

Of course, all of this completely ignores the fact that your phone likely already has several copies of your fingerprint already on it since you touched it, so it's not like someone hacking your fingerprints is even necessary. That's an entirely different reason of why fingerprint security is abysmal, though.

Re: I recommend against using biometric identification

#110
post #35

Earlier quoted context omitted.

Biometrics is closer to a username.

Why? I am not terribly upset if someone has my username, but I would be very concerned if they had reproducible biometrics of mine (fingerprints, facial, etc).

Usernames are fixed values and are generally public. Biometrics are also fixed values and are generally only slightly less public. They're both identifiers.

Passwords can be changed and are secrets. They're authenticators.

The difference between them is exactly the difference between identifiers and authenticators. Misunderstanding this difference causes tons of issues, in a wide variety of situations. The most notable one recently is probably Social Security Numbers being used as both, which leads to identity theft.

Post reply on HN