Live data from Hacker News

I recommend against using biometric identification

medium.freecodecamp.org

231–239 of 239 posts

Re: I recommend against using biometric identification

#231
post #189

Earlier quoted context omitted.

> Biometrics can't be rotated. But they also can't be phished. Sure they can. Haven't you ever seen a cop show where the detective tricks the suspect into drinking from a cup of coffee so they can lift the suspect's fingerprint from the cup? "Hi John, nice to meet you! * shakes hand *" I now have John's fingerprints from where he touched me when he shook my hand. "Hey John, can you send me a selfie?" I now have a pic…

They can't be phished because they aren't secrets . Yes, if you think of a biometric as a password it is an awful password. But it isn't; its primary source of security is the difficulty of presentation. You should not rely on the secrecy of your biometrics. You probably don't worry very much that your loved ones have been replaced by impostors, and the reason is not that their appearance is secret! It's just that fo…

> They can't be phished because they aren't secrets.

And here lies the problem. Apple treats them as if they are.

"Your fingerprint is one of the best passwords in the world" - Apple during the keynote when they introduced TouchID[1]

"Your face is now your secure password" - Apple during yesterday's keynote introducing FaceID[2]

1: https://youtu.be/X5zt1V7H88I?t=227

2: https://youtu.be/K4wEI5zhHB0?t=109

Re: I recommend against using biometric identification

#232

Earlier quoted context omitted.

What checks exist to prevent police from planting a USB hard drive on an enemy of the state that's encrypted and then claiming the defendant won't decrypt the hard drive? The state would have a really easy time imprisoning him/her because the defendant would never be able to provide a key to decrypt it.

Nothing but morale prevents it, just like planting any other evidence.

I'd say though that if a judge can get a free pass to lock anyone away indefinitely by police planting a USB drive -- by claiming the defendant is in contempt of court -- that's drastically different in terms of payoff on evidence planting.

Planting a gun on a defendant is much harder to do than planting a USB drive. If it really was the defendant's, they probably have munition for it, there's biological contamination etc.

It seems to me there should be an onus on the prosecutor to prove that they defendant has the key and isn't giving it up before the defendant is held in contempt of court: "Here's a video showing the defendant access the banned booked on the USB drive, she won't give up the USB-decryption key!"

Re: I recommend against using biometric identification

#233
post #231

Earlier quoted context omitted.

They can't be phished because they aren't secrets . Yes, if you think of a biometric as a password it is an awful password. But it isn't; its primary source of security is the difficulty of presentation. You should not rely on the secrecy of your biometrics. You probably don't worry very much that your loved ones have been replaced by impostors, and the reason is not that their appearance is secret! It's just that fo…

> They can't be phished because they aren't secrets. And here lies the problem. Apple treats them as if they are. "Your fingerprint is one of the best passwords in the world" - Apple during the keynote when they introduced TouchID[1] "Your face is now your secure password" - Apple during yesterday's keynote introducing FaceID[2] 1: https://youtu.be/X5zt1V7H88I?t=227 2: https://youtu.be/K4wEI5zhHB0?t=109

I wouldn't have put it that way, but the claim Apple is making (in baby talk) is that these are good authenticators, not that they are good secrets. I don't think the average person in their audience has a strong reason to understand the difference. If people were used to biometrics and you tried to get them using passwords, then it would be critical to explain the difference (if you tell the wrong person your password, it loses all its security!)

The mistakes you can make by misunderstanding biometrics seem like more of a problem for system designers, who hopefully don't get their whole understanding of security from Apple keynotes.

Re: I recommend against using biometric identification

#234
post #231

Earlier quoted context omitted.

> They can't be phished because they aren't secrets. And here lies the problem. Apple treats them as if they are. "Your fingerprint is one of the best passwords in the world" - Apple during the keynote when they introduced TouchID[1] "Your face is now your secure password" - Apple during yesterday's keynote introducing FaceID[2] 1: https://youtu.be/X5zt1V7H88I?t=227 2: https://youtu.be/K4wEI5zhHB0?t=109

I wouldn't have put it that way, but the claim Apple is making (in baby talk) is that these are good authenticators, not that they are good secrets. I don't think the average person in their audience has a strong reason to understand the difference. If people were used to biometrics and you tried to get them using passwords, then it would be critical to explain the difference (if you tell the wrong person your passwo…

> I don't think the average person in their audience has a strong reason to understand the difference.

