Fingerprint technology is hackable, easily so. Edit: Face recognition is even easier. Iris scanners are the only sure way to recognize someone.
For now.
31–40 of 113 posts
Fingerprint technology is hackable, easily so. Edit: Face recognition is even easier. Iris scanners are the only sure way to recognize someone.
For now.
Intel needs to allow 3rd parties to build a small piece of hardware for private key storage, generation, signing and encryption, with self-distruction upon tampering. Then customers need to be able to go to the store, pick which vendor they want, and they plug it into their motherboard. By selling them in the store when the customer can make a surprise purchase, then that prevents tampering upon shipping withe ecommerce deliverables.
This is an adorably bad idea: + As fdik said above, you can't change your fingerprint or face easily, and it's always public + Face recognition and fingerprint scanning are not robust against spoofing — there are known ways to circumvent both + You can be compelled to authenticate a biometric without a warrant Don't use biometrics as a password; use them as a username.
Even then people's faces change and through accidents fingerprints can also be changed / removed and then you're shit out of luck. I'm terrified I would store my important shit in something like that then get into a car accident or something and be no longer able to open it.
Earlier quoted context omitted.
You can use fingerprints as a password. They aren't perfect but in many situations they are fine. Security isn't black and white.
Dear IshKebab, We at startup xyz take security seriously. We regret to inform you that on the night of 1st December 2016 our database was compromised. The database contained your name, address and fingerprint data. Please see a plastic surgeon about resetting your fingerprints at as soon as possible. Thank you, Startup Xyz
"A Virginia Circuit Court judge ruled Tuesday that police officers cannot force criminal suspects to divulge cellphone passwords, but they can force them to unlock the phone with a fingerprint scanner."
Source: http://blogs.wsj.com/digits/2014/10/31/judge-rules-suspect-c...
Second, as others have already noted, you cannot hide or change most biometric identifiers and some people may not even have them at all. Therefore, passwords will always be the safest, most accessible option. However, more education regarding their creation, use, and support needs to occur:
Password Strength: https://xkcd.com/936/
Password Reuse: https://xkcd.com/792/
NIST’s new password rules – what you need to know: https://nakedsecurity.sophos.com/2016/08/18/nists-new-passwo...
Personally, I like to choose a small token representing the site or service at hand, then surround it with multiple pass phrases I've memorized over the years. This creates a strong password which is both unique and easy to remember. Not to mention when a site I use is inevitably hacked and my hash is stolen, I only need to update a single instance of this pattern--not reevaluate my entire system.
This is an adorably bad idea: + As fdik said above, you can't change your fingerprint or face easily, and it's always public + Face recognition and fingerprint scanning are not robust against spoofing — there are known ways to circumvent both + You can be compelled to authenticate a biometric without a warrant Don't use biometrics as a password; use them as a username.
> Don't use biometrics as a password; use them as a username Even then people's faces change and through accidents fingerprints can also be changed / removed and then you're shit out of luck. I'm terrified I would store my important shit in something like that then get into a car accident or something and be no longer able to open it.
True Key makes use of the Intel Management Engine (IME). It gives a hint at what Intel is up to with the IME. One of the intended uses is "identity protection", storing secrets like e.g. biometric data in the realm of the IME, and to ultimately get rid of passwords. Considering the security concerns regarding the IME, I doubt that it is a good idea to hand your passwords over to Intel (ME). At least I don't want to s…
Interesting that Apple is doing similar things with the embedded ARM stuff in the new touchbar MBPs.
The truth is that we can't trust INTEL. Their CPU micro-code or ME (Management engine) can and does "phone home" to the internet, grab updates and update the CPU. They don't allow the customer to turn this OFF, which betray's the customer who purchased the CPU. Anyone who can sign the update and intercept the download channel can update your CPU with you having no ability to protect yourself. We can't trust intel. In…
Earlier quoted context omitted.
Dear IshKebab, We at startup xyz take security seriously. We regret to inform you that on the night of 1st December 2016 our database was compromised. The database contained your name, address and fingerprint data. Please see a plastic surgeon about resetting your fingerprints at as soon as possible. Thank you, Startup Xyz
Genuinely surprised to not see this happen yet. I guess it's a good thing Apple and Google are the ones who typically store Fingerprints and not third party apps.
Earlier quoted context omitted.
Dear IshKebab, We at startup xyz take security seriously. We regret to inform you that on the night of 1st December 2016 our database was compromised. The database contained your name, address and fingerprint data. Please see a plastic surgeon about resetting your fingerprints at as soon as possible. Thank you, Startup Xyz
Genuinely surprised to not see this happen yet. I guess it's a good thing Apple and Google are the ones who typically store Fingerprints and not third party apps.