Fake fingerprints can imitate real ones in biometric systems
21–30 of 44 posts
Re: Fake fingerprints can imitate real ones in biometric systems
#22Earlier quoted context omitted.
> user IDs which by definition are all changeable, since they are essentially aesthetic symbolic pointers towards primary keys and bundles of identity Citation needed? A fingerprint can absolutely be used to generate a hash that functions as a pointer to primary keys.
Are you seriously arguing a fingerprint is an aesthetic symbolic pointer in the way a name is? That you are going to just refer to other people (whether IRL or online) by "fingerprint"? That people choose their fingerprints based on what they think will be a good one? That there can just be a simple process to arbitrarily change their fingerprint if they later decide they'd prefer another one? Because all of those ap…
TLDR yes, biometrics are the closest thing to a user ID
> Are you seriously arguing a fingerprint is an aesthetic symbolic pointer in the way a name is? Absolutely. A given name is non-unique, and not chosen by you. Yet everyone refers you by it, if only by convention.
> That you are going to just refer to other people (whether IRL or online) by "fingerprint"? No but computers might as well do, much as you identify someone by their face. You might refer to someone by their public key fingerprint too (also similarly non-collision resistant)
> That people choose their fingerprints based on what they think will be a good one? People rarely choose their names, nicknames, or usernames. Why is choice an issue here?
> That there can just be a simple process to arbitrarily change their fingerprint if they later decide they'd prefer another one? People find it difficult to arbitrarily change their face, most are reluctant to change their given names - and indeed there's significant pressure from 'the system' to make it difficult for you, and also what about the many who find it annoying when their preferred username is unavailable, etc. I can't see what your point is here?
> Because all of those apply to user IDs. A user id, isn't a primary key in the real world - only when it comes to a particular computer system.
Finally your fingerprints do change over time, though not necessarily in a manner which will confuse current matching techniques
Re: Fake fingerprints can imitate real ones in biometric systems
#23Earlier quoted context omitted.
No, we shouldn't because that is entirely wrong. "corpMaverick" is a user ID. Your real name could be a form of user ID. "Something you are" is not a user ID. For root's sake, are you really actually thinking it through when you say stuff like this? In one breath your argument is "well biometrics aren't changeable so not like passwords" then you suggest it is equivalent to user IDs which by definition are all changea…
> user IDs which by definition are all changeable, since they are essentially aesthetic symbolic pointers towards primary keys and bundles of identity Citation needed? A fingerprint can absolutely be used to generate a hash that functions as a pointer to primary keys.
Systems that try to do this in software are always trivially circumvented because you can just change the software to allow ‘not enough matches’ instead of ‘enough matches’. The key is necessarily in the device and software can’t protect it.
Re: Fake fingerprints can imitate real ones in biometric systems
#24Earlier quoted context omitted.
It's a common sentiment amongst those who think they're educated about security. Just like "rotate passwords at rapid intervals and you must satisfy this baroque complex set of requirements for them too" is common sentiment. Unfortunately.
i think we agree more than it might seem, but i can't tell. sure those types of requirements are often absurd and result of ignorance. but back to the point, i don't understand what your argument is about user IDs. remember the context of the comment you criticized is that there are vulnerabilities in biometric security. those vulnerabilities apply when the biometric data is used as a password; it does not apply when…
Names/User IDs are not equivalent to biometrics. Nor passwords. Nor tokens. They are symbols that exist to enhance human UX. That's it.
>remember the context of the comment you criticized is that there are vulnerabilities in biometric security
Yes, just like in every single form of authentication. Which is utterly irrelevant.
>so if you're merely saying (as i think you are) that biometrics make poor usernames, much as they make poor passwords
>that biometrics make better passwords than usernames, i'll reiterate: that's wrong.
These are utterly non-sensical statements. Biometrics are not user names (a public symbol) nor are they passwords ("something you know"), "poor" has nothing to do with it, they are one of the other two classes of unique authentication factors. They have their own strengths and weaknesses, and yield different practical results when combined with one (or both) of the other two in a multi-factor authentication system. And a biometric/token MF system can absolutely be superior in security for many common threat scenarios and use cases compared to passwords. Achieving good security requires intelligent deployment of all 3.
Re: Fake fingerprints can imitate real ones in biometric systems
#25Earlier quoted context omitted.
