Live data from Hacker News

Fake fingerprints can imitate real ones in biometric systems

theguardian.com

21–30 of 44 posts

Re: Fake fingerprints can imitate real ones in biometric systems

#22
post #16

Earlier quoted context omitted.

> user IDs which by definition are all changeable, since they are essentially aesthetic symbolic pointers towards primary keys and bundles of identity Citation needed? A fingerprint can absolutely be used to generate a hash that functions as a pointer to primary keys.

Are you seriously arguing a fingerprint is an aesthetic symbolic pointer in the way a name is? That you are going to just refer to other people (whether IRL or online) by "fingerprint"? That people choose their fingerprints based on what they think will be a good one? That there can just be a simple process to arbitrarily change their fingerprint if they later decide they'd prefer another one? Because all of those ap…

Not trolling, but pouring more oil on the fire...

TLDR yes, biometrics are the closest thing to a user ID

> Are you seriously arguing a fingerprint is an aesthetic symbolic pointer in the way a name is? Absolutely. A given name is non-unique, and not chosen by you. Yet everyone refers you by it, if only by convention.

> That you are going to just refer to other people (whether IRL or online) by "fingerprint"? No but computers might as well do, much as you identify someone by their face. You might refer to someone by their public key fingerprint too (also similarly non-collision resistant)

> That people choose their fingerprints based on what they think will be a good one? People rarely choose their names, nicknames, or usernames. Why is choice an issue here?

> That there can just be a simple process to arbitrarily change their fingerprint if they later decide they'd prefer another one? People find it difficult to arbitrarily change their face, most are reluctant to change their given names - and indeed there's significant pressure from 'the system' to make it difficult for you, and also what about the many who find it annoying when their preferred username is unavailable, etc. I can't see what your point is here?

> Because all of those apply to user IDs. A user id, isn't a primary key in the real world - only when it comes to a particular computer system.

Finally your fingerprints do change over time, though not necessarily in a manner which will confuse current matching techniques

Re: Fake fingerprints can imitate real ones in biometric systems

#23
post #12

Earlier quoted context omitted.

No, we shouldn't because that is entirely wrong. "corpMaverick" is a user ID. Your real name could be a form of user ID. "Something you are" is not a user ID. For root's sake, are you really actually thinking it through when you say stuff like this? In one breath your argument is "well biometrics aren't changeable so not like passwords" then you suggest it is equivalent to user IDs which by definition are all changea…

> user IDs which by definition are all changeable, since they are essentially aesthetic symbolic pointers towards primary keys and bundles of identity Citation needed? A fingerprint can absolutely be used to generate a hash that functions as a pointer to primary keys.

A fingerprint cannot be used as a hash to encrypt keys. All you can do is store some data and compare the fingerprint to see if there are enough matches. That is why secure fingerprint systems always involve some ‘secure’ hardware that stores and compares the fingerprint to the stored data and then releases some key.

Systems that try to do this in software are always trivially circumvented because you can just change the software to allow ‘not enough matches’ instead of ‘enough matches’. The key is necessarily in the device and software can’t protect it.

Re: Fake fingerprints can imitate real ones in biometric systems

#24
post #18
post #17

Earlier quoted context omitted.

It's a common sentiment amongst those who think they're educated about security. Just like "rotate passwords at rapid intervals and you must satisfy this baroque complex set of requirements for them too" is common sentiment. Unfortunately.

i think we agree more than it might seem, but i can't tell. sure those types of requirements are often absurd and result of ignorance. but back to the point, i don't understand what your argument is about user IDs. remember the context of the comment you criticized is that there are vulnerabilities in biometric security. those vulnerabilities apply when the biometric data is used as a password; it does not apply when…

>i don't understand what your argument is about user IDs

Names/User IDs are not equivalent to biometrics. Nor passwords. Nor tokens. They are symbols that exist to enhance human UX. That's it.

>remember the context of the comment you criticized is that there are vulnerabilities in biometric security

Yes, just like in every single form of authentication. Which is utterly irrelevant.

>so if you're merely saying (as i think you are) that biometrics make poor usernames, much as they make poor passwords

>that biometrics make better passwords than usernames, i'll reiterate: that's wrong.

These are utterly non-sensical statements. Biometrics are not user names (a public symbol) nor are they passwords ("something you know"), "poor" has nothing to do with it, they are one of the other two classes of unique authentication factors. They have their own strengths and weaknesses, and yield different practical results when combined with one (or both) of the other two in a multi-factor authentication system. And a biometric/token MF system can absolutely be superior in security for many common threat scenarios and use cases compared to passwords. Achieving good security requires intelligent deployment of all 3.

Re: Fake fingerprints can imitate real ones in biometric systems

#25
post #22
post #16

Earlier quoted context omitted.

Are you seriously arguing a fingerprint is an aesthetic symbolic pointer in the way a name is? That you are going to just refer to other people (whether IRL or online) by "fingerprint"? That people choose their fingerprints based on what they think will be a good one? That there can just be a simple process to arbitrarily change their fingerprint if they later decide they'd prefer another one? Because all of those ap…

Not trolling, but pouring more oil on the fire... TLDR yes, biometrics are the closest thing to a user ID > Are you seriously arguing a fingerprint is an aesthetic symbolic pointer in the way a name is? Absolutely. A given name is non-unique, and not chosen by you. Yet everyone refers you by it, if only by convention. > That you are going to just refer to other people (whether IRL or online) by "fingerprint"? No but…

[flagged]

Re: Fake fingerprints can imitate real ones in biometric systems

#26
post #25
post #22

Earlier quoted context omitted.