In my experience as a security consultant, one of the biggest problems (and it's a very big problem) we face is that average users lack training and awareness of good security principles. It's really bad to rely solely on system designers for your security. Even if your system designer is 100% effective, it just takes one unaware user to do something bad such as give their password over to a phishing call and you're screwed. And if for nothing else, training and awareness is necessary because without it, you get users kicking and screaming when they don't understand why you've implemented certain security features, which typically means you end up implementing less security to avoid the kicking and screaming.

And just like in your average security training and awareness session you'll have a lesson on "don't give your password to someone on the phone, even if they claim to be your IT guy", we also have lessons on "fingerprints are not passwords, and you should not use them as such", but this is hard to get through people's heads when Apple's marketing material says otherwise (as shown in my previous comment).

Re: I recommend against using biometric identification

#235

Earlier quoted context omitted.

Encryption is nothing like locking in a safe further in a similar situation I'm pretty sure rather than going to court they just open the safe making the example even more useless.

> Encryption is nothing like locking in a safe Sure, to technical folks like us, but notice I said "in the eyes of the law". Furthermore, police can not open a safe without a court order, so guess your reply was a bust all around?

Do you have a citation wherein encryption is treated like a safe or are you like most people kind of winging it?

I know they can't open a safe or for that matter a door without a court order. The point was that the comparison between forcing open a safe and forcing someone to produce a passphrase was meaningless because the apparently treacherous question of compulsion to testify against yourself wouldn't be tested when I drill could do the job.

I am not a lawyer but I know enough to know that most people in most discussions are full of it and know little. What actually is mysterious is why people believe that their nonexistent expertise adds to the discussion.

Imagine if the matter were technical and a bunch of non tech people, say the kind who get confused about ram and storage, referring to both as memory,or call the entire thing the cpu were volunteering different insights into the question at hand. It would be useless in a funny sort of way.

Re: I recommend against using biometric identification

#236
post #149

Earlier quoted context omitted.

The answer is probably no. Requiring a person to unlock a device is not prohibited by the Fifth Amendment simply because the device contains incriminating information that would otherwise be inaccessible to police. If the police have a valid warrant to search your safe, you are generally required to unlock it for them, even if the safe contains evidence that incriminates you. If you are issued a valid subpoena to pro…

What checks exist to prevent police from planting a USB hard drive on an enemy of the state that's encrypted and then claiming the defendant won't decrypt the hard drive? The state would have a really easy time imprisoning him/her because the defendant would never be able to provide a key to decrypt it.

The check there is the judge and jury, which could be convinced by the defense that this is not their hard drive - unlike the case of Francis Rawls, where they haven't even attempted to contest that he knows the password. They haven't claimed that they are unable to perform the action, they're simply refusing to do it (and unsuccessfully contesting that they don't have to do this), so that's contempt.

It's kind of counterproductive to assume a singular agent "the state" in this context - all legal checks and balances essentially rely on multiple, separate, competing agents of the state controlling each other, separation of powers and all that. If police and all the judges are both on the same corrupt side then there's nothing stopping them from convicting you for murder of Abraham Lincoln and locking you up indefinitely for that, but we're working off of the assumption that this is not the case.

Re: I recommend against using biometric identification

#237

Earlier quoted context omitted.

I think the safe analogy is an excellent way to illustrate the issue. Encrypting a file is essentially the same thing as locking it in a safe in what I believe is the ultimate "eyes of the law" once this gets fully tried.

Encryption is nothing like locking in a safe further in a similar situation I'm pretty sure rather than going to court they just open the safe making the example even more useless.

