Earlier quoted context omitted.
The problem with biometrics is not username vs password, biometrics are password. The problem is that these are client-side protections, and there's no data sent to a server that can verify the identity. And you can't build a remote identity verification with this data, because there's no way for the user to change it and revoke it (let alone it's very privacy sensitive). The biometric access control systems (the one…
> The problem with biometrics is not username vs password, biometrics are password. Yes, that is the problem. No, biometrics are not password. Please stop spouting this nonsense? Biometrics are akin to username; they suggest your identity, but don't authenticate you. They should not be used as password because they cannot be changed, and cannot be kept secret. A password (or better, TOTP authentication) can be change…
I still disagree on the username. You know my username here and on twitter, you don't know my fingerprint. And no, you can't repro my fingerprint so easily as you think because "fingerprint reader" is a short for a sophisticated piece of hardware that measures other things, e.g. blood pressure.
On the research, I didn't say biometrics can be revoked. I said you can build a function of biometrics info, whose result can be revoked [1]. No one is disagreeing with your premises, but this doesn't mean that the problem has no solutions.
[1] https://scholar.google.com/scholar?hl=en&as_sdt=0,5&q=revoca...