Not trolling, but pouring more oil on the fire... TLDR yes, biometrics are the closest thing to a user ID > Are you seriously arguing a fingerprint is an aesthetic symbolic pointer in the way a name is? Absolutely. A given name is non-unique, and not chosen by you. Yet everyone refers you by it, if only by convention. > That you are going to just refer to other people (whether IRL or online) by "fingerprint"? No but…

[flagged]

pedantic.

Re: Fake fingerprints can imitate real ones in biometric systems

#27
post #10

Earlier quoted context omitted.

I would say biometrics is “usually” used in phones where it’s used completely on its own to unlock them. You might still need a PIN to install an OS update, but that won’t keep someone from going through all of your photos and emails.

> I would say biometrics is “usually” used in phones where it’s used completely on its own to unlock them. So you'd say that "there is an actual master password and the biometric authentication is being combined with a physical token as a shortcut/proxy" then? Because that's what it is. > but that won’t keep someone from going through all of your photos and emails. Neither will a PIN in a targeted physical attack. Th…

>So you'd say that "there is an actual master password and the biometric authentication is being combined with a physical token as a shortcut/proxy" then? Because that's what it is.

I'd say that the fingerprint is the single factor to unlock your phone and access all of your data. Sp I'm not sure I understand your point about a physical token. That the phone is a physical token that you need in order to unlock the phone?

I guess that's true, but it's a weird way of describing it versus just calling the fingerprint a single factor used to unlock the physical device.

That feels like saying "My house has two factor authentication, one factor is they key and the other is the house." The house isn't a second factor, it's the thing you're getting access to.

Re: Fake fingerprints can imitate real ones in biometric systems

#28
post #24
post #18

Earlier quoted context omitted.

i think we agree more than it might seem, but i can't tell. sure those types of requirements are often absurd and result of ignorance. but back to the point, i don't understand what your argument is about user IDs. remember the context of the comment you criticized is that there are vulnerabilities in biometric security. those vulnerabilities apply when the biometric data is used as a password; it does not apply when…

>i don't understand what your argument is about user IDs Names/User IDs are not equivalent to biometrics. Nor passwords. Nor tokens. They are symbols that exist to enhance human UX. That's it. > remember the context of the comment you criticized is that there are vulnerabilities in biometric security Yes, just like in every single form of authentication . Which is utterly irrelevant. > so if you're merely saying (as…

defined as such! good grief. anyone can code up a system that uses a fingerprint as a username -- you can't reply "thats not a username!" yes it is, because its defined as such! similarly, lots of applications use the fingerprint as both username and password, again defying your platonic ideal. you can go ahead and define the proper "taxonomy of authentication factors" but the whole irony is you think everyone has this biometric username/password false dichotomy when you fail to recognize that this dichotomy exists in the wild and often in really bad ways ;P

Re: Fake fingerprints can imitate real ones in biometric systems

#29
post #13

I used to have stacks of these yellow sticky notes with my password printed on it. I ensured, that whereever I went, I would stick one of them to anything I touched, so I'd have it ready just in case. Thanks to fingerprint biometrics I can do this now just as well without even having to buy sticky notes.

> I ensured, that whereever I went, I would stick one of them to anything I touched, so I'd have it ready just in case. Indeed, sticky notes with a password printed on them stuck around where they'd be needed is exactly what my very intelligent grandmother, doctor, and likely tens if not hundreds of millions of other people do worldwide. Often to comply with "good password policies" passed down from on high by though…

Your grandmother, doctor, etc are not aware they can use a password manager with a master password such as "dandy-pencil-colonist-precise-populate-stardom" which would be more difficult to crack than finding and copying a fingerprint on your device. Its only a matter of time until one of these is cracked, and with touchID and faceID they're going to get cracked before said password is cracked.

PS: Just a piece of advice, your tone throughout this thread isn't going to convince anyone. On the contrary.

Re: Fake fingerprints can imitate real ones in biometric systems

#30
post #28
post #24

Earlier quoted context omitted.

>i don't understand what your argument is about user IDs Names/User IDs are not equivalent to biometrics. Nor passwords. Nor tokens. They are symbols that exist to enhance human UX. That's it. > remember the context of the comment you criticized is that there are vulnerabilities in biometric security Yes, just like in every single form of authentication . Which is utterly irrelevant. > so if you're merely saying (as…

defined as such! good grief. anyone can code up a system that uses a fingerprint as a username -- you can't reply "thats not a username!" yes it is, because its defined as such! similarly, lots of applications use the fingerprint as both username and password, again defying your platonic ideal. you can go ahead and define the proper "taxonomy of authentication factors" but the whole irony is you think everyone has th…

to be clear i think we can basically agree on the fundamentals: the FFIEC guidelines where two or more of the three basic auth factors are used in combination (biometrics, usernames, and passwords are independent) and our argument is really about the best way to help everyone else who can only see 2 categories. this was fun.
Post reply on HN