It's a bit like the safe exactly because there's a lot of actual existing precedent where they do not "just open the safe" but require the defendant to produce the key/code to the safe; and instead of attempting to breach the safe, hold the defendant jailed for contempt if they refuse to do so.

In this particular case the authorities are explicitly arguing that there's no good reason to use a different process for passwords as they currently use for safes, and this (requiring the defendant to unlock it) is the standard procedure, not drilling the safe open.

Re: I recommend against using biometric identification

#238
post #229

Earlier quoted context omitted.

>For pretty much anyone who is logged into their work email/VPN via their phone, or is using fingerprint scanners to secure their work laptop, this is a very real concern that I have seen exploited a few times in the real world. You're conflating every fingerprint scanner with the Apple's implementation of TouchID, which is far more secure than the check-the-box-to-win-a-government-contract stuff that's been built in…

> You're conflating every fingerprint scanner with the Apple's implementation of TouchID, which is far more secure than the check-the-box-to-win-a-government-contract stuff that's been built into most laptops. No, I'm not. TouchID is the most popular implementation, and because it's present on every iPhone (which is the most common device to be a work phone, and thus also connected to work email and work networks), a…

>(which is the most common device to be a work phone, and thus also connected to work email and work networks)

So your VPN isn't adding any extra layer of auth? This doesn't seem like a TouchID problem. . .

This is also a security design problem. You shouldn't be transmitting sensitive information via e-mail. If I want sensitive data stored in your e-mail, I'd start with a phishing attack long before I decide that physically jacking your phone and coming up with a complicated finger-print stealing process is the way to go.

>This is not possible on the iPhone,

To unlock the phone. You can add addition layers after the iPhone auths all you want.

>consumers are under the false impression that fingerprints are the best security available, and they become frustrated to learn that Apple has been lying to them when corporate IT tells them fingerprints actually suck

Heh. If your clients trust Apple's marketing more than their own IT people this again speaks to me of a severe communication problem among the IT people.

>You can steal someone's fingerprint by simply having access to something they touched

Not with high enough resolution to reliably fool TouchID in few enough attempts to keep it from passcode locking you out. You're fixation on worst-case scenarios where your adversaries benefit from multiple passes of blind luck doesn't make for great or realistic risk-assessment.

>Network access to a corporate environment that has millions of SSNs, credit card numbers, etc. You think that a few hours of fiddling around with a latex mold is "too much work" for this? Think again.

And you're not monitoring for suspicious activity or any additional access control on a data source that has all that sensitive information? You're just letting people mosey on into it with just their phones without so much as a warning flag going up somewhere?

>Fingerprints are inherently insecure. Using fingerprints for more accounts is, thus, more insecure.

This is both highly simplistic and wrong. For one thing, passwords are also inherently insecure, especially when people write them on sticky notes and put them under their monitors. Secondly, not all accounts need maximal security. Not all activities within an account need to give people access to the maximal extent of their privileges. Insisting on going all out on every single thing people try to do fosters insecure habits and insecure system design. You're making the problem worse.

>Apple refers to TouchID as "the gold standard", "one of the most powerful passwords in the world", says "it is the most advanced technology", calls it "very high security".

None of which is false for the use cases they're talking about. You're talking about access to sensitive PII, which Apple did not tell you to gate behind TouchID. I also have years of experience in Infosec and setting the record straight on things takes all of 30 seconds of explanation and taking the time to understand their business context. All it takes is to not treat your clients with contempt.

Re: I recommend against using biometric identification

#239
post #131
post #50

Earlier quoted context omitted.

The "door lock" analogy ignores the biggest flaw with fingerprints: they're forever. If your door lock is compromised, you can change the key. If someone steals your password, you can change the password. If someone steals your fingerprint, you can never change your fingerprint (same with your face). The other stuff is dead-on: its a "good enough" security measure for phones. But as a security practitioner, the bigge…

> ignores the biggest flaw with fingerprints: they're forever. The second biggest flaw being your phone is covered in your fingerprints !

Third is that in a woeof hires photography every picture can contain your fingerprints.
Post reply on HN