Are you seriously arguing a fingerprint is an aesthetic symbolic pointer in the way a name is? That you are going to just refer to other people (whether IRL or online) by "fingerprint"? That people choose their fingerprints based on what they think will be a good one? That there can just be a simple process to arbitrarily change their fingerprint if they later decide they'd prefer another one? Because all of those ap…
Not trolling, but pouring more oil on the fire... TLDR yes, biometrics are the closest thing to a user ID > Are you seriously arguing a fingerprint is an aesthetic symbolic pointer in the way a name is? Absolutely. A given name is non-unique, and not chosen by you. Yet everyone refers you by it, if only by convention. > That you are going to just refer to other people (whether IRL or online) by "fingerprint"? No but…
Re: Fake fingerprints can imitate real ones in biometric systems
#26Earlier quoted context omitted.
Not trolling, but pouring more oil on the fire... TLDR yes, biometrics are the closest thing to a user ID > Are you seriously arguing a fingerprint is an aesthetic symbolic pointer in the way a name is? Absolutely. A given name is non-unique, and not chosen by you. Yet everyone refers you by it, if only by convention. > That you are going to just refer to other people (whether IRL or online) by "fingerprint"? No but…
[flagged]
Re: Fake fingerprints can imitate real ones in biometric systems
#27Earlier quoted context omitted.
I would say biometrics is “usually” used in phones where it’s used completely on its own to unlock them. You might still need a PIN to install an OS update, but that won’t keep someone from going through all of your photos and emails.
> I would say biometrics is “usually” used in phones where it’s used completely on its own to unlock them. So you'd say that "there is an actual master password and the biometric authentication is being combined with a physical token as a shortcut/proxy" then? Because that's what it is. > but that won’t keep someone from going through all of your photos and emails. Neither will a PIN in a targeted physical attack. Th…
I'd say that the fingerprint is the single factor to unlock your phone and access all of your data. Sp I'm not sure I understand your point about a physical token. That the phone is a physical token that you need in order to unlock the phone?
I guess that's true, but it's a weird way of describing it versus just calling the fingerprint a single factor used to unlock the physical device.
That feels like saying "My house has two factor authentication, one factor is they key and the other is the house." The house isn't a second factor, it's the thing you're getting access to.
Re: Fake fingerprints can imitate real ones in biometric systems
#28Earlier quoted context omitted.
i think we agree more than it might seem, but i can't tell. sure those types of requirements are often absurd and result of ignorance. but back to the point, i don't understand what your argument is about user IDs. remember the context of the comment you criticized is that there are vulnerabilities in biometric security. those vulnerabilities apply when the biometric data is used as a password; it does not apply when…
>i don't understand what your argument is about user IDs Names/User IDs are not equivalent to biometrics. Nor passwords. Nor tokens. They are symbols that exist to enhance human UX. That's it. > remember the context of the comment you criticized is that there are vulnerabilities in biometric security Yes, just like in every single form of authentication . Which is utterly irrelevant. > so if you're merely saying (as…
Re: Fake fingerprints can imitate real ones in biometric systems
#29I used to have stacks of these yellow sticky notes with my password printed on it. I ensured, that whereever I went, I would stick one of them to anything I touched, so I'd have it ready just in case. Thanks to fingerprint biometrics I can do this now just as well without even having to buy sticky notes.
> I ensured, that whereever I went, I would stick one of them to anything I touched, so I'd have it ready just in case. Indeed, sticky notes with a password printed on them stuck around where they'd be needed is exactly what my very intelligent grandmother, doctor, and likely tens if not hundreds of millions of other people do worldwide. Often to comply with "good password policies" passed down from on high by though…
PS: Just a piece of advice, your tone throughout this thread isn't going to convince anyone. On the contrary.
Re: Fake fingerprints can imitate real ones in biometric systems
#30Earlier quoted context omitted.
>i don't understand what your argument is about user IDs Names/User IDs are not equivalent to biometrics. Nor passwords. Nor tokens. They are symbols that exist to enhance human UX. That's it. > remember the context of the comment you criticized is that there are vulnerabilities in biometric security Yes, just like in every single form of authentication . Which is utterly irrelevant. > so if you're merely saying (as…
defined as such! good grief. anyone can code up a system that uses a fingerprint as a username -- you can't reply "thats not a username!" yes it is, because its defined as such! similarly, lots of applications use the fingerprint as both username and password, again defying your platonic ideal. you can go ahead and define the proper "taxonomy of authentication factors" but the whole irony is you think everyone has th…